Accelerate GDPR compliance with the Microsoft Cloud
Henrik Mønsted Cloud Solutions Architect Microsoft Denmark
This presentation is intended to provide an overview of GDPR and is not a definitive statement of the law.
Accelerate GDPR compliance with the Microsoft Cloud Henrik Mnsted - - PowerPoint PPT Presentation
Accelerate GDPR compliance with the Microsoft Cloud Henrik Mnsted Cloud Solutions Architect Microsoft Denmark This presentation is intended to provide an overview of GDPR and is not a definitive statement of the law. 1. Data Privacy and
Henrik Mønsted Cloud Solutions Architect Microsoft Denmark
This presentation is intended to provide an overview of GDPR and is not a definitive statement of the law.
Enhanced personal privacy rights Increased duty for protecting data Mandatory breach reporting Significant penalties for non-compliance
Microsoft believes the GDPR is an important step forward for clarifying and enabling individual privacy rights
Personal privacy
Controls and notifications Transparent policies IT and training
Organizations will need to:
& employees
policies
Officer (if required)
compliant vendor contracts Organizations will need to:
using appropriate security
72 hours of breaches
consents for processing data
data processing Individuals have the right to:
data
personal data
their personal data
Organizations are required to:
data collection
purposes and use cases
and deletion policies
GDPR Compliance GDPR Compliance GDPR Compliance
Identify what personal data you have and where it resides
Discover 1
Govern how personal data is used and accessed
Manage 2
Establish security controls to prevent, detect, and respond to vulnerabilities & data breaches
Protect 3
Keep required documentation, manage data requests and breach notifications
Report 4
In-scope:
Microsoft Azure Data Catalog
Enterprise Mobility + Security (EMS)
Microsoft Cloud App Security
Dynamics 365
Audit Data & User Activity Reporting & Analytics
Office & Office 365
Data Loss Prevention Advanced Data Governance Office 365 eDiscovery
SQL Server and Azure SQL Database
SQL Query Language
Windows & Windows Server
Windows Search
Data governance:
Azure Active Directory Azure Information Protection Azure Role-Based Access Control (RBAC)
Enterprise Mobility + Security (EMS)
Azure Information Protection
Dynamics 365
Security Concepts
Office & Office 365
Advanced Data Governance Journaling (Exchange Online)
Windows & Windows Server
Microsoft Data Classification Toolkit
Classification and labelling Encryption and rights management Intuitive, one-click process Detailed tracking and reporting
Built-in Azure, no setup required Automatically discover and monitor security of Azure resources Gain insights for hybrid resources Easily onboard resources running in other clouds and on-premises
Record-keeping:
Service Trust Portal
Microsoft Azure
Azure Auditing & Logging Azure Data Lake Azure Monitor
Enterprise Mobility + Security (EMS)
Azure Information Protection
Dynamics 365
Reporting & Analytics
Office & Office 365
Service Assurance Office 365 Audit Logs Customer Lockbox
Windows & Windows Server
Windows Defender Advanced Threat Protection
The Service Trust Platform (STP) is a companion feature to the Microsoft Trust Center, and allows you to:
how can you use Microsoft cloud service features to manage compliance with various regulations.
Microsoft cloud services help protect your data. servicetrust.microsoft.com
Manage your compliance from one place
An intelligent score shows your compliance posture against evolving regulations
Recommended actions to improve your data protection capabilities
Streamlined workflow and audit-ready reports
Azure Data Catalog/Azure App Catalog
will help discover patient and health data across your applications, tools and databases.
Microsoft Azure provides a secure
and robust platform to store patient and health data. Utilize pseudonymizing and encryption capabilities to increase security and reduce exposure to risk.
Windows 10 prevents unauthorized apps
from accessing health and patient data, and health professionals from leaking data with copy and paste protection.
Compliance Manager helps assess and
track data protection and compliance posture and get actionable insights to
can better understand their compliance posture against regulatory standards.
Discover Manage Protect Report
Service Trust Platform
provides access to audit reports and compliance guides to help you understand how can you use Microsoft cloud service features to manage compliance
Existing compliance approaches and attestations already in
alignment with the GDPR provide a good foundation to start from.
Identity and Access Management and Conditional Access can help
manage access to data across platforms, whether in the cloud, on premise or in a hybrid environment.
BRK3241 Secure your data in Azure SQL Database and SQL Data Warehouse BRK3087 Azure SQL Database: The world's first intelligent cloud database service BRK22 K2230 30 Wh What' t's new with Azu zure SQL L Database tabase: : Focu cus s on your busines iness, s, not on the databas tabase THR2024 Practica ctical tips s and conside sidera ration tions s by indust stry y experts ts on how w to become
PR complia pliant nt