SECURITYMADEIN.LU's 4th security breakfast was held at the premises of Allen & Overy and celebrated "Data Protection Day" by reviewing the next reform of legislation on the protection of personal data with the help of four experts: Dr. Catherine Di Lorenzo (Allen & Overy); Dr. Michèle Feltz (CNPD); Dr. Matthieu Farcot (Securitymadein.lu); and Mélanie Gagnon (MGSI). At this, they discussed the evolution of the new security directive.

The GDPR (General Data Protection Regulation) is the fruit of three years of discussions at various levels and replaces the current directive. It will come into effect without the need to be introduced in national legislation, probably sometime in 2018.

The new regulation amends the current Directive including the definition of personal data, adding location and login credentials to the list of information that can be included in the identification of a person. The definition of processing of personal data does not change but the concept of "pseudonymisation" is introduced, i.e. the possibility of applying a treatment to personal data so that they can be assigned to people.

The new regulation also provides details on the measures to ensure the protection, integrity and availability of personal data and the notification requirements in the event of data loss. Last but not least, the penalties for non-compliance with this new regulation will be calculated based on the net global turnover of companies (2-4%) according to the gravity of the offense committed.

During the event, Matthieu Farcot referenced the case of VTECH which hit the headlines late 2015 with a serious data leak (6.3 million profiles including 5,014 in Luxembourg) that involved children and contained many sensitive data including passwords. The collateral damage affected those who have the bad habit of using the same password for different services.

The concept of "Privacy by Design" will emerge as new standard to allow users to better control the collection of their personal data, systematically, on the assumption that the highest protection must be proposed by default. Privacy by Design is a preventive approach that integrates data protection requirements from the start, in the same design applications or online services.

SECURITYMADEIN.LU‘s cyber security breakfasts are the place to meet the local cyber security ecosystem, discuss relevant and current topics of interest and share information relevant to your business and/or daily operational work.

Organised on a monthly basis and in collaboration with members of the Luxembourg Cybersecurity Ecosystem, the model is simple:

- keynote on a specific theme of interest,
- round-table discussion with field experts
- and enough time for questions of the audience and networking.

For further details, email: info@securitymadein.lu.