Eduardo Lopez

The challenges of the general data protection regulation

IT professional with over 25 years of experience in IT management.
Co-founder of SIA, a company with more than 650 professionals working for large organizations in Finance, Energy, Distribution, Health and Government organizations, mainly in the areas of Security, IT Governance and Data Intelligence. Telecommunication Engineer by Madrid University (UPM) and with Post graduate studies in Germany (University of Stuttgart), achieving Doctor Engineer degree in Telecommunications. Education is also completed with MBA by ESIC-Madrid and studies in Arts. Mr. Lopez has deployed his professional activity in Spain, Germany, The Netherland, Belgium and Portugal , and has been focus in Security and IT Management, especially in the areas of Identity Management, Encryption and Digital Signatures, and IT architectures and services.

Nationality: Portugal

Scientific areas: Dental assistant course

10 of november, from 14h30 until 16h00

Auditório D

Conference summary

Most of the existing processes in organizations rely to a large extent on the processing of personal data belonging to different stakeholder groups. The nature of the risks to which the processing of personal data is exposed presupposes the need not only to introduce initially the legal, technical and organizational requirements established by the regulatory frame of reference but also, and in particular to manage the maintenance of compliance effective over time.

The exercise of good control and management of personal data is essential to ensure, and be able to demonstrate, compliance with the RGPD. Risk management is an effective way of protecting “the fundamental rights and freedoms of natural persons, and in particular their right to privacy with regard to the processing of personal data”.

The regulatory framework requires that all treatment activities go through Need and Minimization. Organizations shall have the capacity to justify the need for collection, conservation, consultation and transfer of information and shall collect the minimum data required, retain for the minimum time required and be accessed and shared with a minimum number of persons or organizations.

The security of personal information should be based on respect for good practices and maintenance of data processing systems in order to be protected against attacks. Information security should include the use of information systems that include mechanisms to record the actions of each user in the system during a defined period of time; ensure the integrity of the data and include a mechanism for any deletion, archiving or anonymisation of such data when the retention period expires.