Educause Security Discussion mailing list archives

Re: EU's GDPR - is anyone worrying/doing anything?


From: Jim Dillon <jim.dillon () CU EDU>
Date: Mon, 5 Jun 2017 17:12:29 +0000

Laura,

No plans (solid/documented/complete) I'm aware of yet, but our compliance audit manager is fairly concerned about its 
potential impact and we are gathering opinions and researching the topic.  Her sense is we will need to take steps to 
comply.  Not being a legal expert myself I'm always in jurisdictional quandaries about regulations from other nations 
and in other states (remember California's privacy rules?) and how those could have tangible impact, but so far people 
closer to this issue than I believe it to be real.  Since CU is very heavily reaching out to international students we 
may have this problem to a greater degree than others.

Sorry nothing specific to report other than it does pay to pay attention here.  I suggest taking this to compliance and 
legal folks for interpretation as they will (or should) have a more sound understanding of the implications.  My 
impression is that if we advertise and register students in GDPR nations we are definitely accountable for any actions 
there, and that given the typical Internet jurisdictional concerns, we probably are here as well.  I don't have a 
handle on what that means from an operational standpoint yet but it looks a bit onerous to me at the moment.  Yet 
another set of demands to add to your favorite cross-walk.

Might be a good question for the privacy/policy forums if you don't mind cross-posting a bit.

Best regards,

Jim Dillon

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _
Jim Dillon
Director of IT Audit Services, CU Internal Audit
303-735-7028

-----Original Message-----
From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Laura 
Raderman
Sent: Monday, June 05, 2017 10:48 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] EU's GDPR - is anyone worrying/doing anything?

Is there any institution that’s worried about or otherwise doing anything about the GDPR and getting ready for the May 
2018 “deadline”?  If so, would you be willing to give me a quick overview of what you’re including in your plans?

Thanks,
Laura

Laura Raderman
ISO Policy & Compliance Coordinator
Carnegie Mellon University
lraderman () cmu edu


Current thread: