<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Compliance on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/compliance/</link>
    <description>Recent content in Compliance on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 21 Jun 2017 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/compliance/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>GDPR and Pseudonymisation – Easing the Pain of Regulation</title>
      <link>https://insinuator.net/2017/06/gdpr-and-pseudonymisation-easing-the-pain-of-regulation/</link>
      <pubDate>Wed, 21 Jun 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/06/gdpr-and-pseudonymisation-easing-the-pain-of-regulation/</guid>
      <description>&lt;p&gt;27 April 2016 marked a turning point for a lot of countries as well as a lot businesses worldwide: EU regulation 2016/679 (going by it’s more widely known name General Data Protection Regulation and abbreviated GDPR) was adopted by the European Parliament, the Council as well as the Commission [1]. Especially readers from countries outside of the EU might ask “Why should this be of interest for me?”.&lt;/p&gt;&#xA;&lt;p&gt;The point is: if your business is dealing with data of EU citizens (e.g. because you are having an online shop selling goods in the EU, or you operate a social network platform with customers that are EU citizens) you are liable under GDPR – this is regulated in Article 3, section 2 of the regulation: &lt;em&gt;“This Regulation applies to the processing of personal data of data subjects residing in the Union by a controller not established in the Union, where the processing activities are related to:&lt;/em&gt;&lt;br&gt;&#xA;&lt;em&gt;(a) the offering of goods or services to such data subjects in the Union; or&lt;/em&gt;&lt;br&gt;&#xA;&lt;em&gt;(b) the monitoring of their behaviour.”&lt;/em&gt;&lt;br&gt;&#xA;I’d guess that if you are reading these lines you become aware (if not have been so before) that your business might most probably be affected by GDPR as well. Now, the purpose of this blog post is not to enlighten you on the basics of GDPR but to discuss one special, interesting aspect of this regulation: pseudonymisation and how it might support your way to become compliant with GDPR.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Windows Server 2008 R2 BSI-compliance</title>
      <link>https://insinuator.net/2012/07/windows-server-2008-r2-bsi-compliance/</link>
      <pubDate>Thu, 26 Jul 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/07/windows-server-2008-r2-bsi-compliance/</guid>
      <description>&lt;p&gt;Recommendations by the &lt;a href=&#34;https://www.bsi.bund.de/EN/Home/home_node.html&#34;&gt;German Federal Office for Information Security&lt;/a&gt; (&lt;em&gt;BSI – Bundesamt für Sicherheit in der Informationstechnik&lt;/em&gt;) are obligatory for German government agencies, civil services and authorities (like recommendations of the NIST are relevant to American government agencies and authorities). They are often used as references and security best practices in other countries as well. Hence it is hard to understand why the recommendations on how to harden Windows Server &lt;strong&gt;2008&lt;/strong&gt; based systems were published only some weeks ago and only on a preliminary draft basis (which is, obviously, better than nothing ;-)).&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
