SlideShare uma empresa Scribd logo
1 de 34
Baixar para ler offline
@aureliepols
© 2016
Data Accountability &
Consumer Trust
June 23rd 2016
Aurélie Pols
@aureliepols
About me: MAD / BRU / SFO
1.  Data Governance & Privacy Advocate for Krux Digital
2.  EAG: Ethics Advisory Group for the European Data Protection
Supervisor (EDPS)
3.  Chief Visionary Officer for Mind Your Privacy
•  Training Advisory Board, International Association of Privacy Professionals (IAPP)
•  Ethics & Privacy professor in Big Data & Analytics Master, Instituto de Empresa (IE)
•  [Entrepreneur / Data Scientist? / Privacy Engineer? / Mother]
•  (Dutch nationality, French mother tongue, work mostly in English, live in Spain)
2
@aureliepols
The European Data Protection
Supervisor:
an independent institution
responsible for ensuring the
protection of personal data by the
EU institutions and bodies
The EDPS
Giovanni Buttarelli
EDPS
Wojciech Wiewiórowski
Assistant EDPS
3
@aureliepols
[Entrepreneur / Data Scientist / Privacy Engineer / Mother]
4
@aureliepols
The Internet grows up; enters Big (& ubiquity of) Data
5
The New Yorker - July 5, 1993 10 years later…
@aureliepols
Digital Ads & Targeting
Online Advertising surpasses TV to record annual
spend of €36.2bn
DATA load
2.5 quintillion bytes of data
are created everyday
Perpetually connected consumer
} 3 connected devices used per person in 2014
} 9h53m is the average time spent by US adult
on connected screens every day
Sources : IAB (2016), IBM (2014), Statistica (US, 2014), eMarketer (US, 2015)
DATA PRIVACY
THE NEW ERA
@aureliepols
DATA PRIVACY
THE PARADOX
65% of consumers do not have
confidence in the security of their personal
data.
67% are willing to share personal
data in exchange for additional services.
Source: Accenture
@aureliepols
Setting the Data Privacy
stage
@aureliepols
Privacy actors within the data ecosystem
9
DATA
ECOSYSTEM
Citizens
Consumers
Voters
Authorities
law +
enforcement
Companies
Businesses
DATA QUALITY CLASS ACTIONS
AdBlocking
COMPLIANCE
GDPR Fines:
4% of Global Turn-
Over
@aureliepols
Framing digital data accountability
10
OUR
CLIENTS
DATA FLOW
RESPONSIBLITY
DATA
CONTROLLER
DATA
PROCESSOR
THEIR
CUSTOMERS
PRIVACY
RIGHTS
DATA PROTECTION / SECURITY
PRIVACY BY DESIGN (PbD)
DATA ETHICS
@aureliepols
Foundations of Privacy Law
@aureliepols
One legal concept to rule them all
FTCs Fair Information Practice Principles (FIPPs)
Transparency
Choice
Information
review &
correction
Information
protection
Accountability
12
@aureliepols 13
Comparing global Privacy legislation
@aureliepols
Purpose, Consent & Data Uses evolution
Purpose
Consent
FIPPs
Data for
approved use
Before Big Data:
Purpose
Consent
FIPPsData analysis or
merging
New business
opportunity
Today’s challenge:
@aureliepols
The devil in the details, for our clients
Purpose = Reason for data collection, usually broad
•  Website improvement, better UX
•  Marketing communication
•  Sharing data with 3rd parties
Consent
•  Types
•  Implicit: Opt-in? Double opt-in?; Explicit: Opt-out?
•  Depends upon
•  Type of data: PII, sensitive data, …
•  Type of sector: financial, health, …
•  Geography: US vs. EU, Singapore, …
15
@aureliepols 16
Privacy legislation kicks in
with PII / Personal Data
(yet lines are blurring!)
@aureliepols
General Data
Protection Regulation
(GPDR) - May 25 2018
GDPR Fines: 4% of
Global Turn-Over !!!
Which variables or combination exactly?
Data types & the law: obligations vary
Hashing & encryption (by default)
17
@aureliepols
Tension between US PII & EU Personal Data
Personally Identifiable Information (PII) Personal Data
1.  Name, such as full names, maiden name, mother’s
maiden name, or alias;
2.  Personal identification #: social security # (SSN),
passport #, driver’s license #, account and credit card
#;
3.  Address information: street address or email;
4.  Asset information: Internet Protocol (IP) or Media
Access Control (MAC);
5.  Phone #, including mobile, business and personal.
Information identifying personally owned property
such as vehicle registration # or title # and related
information.
“Personal data shall mean any information relating
to an individual or identifiable natural person (“data
subject”); an identifiable person is one who can be
identified, directly or indirectly, in particular or by
reference to an identification number or to one or
more factors specific to his physical, mental,
economic, cultural or social identity”
Based on the definition commonly used by most US States Directive 95/46/EC, the Data Protection Directive
@aureliepols
De-identification is a compliance exercise
From Shades of Grey: Seeing the full spectrum of Practical Data De-Identification by Jules Polonetsky, Omer Tene & Kelsey Finch,
April 1st 2016, http://papers.ssrn.com/sol3/papers.cfm?abstract_id=2757709
19
@aureliepols
Identification capabilities is a TRUST issue
From Data Privacy: Understanding Privacy principles and ensuring compliance of your digital activities
by Aurélie Pols for AT Internet, May 2016
20
@aureliepols
Moving beyond the divide: Digital Ethics
•  Layer approach for data driven companies:
Privacy Engineering by Krux
•  Promise to our clients’ clients: TRUST
•  Bare minimum: Compliance!
VALUE / ETHICS
Respect individuals
Corporate Social
Responsibility
RISK
Do not harm
Standard Operating
Procedure
COMPLIANCE
Don’t hit people! Legislation
ETHICS
PROCESS
LAW
@aureliepols
For Krux, this means
22
ü Assuring compliance & limiting risk for Krux
ü Assuring our clients’ data uses are compliant with
legislations they address + global platform !!!
ü Leveraging the data to allow our clients to make
ethical decisions about their data uses
@aureliepols 23
Evolving Privacy legislation
(short term)
@aureliepols
Old and new EU Privacy rules
STABLE EU PRIVACY LEGISLATION
SafeHarbor
for international transfers
of personal data
EU Data Protection Directive (95/46/EC)
regulates personal data within the EU
EU ePrivacy Directive* on Privacy &
Electronic Communication – think cookies!
* (2002/58/EC amended 2006/24/EC & 2009/136/EC)
FUTURE EU PRIVACY
LEGISLATION
PrivacyShield
strong enough?
EU General Data Protection
Regulation (GDPR) strengthens &
unifies data protection for EU citizens
Revision of the ePrivacy Directive à
Regulation? Confidentiality for all
communications (Skype, WhatsApp, …) +
strengthen consent rules?
May 25 2018
Draft December
2016: EU DNT?
@aureliepols
Data Privacy laws globally?
Blue = Strong Privacy legislation - Green = Moderate - Orange = Limited ??
25
Data Balkanization vs. UN Globalization effort
Joe Cannataci
UN Special Rapporteur
Privacy in the Digital Age
@aureliepols 26
Challenges & Opportunities
@aureliepols
Competing on Privacy?
•  Increased non compliance
risk for the data industry
•  Clients will require:
ü Guidance
ü Documentation
ü Features
Privacy Engineering by Krux
27
@aureliepols
For Krux, this means
28
ü Assuring compliance & limiting risk for Krux
ü Assuring our clients’ data uses are compliant with
legislations they address + global platform !!!
ü Leveraging the data to allow our clients to make
ethical decisions about their data uses
@aureliepols
@aureliepols
DOs
1.  Define your role with the Data Ecosystem
2.  Keep metadata on Purpose and Consent*
3.  Undergo Privacy Impact/Risk Assessments (PIAs) for
§  Product Launches
§  (new) Data Uses
4.  Document Data Flows
5.  Keep data clean & to a minimum: data retention & breach
notifications
* Unless anonymization today, not tomorrow!!!
30
@aureliepols
DON’Ts*
1.  Break the Consent chain
2.  Disrespect Customer Expectations
3.  Sell personal data without Consent
4.  Buy data without understanding Purpose
5.  Enrich data without understanding previous rules
•  Unless anonymization today, not tomorrow
31
@aureliepols
Ethics of the data analyst
32
I shall remember data are not only numbers but actual people, that could be harmed by my work;
I shall treat data that might identify individuals with the utmost care, which includes respect for their dignity, avoiding discrimination, as
well as security best practices;
I will not do to personal data what I wouldn’t find acceptable for data related to my family, friends, loved ones or myself;
I understand personal data, PII &/or sensitive data is context based and often difficult to identify. In case of doubt, I will ask for
help or escalate in order to take the appropriate measures;
I understand data about individuals needs to travel with initial purpose of the data – the reason why it exists - & their respective
consent mechanisms;
a)  I will never use data without knowing where it comes from, it’s purpose and consent mechanisms (see Quién es la Última Principle);
b)  I will never sell non consented data about individuals;
c)  If I sell consented data, it will be accompanied by purpose. Up to the buyer to define whether subsequent data uses are aligned.
I understand consent might be revoked and a Right to be Forgotten – i.e. deletion – could be requested, that might need to be applied;
I shall align security protocols with how personal &/or sensitive the data is;
I will keep trace and document the data used in order to minimize risk related to data uses.
@aureliepolsDigital Intelligence Solutions
DATA IS TRANSFORMING OUR VERY LIVES
PRESERVATION OF HUMAN DIGNITY IS AT STAKE
@aureliepols
Gracias / Merci / Danke
Schön / Bedankt / ‫תודה‬ /
ευχαριστίες
krux.com
apols@krux.com

Mais conteúdo relacionado

Mais procurados

Information Security in the Age of Wikileaks
Information Security in the Age of WikileaksInformation Security in the Age of Wikileaks
Information Security in the Age of Wikileaksdbarton944
 
Security and Safe Keeping of Official Information by DPO
Security and Safe Keeping of Official Information by DPOSecurity and Safe Keeping of Official Information by DPO
Security and Safe Keeping of Official Information by DPOAtlantic Training, LLC.
 
Privacy in Bigdata Era
Privacy in Bigdata  EraPrivacy in Bigdata  Era
Privacy in Bigdata EraSrinath Perera
 
Ark presentation
Ark presentationArk presentation
Ark presentationbrentcarey
 
Lasa European NFP Technology Conference 2010 - Data protection and the cloud
Lasa European NFP Technology Conference 2010 - Data protection and the cloudLasa European NFP Technology Conference 2010 - Data protection and the cloud
Lasa European NFP Technology Conference 2010 - Data protection and the cloudukriders
 
Handling information Standard by Skills for Care
Handling information Standard by Skills for CareHandling information Standard by Skills for Care
Handling information Standard by Skills for CareAtlantic Training, LLC.
 
Why do you need an it policy it-toolkits
Why do you need an it policy     it-toolkitsWhy do you need an it policy     it-toolkits
Why do you need an it policy it-toolkitsIT-Toolkits.org
 
Privacy learning forum broadmeadows
Privacy learning forum broadmeadowsPrivacy learning forum broadmeadows
Privacy learning forum broadmeadowsbrentcarey
 
Training for managers and supervisors presentation
Training for managers and supervisors presentationTraining for managers and supervisors presentation
Training for managers and supervisors presentationbrentcarey
 
Developing a privacy compliance program
Developing a privacy compliance programDeveloping a privacy compliance program
Developing a privacy compliance programRaoul Miller
 
Privacy morwell june 09
Privacy morwell june 09 Privacy morwell june 09
Privacy morwell june 09 brentcarey
 
Trivadis TechEvent 2016 Big Data Privacy and Security Fundamentals by Florian...
Trivadis TechEvent 2016 Big Data Privacy and Security Fundamentals by Florian...Trivadis TechEvent 2016 Big Data Privacy and Security Fundamentals by Florian...
Trivadis TechEvent 2016 Big Data Privacy and Security Fundamentals by Florian...Trivadis
 
Seth Earley Talks About Enterprise Information Architecture
Seth Earley Talks About Enterprise Information ArchitectureSeth Earley Talks About Enterprise Information Architecture
Seth Earley Talks About Enterprise Information ArchitectureEarley Information Science
 

Mais procurados (13)

Information Security in the Age of Wikileaks
Information Security in the Age of WikileaksInformation Security in the Age of Wikileaks
Information Security in the Age of Wikileaks
 
Security and Safe Keeping of Official Information by DPO
Security and Safe Keeping of Official Information by DPOSecurity and Safe Keeping of Official Information by DPO
Security and Safe Keeping of Official Information by DPO
 
Privacy in Bigdata Era
Privacy in Bigdata  EraPrivacy in Bigdata  Era
Privacy in Bigdata Era
 
Ark presentation
Ark presentationArk presentation
Ark presentation
 
Lasa European NFP Technology Conference 2010 - Data protection and the cloud
Lasa European NFP Technology Conference 2010 - Data protection and the cloudLasa European NFP Technology Conference 2010 - Data protection and the cloud
Lasa European NFP Technology Conference 2010 - Data protection and the cloud
 
Handling information Standard by Skills for Care
Handling information Standard by Skills for CareHandling information Standard by Skills for Care
Handling information Standard by Skills for Care
 
Why do you need an it policy it-toolkits
Why do you need an it policy     it-toolkitsWhy do you need an it policy     it-toolkits
Why do you need an it policy it-toolkits
 
Privacy learning forum broadmeadows
Privacy learning forum broadmeadowsPrivacy learning forum broadmeadows
Privacy learning forum broadmeadows
 
Training for managers and supervisors presentation
Training for managers and supervisors presentationTraining for managers and supervisors presentation
Training for managers and supervisors presentation
 
Developing a privacy compliance program
Developing a privacy compliance programDeveloping a privacy compliance program
Developing a privacy compliance program
 
Privacy morwell june 09
Privacy morwell june 09 Privacy morwell june 09
Privacy morwell june 09
 
Trivadis TechEvent 2016 Big Data Privacy and Security Fundamentals by Florian...
Trivadis TechEvent 2016 Big Data Privacy and Security Fundamentals by Florian...Trivadis TechEvent 2016 Big Data Privacy and Security Fundamentals by Florian...
Trivadis TechEvent 2016 Big Data Privacy and Security Fundamentals by Florian...
 
Seth Earley Talks About Enterprise Information Architecture
Seth Earley Talks About Enterprise Information ArchitectureSeth Earley Talks About Enterprise Information Architecture
Seth Earley Talks About Enterprise Information Architecture
 

Destaque

Joe Reid, Krux: People Data Activation, from paradox to paradigm @ iMedia Dat...
Joe Reid, Krux: People Data Activation, from paradox to paradigm @ iMedia Dat...Joe Reid, Krux: People Data Activation, from paradox to paradigm @ iMedia Dat...
Joe Reid, Krux: People Data Activation, from paradox to paradigm @ iMedia Dat...ad:tech London, MMS & iMedia
 
Digitale kundeoplevelser den 29. januar - Morten Schroeder, Wilke
Digitale kundeoplevelser den 29. januar - Morten Schroeder, WilkeDigitale kundeoplevelser den 29. januar - Morten Schroeder, Wilke
Digitale kundeoplevelser den 29. januar - Morten Schroeder, WilkeHusetMarkedsforing
 
Mo' Metrics, Mo' Problems
Mo' Metrics, Mo' ProblemsMo' Metrics, Mo' Problems
Mo' Metrics, Mo' ProblemsErin Willingham
 
Marketing in Motion: From Unified Data to Actionable Insights
Marketing in Motion: From Unified Data to Actionable InsightsMarketing in Motion: From Unified Data to Actionable Insights
Marketing in Motion: From Unified Data to Actionable InsightsKrux
 
People Data Activation: From Paradox to Paradigm
People Data Activation: From Paradox to Paradigm People Data Activation: From Paradox to Paradigm
People Data Activation: From Paradox to Paradigm Krux
 
RTB Update 2: Richard Foster, Krux
RTB Update 2: Richard Foster, KruxRTB Update 2: Richard Foster, Krux
RTB Update 2: Richard Foster, KruxHusetMarkedsforing
 
How Genentech developed its employee advocacy program | Talent Connect 2016
How Genentech developed its employee advocacy program | Talent Connect 2016How Genentech developed its employee advocacy program | Talent Connect 2016
How Genentech developed its employee advocacy program | Talent Connect 2016LinkedIn Talent Solutions
 

Destaque (8)

Joe Reid, Krux: People Data Activation, from paradox to paradigm @ iMedia Dat...
Joe Reid, Krux: People Data Activation, from paradox to paradigm @ iMedia Dat...Joe Reid, Krux: People Data Activation, from paradox to paradigm @ iMedia Dat...
Joe Reid, Krux: People Data Activation, from paradox to paradigm @ iMedia Dat...
 
Personal Clouds + Augmented Reality
Personal Clouds + Augmented RealityPersonal Clouds + Augmented Reality
Personal Clouds + Augmented Reality
 
Digitale kundeoplevelser den 29. januar - Morten Schroeder, Wilke
Digitale kundeoplevelser den 29. januar - Morten Schroeder, WilkeDigitale kundeoplevelser den 29. januar - Morten Schroeder, Wilke
Digitale kundeoplevelser den 29. januar - Morten Schroeder, Wilke
 
Mo' Metrics, Mo' Problems
Mo' Metrics, Mo' ProblemsMo' Metrics, Mo' Problems
Mo' Metrics, Mo' Problems
 
Marketing in Motion: From Unified Data to Actionable Insights
Marketing in Motion: From Unified Data to Actionable InsightsMarketing in Motion: From Unified Data to Actionable Insights
Marketing in Motion: From Unified Data to Actionable Insights
 
People Data Activation: From Paradox to Paradigm
People Data Activation: From Paradox to Paradigm People Data Activation: From Paradox to Paradigm
People Data Activation: From Paradox to Paradigm
 
RTB Update 2: Richard Foster, Krux
RTB Update 2: Richard Foster, KruxRTB Update 2: Richard Foster, Krux
RTB Update 2: Richard Foster, Krux
 
How Genentech developed its employee advocacy program | Talent Connect 2016
How Genentech developed its employee advocacy program | Talent Connect 2016How Genentech developed its employee advocacy program | Talent Connect 2016
How Genentech developed its employee advocacy program | Talent Connect 2016
 

Semelhante a Data Accountability & Consumer Trust

eMetrics Summit Boston 2014 - Big Data for Marketing - Privacy Principles & P...
eMetrics Summit Boston 2014 - Big Data for Marketing - Privacy Principles & P...eMetrics Summit Boston 2014 - Big Data for Marketing - Privacy Principles & P...
eMetrics Summit Boston 2014 - Big Data for Marketing - Privacy Principles & P...Aurélie Pols
 
eMetrics Summit Boston 2014 - Big Data Marketing - From Über Creepy to Over ...
 eMetrics Summit Boston 2014 - Big Data Marketing - From Über Creepy to Over ... eMetrics Summit Boston 2014 - Big Data Marketing - From Über Creepy to Over ...
eMetrics Summit Boston 2014 - Big Data Marketing - From Über Creepy to Over ...Aurélie Pols
 
A Framework of Purpose and Consent for Data Security and Consumer Privacy
A Framework of Purpose and Consent for Data Security and Consumer PrivacyA Framework of Purpose and Consent for Data Security and Consumer Privacy
A Framework of Purpose and Consent for Data Security and Consumer PrivacyAurélie Pols
 
Storm on the Horizon: Data Governance & Security vs. Employee Privacy
Storm on the Horizon: Data Governance & Security vs. Employee PrivacyStorm on the Horizon: Data Governance & Security vs. Employee Privacy
Storm on the Horizon: Data Governance & Security vs. Employee PrivacyAurélie Pols
 
Privacy & Analytics: Yeti or Snow Fairy?
Privacy & Analytics: Yeti or Snow Fairy?Privacy & Analytics: Yeti or Snow Fairy?
Privacy & Analytics: Yeti or Snow Fairy?FLUZO
 
Hivos and Responsible Data
Hivos and Responsible DataHivos and Responsible Data
Hivos and Responsible DataTom Walker
 
Smarter comm"The Future of Privacy". Aurélie Pols at IBM Smarter Commerce Glo...
Smarter comm"The Future of Privacy". Aurélie Pols at IBM Smarter Commerce Glo...Smarter comm"The Future of Privacy". Aurélie Pols at IBM Smarter Commerce Glo...
Smarter comm"The Future of Privacy". Aurélie Pols at IBM Smarter Commerce Glo...FLUZO
 
A Global Marketer's Guide to Privacy
A Global Marketer's Guide to PrivacyA Global Marketer's Guide to Privacy
A Global Marketer's Guide to PrivacyFLUZO
 
Data Privacy: What you need to know about privacy, from compliance to ethics
Data Privacy: What you need to know about privacy, from compliance to ethicsData Privacy: What you need to know about privacy, from compliance to ethics
Data Privacy: What you need to know about privacy, from compliance to ethicsAT Internet
 
Privacy & Data Ethics
Privacy & Data EthicsPrivacy & Data Ethics
Privacy & Data EthicsErik Kokkonen
 
Data set Legislation
Data set   Legislation Data set   Legislation
Data set Legislation Data-Set
 
Privacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital SetupPrivacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital SetupPiwik PRO
 
Scotland legal update 25 sept
Scotland legal update   25 septScotland legal update   25 sept
Scotland legal update 25 septRachel Aldighieri
 
Respect Thy Data: The Gospel
Respect Thy Data: The GospelRespect Thy Data: The Gospel
Respect Thy Data: The GospelJill Gilbert
 
Data set Legislation
Data set LegislationData set Legislation
Data set LegislationData-Set
 
Data set Legislation
Data set LegislationData set Legislation
Data set LegislationData-Set
 
AI Roles and Risk for election year 2024
AI Roles and Risk for election year 2024AI Roles and Risk for election year 2024
AI Roles and Risk for election year 2024Aurélie Pols
 
Data set module 4
Data set   module 4Data set   module 4
Data set module 4Data-Set
 
Ethics in Data Management.pptx
Ethics in Data Management.pptxEthics in Data Management.pptx
Ethics in Data Management.pptxRavindra Babu
 
Aurélie Pols en Strata Conference: Digital analytics & privacy - it’s not the...
Aurélie Pols en Strata Conference: Digital analytics & privacy - it’s not the...Aurélie Pols en Strata Conference: Digital analytics & privacy - it’s not the...
Aurélie Pols en Strata Conference: Digital analytics & privacy - it’s not the...FLUZO
 

Semelhante a Data Accountability & Consumer Trust (20)

eMetrics Summit Boston 2014 - Big Data for Marketing - Privacy Principles & P...
eMetrics Summit Boston 2014 - Big Data for Marketing - Privacy Principles & P...eMetrics Summit Boston 2014 - Big Data for Marketing - Privacy Principles & P...
eMetrics Summit Boston 2014 - Big Data for Marketing - Privacy Principles & P...
 
eMetrics Summit Boston 2014 - Big Data Marketing - From Über Creepy to Over ...
 eMetrics Summit Boston 2014 - Big Data Marketing - From Über Creepy to Over ... eMetrics Summit Boston 2014 - Big Data Marketing - From Über Creepy to Over ...
eMetrics Summit Boston 2014 - Big Data Marketing - From Über Creepy to Over ...
 
A Framework of Purpose and Consent for Data Security and Consumer Privacy
A Framework of Purpose and Consent for Data Security and Consumer PrivacyA Framework of Purpose and Consent for Data Security and Consumer Privacy
A Framework of Purpose and Consent for Data Security and Consumer Privacy
 
Storm on the Horizon: Data Governance & Security vs. Employee Privacy
Storm on the Horizon: Data Governance & Security vs. Employee PrivacyStorm on the Horizon: Data Governance & Security vs. Employee Privacy
Storm on the Horizon: Data Governance & Security vs. Employee Privacy
 
Privacy & Analytics: Yeti or Snow Fairy?
Privacy & Analytics: Yeti or Snow Fairy?Privacy & Analytics: Yeti or Snow Fairy?
Privacy & Analytics: Yeti or Snow Fairy?
 
Hivos and Responsible Data
Hivos and Responsible DataHivos and Responsible Data
Hivos and Responsible Data
 
Smarter comm"The Future of Privacy". Aurélie Pols at IBM Smarter Commerce Glo...
Smarter comm"The Future of Privacy". Aurélie Pols at IBM Smarter Commerce Glo...Smarter comm"The Future of Privacy". Aurélie Pols at IBM Smarter Commerce Glo...
Smarter comm"The Future of Privacy". Aurélie Pols at IBM Smarter Commerce Glo...
 
A Global Marketer's Guide to Privacy
A Global Marketer's Guide to PrivacyA Global Marketer's Guide to Privacy
A Global Marketer's Guide to Privacy
 
Data Privacy: What you need to know about privacy, from compliance to ethics
Data Privacy: What you need to know about privacy, from compliance to ethicsData Privacy: What you need to know about privacy, from compliance to ethics
Data Privacy: What you need to know about privacy, from compliance to ethics
 
Privacy & Data Ethics
Privacy & Data EthicsPrivacy & Data Ethics
Privacy & Data Ethics
 
Data set Legislation
Data set   Legislation Data set   Legislation
Data set Legislation
 
Privacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital SetupPrivacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital Setup
 
Scotland legal update 25 sept
Scotland legal update   25 septScotland legal update   25 sept
Scotland legal update 25 sept
 
Respect Thy Data: The Gospel
Respect Thy Data: The GospelRespect Thy Data: The Gospel
Respect Thy Data: The Gospel
 
Data set Legislation
Data set LegislationData set Legislation
Data set Legislation
 
Data set Legislation
Data set LegislationData set Legislation
Data set Legislation
 
AI Roles and Risk for election year 2024
AI Roles and Risk for election year 2024AI Roles and Risk for election year 2024
AI Roles and Risk for election year 2024
 
Data set module 4
Data set   module 4Data set   module 4
Data set module 4
 
Ethics in Data Management.pptx
Ethics in Data Management.pptxEthics in Data Management.pptx
Ethics in Data Management.pptx
 
Aurélie Pols en Strata Conference: Digital analytics & privacy - it’s not the...
Aurélie Pols en Strata Conference: Digital analytics & privacy - it’s not the...Aurélie Pols en Strata Conference: Digital analytics & privacy - it’s not the...
Aurélie Pols en Strata Conference: Digital analytics & privacy - it’s not the...
 

Mais de Aurélie Pols

Preparing for the AI Act - 5 years into GDPR enforcement
Preparing for the AI Act - 5 years into GDPR enforcementPreparing for the AI Act - 5 years into GDPR enforcement
Preparing for the AI Act - 5 years into GDPR enforcementAurélie Pols
 
Creative destruction & Privacy Whitewashing: where does risk lie?
Creative destruction & Privacy Whitewashing: where does risk lie? Creative destruction & Privacy Whitewashing: where does risk lie?
Creative destruction & Privacy Whitewashing: where does risk lie? Aurélie Pols
 
ePrivacy Directive, a 10 steps framework to be as compliant as possible for m...
ePrivacy Directive, a 10 steps framework to be as compliant as possible for m...ePrivacy Directive, a 10 steps framework to be as compliant as possible for m...
ePrivacy Directive, a 10 steps framework to be as compliant as possible for m...Aurélie Pols
 
IAPP - Skills For Minimizing Privacy Risk in Data Science Product and Service...
IAPP - Skills For Minimizing Privacy Risk in Data Science Product and Service...IAPP - Skills For Minimizing Privacy Risk in Data Science Product and Service...
IAPP - Skills For Minimizing Privacy Risk in Data Science Product and Service...Aurélie Pols
 
Women in STEM for IE Girl Up Club
Women in STEM for IE Girl Up Club Women in STEM for IE Girl Up Club
Women in STEM for IE Girl Up Club Aurélie Pols
 
For Superweek 2022: discussing risk using IAB's TCF
For Superweek 2022: discussing risk using IAB's TCFFor Superweek 2022: discussing risk using IAB's TCF
For Superweek 2022: discussing risk using IAB's TCFAurélie Pols
 
Interoperability in Digital will take a Global Village
Interoperability in Digital will take a Global VillageInteroperability in Digital will take a Global Village
Interoperability in Digital will take a Global VillageAurélie Pols
 
The GDPR is here. So do you know what the courts are saying?
The GDPR is here. So do you know what the courts are saying?The GDPR is here. So do you know what the courts are saying?
The GDPR is here. So do you know what the courts are saying?Aurélie Pols
 
CPDP: Data ownership, Innovation and Privacy: looking for an approach on both...
CPDP: Data ownership, Innovation and Privacy: looking for an approach on both...CPDP: Data ownership, Innovation and Privacy: looking for an approach on both...
CPDP: Data ownership, Innovation and Privacy: looking for an approach on both...Aurélie Pols
 
GDPR and the aftermath: what are we building towards?
GDPR and the aftermath: what are we building towards?GDPR and the aftermath: what are we building towards?
GDPR and the aftermath: what are we building towards?Aurélie Pols
 
Who Goes There? Demystifying Digital Identity for All (1/2)
Who Goes There? Demystifying Digital Identity for All (1/2)Who Goes There? Demystifying Digital Identity for All (1/2)
Who Goes There? Demystifying Digital Identity for All (1/2)Aurélie Pols
 
Data is the new infrastructure, Privacy is the new green, Trust is the new cu...
Data is the new infrastructure, Privacy is the new green, Trust is the new cu...Data is the new infrastructure, Privacy is the new green, Trust is the new cu...
Data is the new infrastructure, Privacy is the new green, Trust is the new cu...Aurélie Pols
 
How digitization challenges our values as citizens
How digitization challenges our values as citizens How digitization challenges our values as citizens
How digitization challenges our values as citizens Aurélie Pols
 
Technical Consequences of the Data Subject's Rights
Technical Consequences of the Data Subject's RightsTechnical Consequences of the Data Subject's Rights
Technical Consequences of the Data Subject's RightsAurélie Pols
 
From GDPR to ePrivacy: what does it mean to the advertising sector?
From GDPR to ePrivacy: what does it mean to the advertising sector?From GDPR to ePrivacy: what does it mean to the advertising sector?
From GDPR to ePrivacy: what does it mean to the advertising sector?Aurélie Pols
 
State of EU legislation: GDPR & ePrivacy for Superweek
State of EU legislation: GDPR & ePrivacy for SuperweekState of EU legislation: GDPR & ePrivacy for Superweek
State of EU legislation: GDPR & ePrivacy for SuperweekAurélie Pols
 
The Great GDPR MyData Debate - Aurelie Pols - Keynote
The Great GDPR MyData Debate - Aurelie Pols - KeynoteThe Great GDPR MyData Debate - Aurelie Pols - Keynote
The Great GDPR MyData Debate - Aurelie Pols - KeynoteAurélie Pols
 
The Data Subject First? Decoding the GDPR at StrataData
The Data Subject First? Decoding the GDPR at StrataDataThe Data Subject First? Decoding the GDPR at StrataData
The Data Subject First? Decoding the GDPR at StrataDataAurélie Pols
 
Superweek 2016 Would You Lie to Your Physician?
Superweek 2016 Would You Lie to Your Physician?Superweek 2016 Would You Lie to Your Physician?
Superweek 2016 Would You Lie to Your Physician?Aurélie Pols
 
Multi-tasking teams within cyber security departments
Multi-tasking teams within cyber security departmentsMulti-tasking teams within cyber security departments
Multi-tasking teams within cyber security departmentsAurélie Pols
 

Mais de Aurélie Pols (20)

Preparing for the AI Act - 5 years into GDPR enforcement
Preparing for the AI Act - 5 years into GDPR enforcementPreparing for the AI Act - 5 years into GDPR enforcement
Preparing for the AI Act - 5 years into GDPR enforcement
 
Creative destruction & Privacy Whitewashing: where does risk lie?
Creative destruction & Privacy Whitewashing: where does risk lie? Creative destruction & Privacy Whitewashing: where does risk lie?
Creative destruction & Privacy Whitewashing: where does risk lie?
 
ePrivacy Directive, a 10 steps framework to be as compliant as possible for m...
ePrivacy Directive, a 10 steps framework to be as compliant as possible for m...ePrivacy Directive, a 10 steps framework to be as compliant as possible for m...
ePrivacy Directive, a 10 steps framework to be as compliant as possible for m...
 
IAPP - Skills For Minimizing Privacy Risk in Data Science Product and Service...
IAPP - Skills For Minimizing Privacy Risk in Data Science Product and Service...IAPP - Skills For Minimizing Privacy Risk in Data Science Product and Service...
IAPP - Skills For Minimizing Privacy Risk in Data Science Product and Service...
 
Women in STEM for IE Girl Up Club
Women in STEM for IE Girl Up Club Women in STEM for IE Girl Up Club
Women in STEM for IE Girl Up Club
 
For Superweek 2022: discussing risk using IAB's TCF
For Superweek 2022: discussing risk using IAB's TCFFor Superweek 2022: discussing risk using IAB's TCF
For Superweek 2022: discussing risk using IAB's TCF
 
Interoperability in Digital will take a Global Village
Interoperability in Digital will take a Global VillageInteroperability in Digital will take a Global Village
Interoperability in Digital will take a Global Village
 
The GDPR is here. So do you know what the courts are saying?
The GDPR is here. So do you know what the courts are saying?The GDPR is here. So do you know what the courts are saying?
The GDPR is here. So do you know what the courts are saying?
 
CPDP: Data ownership, Innovation and Privacy: looking for an approach on both...
CPDP: Data ownership, Innovation and Privacy: looking for an approach on both...CPDP: Data ownership, Innovation and Privacy: looking for an approach on both...
CPDP: Data ownership, Innovation and Privacy: looking for an approach on both...
 
GDPR and the aftermath: what are we building towards?
GDPR and the aftermath: what are we building towards?GDPR and the aftermath: what are we building towards?
GDPR and the aftermath: what are we building towards?
 
Who Goes There? Demystifying Digital Identity for All (1/2)
Who Goes There? Demystifying Digital Identity for All (1/2)Who Goes There? Demystifying Digital Identity for All (1/2)
Who Goes There? Demystifying Digital Identity for All (1/2)
 
Data is the new infrastructure, Privacy is the new green, Trust is the new cu...
Data is the new infrastructure, Privacy is the new green, Trust is the new cu...Data is the new infrastructure, Privacy is the new green, Trust is the new cu...
Data is the new infrastructure, Privacy is the new green, Trust is the new cu...
 
How digitization challenges our values as citizens
How digitization challenges our values as citizens How digitization challenges our values as citizens
How digitization challenges our values as citizens
 
Technical Consequences of the Data Subject's Rights
Technical Consequences of the Data Subject's RightsTechnical Consequences of the Data Subject's Rights
Technical Consequences of the Data Subject's Rights
 
From GDPR to ePrivacy: what does it mean to the advertising sector?
From GDPR to ePrivacy: what does it mean to the advertising sector?From GDPR to ePrivacy: what does it mean to the advertising sector?
From GDPR to ePrivacy: what does it mean to the advertising sector?
 
State of EU legislation: GDPR & ePrivacy for Superweek
State of EU legislation: GDPR & ePrivacy for SuperweekState of EU legislation: GDPR & ePrivacy for Superweek
State of EU legislation: GDPR & ePrivacy for Superweek
 
The Great GDPR MyData Debate - Aurelie Pols - Keynote
The Great GDPR MyData Debate - Aurelie Pols - KeynoteThe Great GDPR MyData Debate - Aurelie Pols - Keynote
The Great GDPR MyData Debate - Aurelie Pols - Keynote
 
The Data Subject First? Decoding the GDPR at StrataData
The Data Subject First? Decoding the GDPR at StrataDataThe Data Subject First? Decoding the GDPR at StrataData
The Data Subject First? Decoding the GDPR at StrataData
 
Superweek 2016 Would You Lie to Your Physician?
Superweek 2016 Would You Lie to Your Physician?Superweek 2016 Would You Lie to Your Physician?
Superweek 2016 Would You Lie to Your Physician?
 
Multi-tasking teams within cyber security departments
Multi-tasking teams within cyber security departmentsMulti-tasking teams within cyber security departments
Multi-tasking teams within cyber security departments
 

Último

From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .Alan Dix
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
Assure Ecommerce and Retail Operations Uptime with ThousandEyes
Assure Ecommerce and Retail Operations Uptime with ThousandEyesAssure Ecommerce and Retail Operations Uptime with ThousandEyes
Assure Ecommerce and Retail Operations Uptime with ThousandEyesThousandEyes
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 
UiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to HeroUiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to HeroUiPathCommunity
 
2024 April Patch Tuesday
2024 April Patch Tuesday2024 April Patch Tuesday
2024 April Patch TuesdayIvanti
 
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...Wes McKinney
 
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentEmixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentPim van der Noll
 
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality AssuranceInflectra
 
Testing tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examplesTesting tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examplesKari Kakkonen
 
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxPasskey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxLoriGlavin3
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024Lonnie McRorey
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxLoriGlavin3
 
A Framework for Development in the AI Age
A Framework for Development in the AI AgeA Framework for Development in the AI Age
A Framework for Development in the AI AgeCprime
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersNicole Novielli
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsPixlogix Infotech
 
Connecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdfConnecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdfNeo4j
 

Último (20)

From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
Assure Ecommerce and Retail Operations Uptime with ThousandEyes
Assure Ecommerce and Retail Operations Uptime with ThousandEyesAssure Ecommerce and Retail Operations Uptime with ThousandEyes
Assure Ecommerce and Retail Operations Uptime with ThousandEyes
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 
UiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to HeroUiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to Hero
 
2024 April Patch Tuesday
2024 April Patch Tuesday2024 April Patch Tuesday
2024 April Patch Tuesday
 
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
 
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentEmixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
 
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
 
Testing tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examplesTesting tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examples
 
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxPasskey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptx
 
A Framework for Development in the AI Age
A Framework for Development in the AI AgeA Framework for Development in the AI Age
A Framework for Development in the AI Age
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software Developers
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and Cons
 
Connecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdfConnecting the Dots for Information Discovery.pdf
Connecting the Dots for Information Discovery.pdf
 

Data Accountability & Consumer Trust

  • 1. @aureliepols © 2016 Data Accountability & Consumer Trust June 23rd 2016 Aurélie Pols
  • 2. @aureliepols About me: MAD / BRU / SFO 1.  Data Governance & Privacy Advocate for Krux Digital 2.  EAG: Ethics Advisory Group for the European Data Protection Supervisor (EDPS) 3.  Chief Visionary Officer for Mind Your Privacy •  Training Advisory Board, International Association of Privacy Professionals (IAPP) •  Ethics & Privacy professor in Big Data & Analytics Master, Instituto de Empresa (IE) •  [Entrepreneur / Data Scientist? / Privacy Engineer? / Mother] •  (Dutch nationality, French mother tongue, work mostly in English, live in Spain) 2
  • 3. @aureliepols The European Data Protection Supervisor: an independent institution responsible for ensuring the protection of personal data by the EU institutions and bodies The EDPS Giovanni Buttarelli EDPS Wojciech Wiewiórowski Assistant EDPS 3
  • 4. @aureliepols [Entrepreneur / Data Scientist / Privacy Engineer / Mother] 4
  • 5. @aureliepols The Internet grows up; enters Big (& ubiquity of) Data 5 The New Yorker - July 5, 1993 10 years later…
  • 6. @aureliepols Digital Ads & Targeting Online Advertising surpasses TV to record annual spend of €36.2bn DATA load 2.5 quintillion bytes of data are created everyday Perpetually connected consumer } 3 connected devices used per person in 2014 } 9h53m is the average time spent by US adult on connected screens every day Sources : IAB (2016), IBM (2014), Statistica (US, 2014), eMarketer (US, 2015) DATA PRIVACY THE NEW ERA
  • 7. @aureliepols DATA PRIVACY THE PARADOX 65% of consumers do not have confidence in the security of their personal data. 67% are willing to share personal data in exchange for additional services. Source: Accenture
  • 9. @aureliepols Privacy actors within the data ecosystem 9 DATA ECOSYSTEM Citizens Consumers Voters Authorities law + enforcement Companies Businesses DATA QUALITY CLASS ACTIONS AdBlocking COMPLIANCE GDPR Fines: 4% of Global Turn- Over
  • 10. @aureliepols Framing digital data accountability 10 OUR CLIENTS DATA FLOW RESPONSIBLITY DATA CONTROLLER DATA PROCESSOR THEIR CUSTOMERS PRIVACY RIGHTS DATA PROTECTION / SECURITY PRIVACY BY DESIGN (PbD) DATA ETHICS
  • 12. @aureliepols One legal concept to rule them all FTCs Fair Information Practice Principles (FIPPs) Transparency Choice Information review & correction Information protection Accountability 12
  • 13. @aureliepols 13 Comparing global Privacy legislation
  • 14. @aureliepols Purpose, Consent & Data Uses evolution Purpose Consent FIPPs Data for approved use Before Big Data: Purpose Consent FIPPsData analysis or merging New business opportunity Today’s challenge:
  • 15. @aureliepols The devil in the details, for our clients Purpose = Reason for data collection, usually broad •  Website improvement, better UX •  Marketing communication •  Sharing data with 3rd parties Consent •  Types •  Implicit: Opt-in? Double opt-in?; Explicit: Opt-out? •  Depends upon •  Type of data: PII, sensitive data, … •  Type of sector: financial, health, … •  Geography: US vs. EU, Singapore, … 15
  • 16. @aureliepols 16 Privacy legislation kicks in with PII / Personal Data (yet lines are blurring!)
  • 17. @aureliepols General Data Protection Regulation (GPDR) - May 25 2018 GDPR Fines: 4% of Global Turn-Over !!! Which variables or combination exactly? Data types & the law: obligations vary Hashing & encryption (by default) 17
  • 18. @aureliepols Tension between US PII & EU Personal Data Personally Identifiable Information (PII) Personal Data 1.  Name, such as full names, maiden name, mother’s maiden name, or alias; 2.  Personal identification #: social security # (SSN), passport #, driver’s license #, account and credit card #; 3.  Address information: street address or email; 4.  Asset information: Internet Protocol (IP) or Media Access Control (MAC); 5.  Phone #, including mobile, business and personal. Information identifying personally owned property such as vehicle registration # or title # and related information. “Personal data shall mean any information relating to an individual or identifiable natural person (“data subject”); an identifiable person is one who can be identified, directly or indirectly, in particular or by reference to an identification number or to one or more factors specific to his physical, mental, economic, cultural or social identity” Based on the definition commonly used by most US States Directive 95/46/EC, the Data Protection Directive
  • 19. @aureliepols De-identification is a compliance exercise From Shades of Grey: Seeing the full spectrum of Practical Data De-Identification by Jules Polonetsky, Omer Tene & Kelsey Finch, April 1st 2016, http://papers.ssrn.com/sol3/papers.cfm?abstract_id=2757709 19
  • 20. @aureliepols Identification capabilities is a TRUST issue From Data Privacy: Understanding Privacy principles and ensuring compliance of your digital activities by Aurélie Pols for AT Internet, May 2016 20
  • 21. @aureliepols Moving beyond the divide: Digital Ethics •  Layer approach for data driven companies: Privacy Engineering by Krux •  Promise to our clients’ clients: TRUST •  Bare minimum: Compliance! VALUE / ETHICS Respect individuals Corporate Social Responsibility RISK Do not harm Standard Operating Procedure COMPLIANCE Don’t hit people! Legislation ETHICS PROCESS LAW
  • 22. @aureliepols For Krux, this means 22 ü Assuring compliance & limiting risk for Krux ü Assuring our clients’ data uses are compliant with legislations they address + global platform !!! ü Leveraging the data to allow our clients to make ethical decisions about their data uses
  • 23. @aureliepols 23 Evolving Privacy legislation (short term)
  • 24. @aureliepols Old and new EU Privacy rules STABLE EU PRIVACY LEGISLATION SafeHarbor for international transfers of personal data EU Data Protection Directive (95/46/EC) regulates personal data within the EU EU ePrivacy Directive* on Privacy & Electronic Communication – think cookies! * (2002/58/EC amended 2006/24/EC & 2009/136/EC) FUTURE EU PRIVACY LEGISLATION PrivacyShield strong enough? EU General Data Protection Regulation (GDPR) strengthens & unifies data protection for EU citizens Revision of the ePrivacy Directive à Regulation? Confidentiality for all communications (Skype, WhatsApp, …) + strengthen consent rules? May 25 2018 Draft December 2016: EU DNT?
  • 25. @aureliepols Data Privacy laws globally? Blue = Strong Privacy legislation - Green = Moderate - Orange = Limited ?? 25 Data Balkanization vs. UN Globalization effort Joe Cannataci UN Special Rapporteur Privacy in the Digital Age
  • 27. @aureliepols Competing on Privacy? •  Increased non compliance risk for the data industry •  Clients will require: ü Guidance ü Documentation ü Features Privacy Engineering by Krux 27
  • 28. @aureliepols For Krux, this means 28 ü Assuring compliance & limiting risk for Krux ü Assuring our clients’ data uses are compliant with legislations they address + global platform !!! ü Leveraging the data to allow our clients to make ethical decisions about their data uses
  • 30. @aureliepols DOs 1.  Define your role with the Data Ecosystem 2.  Keep metadata on Purpose and Consent* 3.  Undergo Privacy Impact/Risk Assessments (PIAs) for §  Product Launches §  (new) Data Uses 4.  Document Data Flows 5.  Keep data clean & to a minimum: data retention & breach notifications * Unless anonymization today, not tomorrow!!! 30
  • 31. @aureliepols DON’Ts* 1.  Break the Consent chain 2.  Disrespect Customer Expectations 3.  Sell personal data without Consent 4.  Buy data without understanding Purpose 5.  Enrich data without understanding previous rules •  Unless anonymization today, not tomorrow 31
  • 32. @aureliepols Ethics of the data analyst 32 I shall remember data are not only numbers but actual people, that could be harmed by my work; I shall treat data that might identify individuals with the utmost care, which includes respect for their dignity, avoiding discrimination, as well as security best practices; I will not do to personal data what I wouldn’t find acceptable for data related to my family, friends, loved ones or myself; I understand personal data, PII &/or sensitive data is context based and often difficult to identify. In case of doubt, I will ask for help or escalate in order to take the appropriate measures; I understand data about individuals needs to travel with initial purpose of the data – the reason why it exists - & their respective consent mechanisms; a)  I will never use data without knowing where it comes from, it’s purpose and consent mechanisms (see Quién es la Última Principle); b)  I will never sell non consented data about individuals; c)  If I sell consented data, it will be accompanied by purpose. Up to the buyer to define whether subsequent data uses are aligned. I understand consent might be revoked and a Right to be Forgotten – i.e. deletion – could be requested, that might need to be applied; I shall align security protocols with how personal &/or sensitive the data is; I will keep trace and document the data used in order to minimize risk related to data uses.
  • 33. @aureliepolsDigital Intelligence Solutions DATA IS TRANSFORMING OUR VERY LIVES PRESERVATION OF HUMAN DIGNITY IS AT STAKE
  • 34. @aureliepols Gracias / Merci / Danke Schön / Bedankt / ‫תודה‬ / ευχαριστίες krux.com apols@krux.com