SlideShare uma empresa Scribd logo
1 de 44
GDPR and IoT:
What do you need to know?
IoT Guildford Meetup
February 27th, Guildford
Michele Nati
Lead Technologist for Digital Trust
Digital Catapult, London
@michelenati
https://www.linkedin.com/in/michelenati/
House keeping
• Need to increase participation
• Rewards participants, hosts, speakers
• Reputation based ecosystem
• Community Engagement List (CEL)
• ERC20 token to build meetup-ers reputation
CEL Token
https://etherscan.io/token/0x662bA51F62591830CD380a7A9bEB23
2DbD7a92a4#balances
Disclaimer:
I am oversimplifying and giving
my personal interpretation!!
What is GDPR?
A regulation for the treatment of personal
data in Europe, superseding previous
DPA (in force on May 25th 2018, after a two
years grace period)
Whose personal data: All EU citizen
Who has to comply: All organizations
processing data of EU citizens
Personal Data – WTF?
According to GDPR: ‘Personal data’ means any information
relating to an identified or identifiable natural person (‘data
subject’); an identifiable natural person is one who can be
identified, directly or indirectly, in particular by reference to an
identifier such as a name, an identification number, location
data, an online identifier or to one or more factors specific to the
physical, physiological, genetic, mental, economic, cultural or
social identity of that natural person
IoT data are most likely personal
• If in doubt, be conservative!
Data Protection basics
Data Subject: the person whom data are collected
and processed for the provisioning of a service
Data Controller: who sets the purpose of the
processing (either collected directly or acquired
from other sources)
Data Processor: who processes the data for the
purpose of providing a service (might be the same
as the Controller)
The Data Economy:
The opportunity
• More companies are
embracing digital
transformation
• With more data used to:
• Improve in Artificial Intelligence and
Machine Learning algorithms
• Deliver more personalised services
and attract new customers
• With IoT increasing
availability of data
• Most of them being personal
First:
Know Your Customers
GDPR: Transparency
Article 12-14, Information notice
concise, transparent, intelligible and easily
accessible” and “clear and in plain language
• Should avoid information fatigue
• Name the recipients of personal data
• Keep up-to-date
IoT Challenges
Some concepts might be difficult to convey
• Privacy Policies complexity > automated
decision
• Layered privacy policy
• Unlikely names of the recipients but
detailed categories
• How to maintain this dynamic and personalised?
• Exceptions might exist
GDPR: Accountability
Article 4 and 7, Consent
Consent would not legitimise collection of data which is not necessary
in relation…
Other legal basis: performance of a contract, legal obligation,
legitimate interest
“any freely given, specific, informed and unambiguous indication of
the data subject’s wishes by which he or she, by a statement or by a
clear affirmative action, signifies agreement to the processing of
personal data relating to him or her“
Consent requirements
Freely given
• Cannot prevent the provisioning of a service
• No data for free app
Specific
• For different data and purpose, and different
recipients
Informed
An unambiguous indication of wishes
• No pre-ticked boxes, no opt-out
Explicit Consent
• Sensitive data
Proof of consent and possibility to remove
How to manage consent:
Solutions Landscape
Consent
Management
Platforms
PIMSTransparency
(e.g.,PDRs)
Service ProvisioningCustomer on-boarding
Standards
IoT Challenges
• How to obtain consent through IoT
device?
• How to remove consent through IoT
device?
• How to keep consent updated?
• E.g. triggering new sensors, collecting new data
• How to obtain consent in shared
space? Or for shared devices? (cars,
home assistants)
GDPR: Level of control
Article 17-19
The right to be informed -> provide information notice
The right of access -> free of charge, within a month
The right to rectification -> within one (or two months)
The right to erasure -> some exceptions are possible
The right to restrict processing -> retain information but stop
processing
The right to data portability -> free of charge, within a month, no
hindrance
The right to object -> marketing and research unless legal basis
Rights in relation to automated decision making and profiling.
IoT Challenges
• Need to know all the collected data
• Be able to link data from different data
sources
• Track who you shared the data with
• Track and keep up to date retention
period
• Interoperable, machine-readable
formats
The risks for IoT
• Understand what data are personal
• You are most likely profiling your
customers (tell them) - Article
• You are most likely combining data
• Do you know where this data comes and how you obtained them?
(Consent)
• Is there risk of de-anonymization?
How to build Digital Trust
Measureable
properties
TrustworthinessTrust
- Transparency
(Article 12-14,
Information notice)
- Accountability
(Article 4 and 7,
Consent)
- Level of Control
(Article 17-19, Data
erasure and
portability)
Example
The case of
transparency
The transparency risk
• Consumers are
becoming savvy
• And demands for trustworthy apps
(33%), with simple privacy
statements (source: MEF Consumer
Trust Report 2017)
• While hidden business
models and lack of
transparency might
hinder this growth
Measurable transparency
Transparency
TrustworthinessTrust
First step:
Transparency
Savvy consumers demand
• Simple privacy
statements
• Clarity on collected
data and access to
them
• Better user
experience
- Transparency
(Article 12-14,
Information notice)
Transparency today
Consumers pain points
• Lie & Agree
• Takes too long to read and
understand
• Want to access the service
• (Often) No choice offered
• Agree & Forget
• Lack of record
• Difficult to retrieve
• Static information
• Lack of interaction
How to redesign
Privacy Policies?
Problem Statement: How to increase consumers’ trust and
businesses’ transparency by developing a GDPR compliant solution
that takes into account the user experience and help to reduce
consumers pain points and organizations compliance burden related
to the provisioning of digital services using personal data?
Personal Data Receipts (PDRs), a human-readable record
summarizing in a simple and clear way what personal data an
organization is collecting about an individual, for what purpose, how
they are stored and for how long and if any third party sharing is
allowed.
Personal Data Receipts
• How it was built
• Multidisciplinary team: UX lead, Marketing expert,
Tech Lead, Lawyer
• Customer-centric approach
• Transparency can be measured, ASK
the Customers
• The categories of data
• The purpose, including 3rd party sharing
• The where, how and how long
• The contact details of the Data Controller
• What else consumers wants
• Simple, non technical, plain text
• Icons only as support
PDRs and GDPR compliance
• Article 12-14, Information notice
• Use of icons and simple text to explain: what, how and for what
purpose
• (could be personalized to target different demographic groups)
• Article 4 and 7, Consent
• Includes data collected under consent
• Provides a record for both individual and organization
• Article 17-19, Data erasure and
portability
• Provides a direct channel with the contact Data Controller
• Educates business to discover their customers data (in particular
IoT and third parties) and simplify cascade updates
• Privacy by Design and DPIA
PDRs: The benefits
For individuals (“Savvy consumers”):
• Privacy Policies become human and simplified
• Track and control on personal data sharing is simplified (and
possible!!)
• Reassurance that data will not end in the wrong hands is
possible (3rd party sharing highlighted)
Services and apps become more trustworthy and
more data are shared with more control
For organizations:
• Attitude to personal data become user-centric
• Open new personal comm channel with their uses
Consumers trust increases and churn is avoided,
while more data are accessed
Where are PDRs are useful:
Patient data collection
BMS Backend
PDR
Hospital/Imaging
Centres
Visitor
BMS
website
Data Collected →
← Response
PostgreSQL
Booking Confirmation
NEW PDR
Application
Data Points for
PDR:
Email, Full Name,
DoB, Phone
Number, Address,
Post Code
Added possibility
to manage
individual rights
Want to know more?
• White paper available in March
• Recommendations and blueprint on
how integrate PDRs
• Templates for PDRs available
Advanced Topics
Artificial intelligence
GDPR and AI Transparency
Article 4 (4) & 22 - Automate decision making and profiling
1. is either provided by the law, such as in the case of fraud prevention
or money laundering checks,
2. or is necessary for the performance of or entering into a contract,
3. or is based on the individual’s prior consent
This requires to explain:
1. the usage of such technologies;
2. the significance and envisaged consequences for the individual; and
3. “meaningful information about the logic involved“
This is a challenge not only for IoT data
AI: Transparency challenges
• Algorithms are becoming too complex
• In particular when using Deep Learning
• Not easy to explain to general public
• Privacy Policies are statics and might need to evolve as the algorithms evolve or
the subject change (PDRs can help instead)
• You want to protect IP of your model
• You can try to:
• Give access to the data you use as input
• Tell how many see the same as you, show fairness (lack of bias in training sets)
Be careful using AI
• Research?
• Be careful with anonymization
• Personalised service?
• Ask for consent and maintain pseudonimity
• Want more efficiency? Combine more data?
• Be transparent, Ask consent, Don’t share
Always be transparent about use of AI and
ask for consent
The complexity of AI
ecosystem
Individuals (Data Subjects)
Algorithm
Controllers
(Data
Controllers
)
Algorithm
Executors
(Data
Processors
)
Algorithm
Creators
The role of AI Governance
Case Study
Blockchain and GDPR
Blockchain properties
• Transactional data are personal
• Anonymization -> Hashing is not anonymization
• Pseudonymization -> Keys are not anonymous
• Unpermissioned vs permissioned
• Decentralized network, who runs it?
• Append-only
• High-redundancy of data
GDRP compliance
• Personal data
• What data to store?
• Jurisdiction
• Who is the data controller?
• Digital rights enforcement
• Minimization?
• Erasure?
• Update? What update means?
• Access request? To who?
• Possible solutions?
• Think about your network first
• Think about what you store
• Consider off-chain data store, store consent but consider carefully meta-data
Other things to consider
Data breaches
• Report within 72 hours (in UK to the ICO)
• Communicate to data subject
• Require to map data (including processors)
Privacy by Design and DPIA
• Risk-based approach
• Might result difficult in case of HW and SW
• Lawyers, with DPO and CIO
Data Retention
• Pre-determined, explicit
• For the duration of the service
• Need frequent review
Get involved
• Resolve more
consumers and
businesses
tensions
• Risk of cybercrime
• Lack of control
• Fear of surveillance
• Identify achievable
trustworthy
measures
• Stimulate debate, Generate
recommendation for EU
• Co-create a DTRL (Digital
Trust Readiness Level)
https://truessec.eu
Other resources – initiatives
IoT Mark: https://iotmark.wordpress.com
Recommendation and a mark for SMEs
IoTSF: https://iotsecurityfoundation.org
Focus on security of IoT systems
Tech Lawyer interpretation: http://www.gamingtechlaw.com
ICO recommendations: https://ico.org.uk/for-organisations/guide-
to-the-general-data-protection-regulation-gdpr/
Digital Catapult workshop:
https://www.eventbrite.co.uk/e/innovation-opportunity-of-the-gdpr-
for-ai-and-ml-workshop-registration-42793145450
EU Recommendations –
Article WP29
Article 29 WP on Consent:
https://iapp.org/media/pdf/resource_center/wp29_consent
-12-12-17.pdf
Article 29 WP on Transparency:
https://iapp.org/media/pdf/resource_center/wp29-
transparency-12-12-17.pdf
Article 29 WP on Data Portability:
https://iapp.org/media/pdf/resource_center/WP29-2017-
04-data-portability-guidance.pdf
THANK YOU!
#DigiCatapult
info@digicatapult.org.uk
0300 1233 101
Digital Catapult
digicatapult.org.uk
/DigitalCatapult
@DigitalCatapult
Questions?

Mais conteúdo relacionado

Mais procurados

security in wireless sensor networks
security in wireless sensor networkssecurity in wireless sensor networks
security in wireless sensor networks
Vishnu Kudumula
 

Mais procurados (20)

Application Layer Protocols for the IoT
Application Layer Protocols for the IoTApplication Layer Protocols for the IoT
Application Layer Protocols for the IoT
 
Security Issues in MANET
Security Issues in MANETSecurity Issues in MANET
Security Issues in MANET
 
Multicast routing protocols in adhoc networks
Multicast routing protocols in adhoc networksMulticast routing protocols in adhoc networks
Multicast routing protocols in adhoc networks
 
Attacks in MANET
Attacks in MANETAttacks in MANET
Attacks in MANET
 
Security in wireless sensor network
Security in wireless sensor networkSecurity in wireless sensor network
Security in wireless sensor network
 
Unit 4 -2 energy management in adhoc wireless network
Unit 4 -2 energy management in adhoc wireless networkUnit 4 -2 energy management in adhoc wireless network
Unit 4 -2 energy management in adhoc wireless network
 
CS6010 Social Network Analysis Unit V
CS6010 Social Network Analysis Unit VCS6010 Social Network Analysis Unit V
CS6010 Social Network Analysis Unit V
 
Zone Routing Protocol
Zone Routing ProtocolZone Routing Protocol
Zone Routing Protocol
 
Software agents
Software agentsSoftware agents
Software agents
 
Beginners: Multi-SIM Operation
Beginners: Multi-SIM OperationBeginners: Multi-SIM Operation
Beginners: Multi-SIM Operation
 
security in wireless sensor networks
security in wireless sensor networkssecurity in wireless sensor networks
security in wireless sensor networks
 
Black hole attack
Black hole attackBlack hole attack
Black hole attack
 
Security of ad hoc networks
Security of ad hoc networksSecurity of ad hoc networks
Security of ad hoc networks
 
energy efficient unicast
energy efficient unicastenergy efficient unicast
energy efficient unicast
 
Checkpointing.pptx
Checkpointing.pptxCheckpointing.pptx
Checkpointing.pptx
 
Map your Bimodal IT
Map your Bimodal ITMap your Bimodal IT
Map your Bimodal IT
 
Wireless Sensor Network Security
Wireless Sensor Network  Security Wireless Sensor Network  Security
Wireless Sensor Network Security
 
Ike A 5G Private Networks PNI-NPN/SNPN LF Edge Akraino Technical Meeting Spri...
Ike A 5G Private Networks PNI-NPN/SNPN LF Edge Akraino Technical Meeting Spri...Ike A 5G Private Networks PNI-NPN/SNPN LF Edge Akraino Technical Meeting Spri...
Ike A 5G Private Networks PNI-NPN/SNPN LF Edge Akraino Technical Meeting Spri...
 
Wormhole attack
Wormhole attackWormhole attack
Wormhole attack
 
Firewall presentation
Firewall presentationFirewall presentation
Firewall presentation
 

Semelhante a GDPR and IoT: What do you need to know?

General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
GrittyCC
 
ISSA Atlanta - Emerging application and data protection for multi cloud
ISSA Atlanta - Emerging application and data protection for multi cloudISSA Atlanta - Emerging application and data protection for multi cloud
ISSA Atlanta - Emerging application and data protection for multi cloud
Ulf Mattsson
 

Semelhante a GDPR and IoT: What do you need to know? (20)

Building Consumers Trust: The role of transparency and control
Building Consumers Trust: The role of transparency and controlBuilding Consumers Trust: The role of transparency and control
Building Consumers Trust: The role of transparency and control
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charities
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
Personal Data Receipts - Michele Nati - Lead Technologist Privacy and Trust -...
Personal Data Receipts - Michele Nati - Lead Technologist Privacy and Trust -...Personal Data Receipts - Michele Nati - Lead Technologist Privacy and Trust -...
Personal Data Receipts - Michele Nati - Lead Technologist Privacy and Trust -...
 
Data Residency: Challenges and the Need for Standards
Data Residency: Challenges and the Need for StandardsData Residency: Challenges and the Need for Standards
Data Residency: Challenges and the Need for Standards
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
What is GDPR and why does it matter to me?
What is GDPR and why does it matter to me? What is GDPR and why does it matter to me?
What is GDPR and why does it matter to me?
 
The Rise of Data Ethics and Security - AIDI Webinar
The Rise of Data Ethics and Security - AIDI WebinarThe Rise of Data Ethics and Security - AIDI Webinar
The Rise of Data Ethics and Security - AIDI Webinar
 
ZyLAB ACEDS Webinar- GDPR
ZyLAB ACEDS Webinar- GDPR ZyLAB ACEDS Webinar- GDPR
ZyLAB ACEDS Webinar- GDPR
 
Bridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and RetentionBridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and Retention
 
Smart_cities_and_sustainability_Korpisaari.pdf
Smart_cities_and_sustainability_Korpisaari.pdfSmart_cities_and_sustainability_Korpisaari.pdf
Smart_cities_and_sustainability_Korpisaari.pdf
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
GDPR Part 1: Quick Facts
GDPR Part 1: Quick FactsGDPR Part 1: Quick Facts
GDPR Part 1: Quick Facts
 
National Volunteering Forum: May18
National Volunteering Forum: May18National Volunteering Forum: May18
National Volunteering Forum: May18
 
GDPR and Blockchain
GDPR and BlockchainGDPR and Blockchain
GDPR and Blockchain
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulations
 
ISSA Atlanta - Emerging application and data protection for multi cloud
ISSA Atlanta - Emerging application and data protection for multi cloudISSA Atlanta - Emerging application and data protection for multi cloud
ISSA Atlanta - Emerging application and data protection for multi cloud
 
Smart Data Module 5 d drive_legislation
Smart Data Module 5 d drive_legislationSmart Data Module 5 d drive_legislation
Smart Data Module 5 d drive_legislation
 

Mais de MicheleNati

Mais de MicheleNati (20)

Trust in the age of blockchain
Trust in the age of blockchainTrust in the age of blockchain
Trust in the age of blockchain
 
Transparency Matters: Building trust into IoT
Transparency Matters: Building trust into IoTTransparency Matters: Building trust into IoT
Transparency Matters: Building trust into IoT
 
IoT Guildford Meetup#27: EU H2020 F-Interop project open call
IoT Guildford Meetup#27: EU H2020 F-Interop project open callIoT Guildford Meetup#27: EU H2020 F-Interop project open call
IoT Guildford Meetup#27: EU H2020 F-Interop project open call
 
IoT Guildford Meetup#27: EU H2020 TagItSmart Open Call
IoT Guildford Meetup#27: EU H2020 TagItSmart Open CallIoT Guildford Meetup#27: EU H2020 TagItSmart Open Call
IoT Guildford Meetup#27: EU H2020 TagItSmart Open Call
 
IoT Guildford Meetup#26: GDPR, IoT and Transparency
IoT Guildford Meetup#26: GDPR, IoT and TransparencyIoT Guildford Meetup#26: GDPR, IoT and Transparency
IoT Guildford Meetup#26: GDPR, IoT and Transparency
 
IoTMeetupGuildford#20: Nick Grove, Payments & Rewards Made Eazsy, Peazzy
IoTMeetupGuildford#20: Nick Grove, Payments & Rewards Made Eazsy, PeazzyIoTMeetupGuildford#20: Nick Grove, Payments & Rewards Made Eazsy, Peazzy
IoTMeetupGuildford#20: Nick Grove, Payments & Rewards Made Eazsy, Peazzy
 
IoTMeetupGuildford#20: Michele Nati, Personal data and Blockchain: Opportunit...
IoTMeetupGuildford#20: Michele Nati, Personal data and Blockchain: Opportunit...IoTMeetupGuildford#20: Michele Nati, Personal data and Blockchain: Opportunit...
IoTMeetupGuildford#20: Michele Nati, Personal data and Blockchain: Opportunit...
 
Personal data and blockchain: Opportunities and Challenges - Michele Nati - L...
Personal data and blockchain: Opportunities and Challenges - Michele Nati - L...Personal data and blockchain: Opportunities and Challenges - Michele Nati - L...
Personal data and blockchain: Opportunities and Challenges - Michele Nati - L...
 
Consent Receipts: The Future of Personal Data - Michele Nati - Lead Technolog...
Consent Receipts: The Future of Personal Data - Michele Nati - Lead Technolog...Consent Receipts: The Future of Personal Data - Michele Nati - Lead Technolog...
Consent Receipts: The Future of Personal Data - Michele Nati - Lead Technolog...
 
IoTMeetupGuildford#19: Michele Nati, Boosting IoT interoperability, F-Interop...
IoTMeetupGuildford#19: Michele Nati, Boosting IoT interoperability, F-Interop...IoTMeetupGuildford#19: Michele Nati, Boosting IoT interoperability, F-Interop...
IoTMeetupGuildford#19: Michele Nati, Boosting IoT interoperability, F-Interop...
 
IoTMeetupGuildford#19: Stelios Georgoulas, Smart Tag for Unlocking Business p...
IoTMeetupGuildford#19: Stelios Georgoulas, Smart Tag for Unlocking Business p...IoTMeetupGuildford#19: Stelios Georgoulas, Smart Tag for Unlocking Business p...
IoTMeetupGuildford#19: Stelios Georgoulas, Smart Tag for Unlocking Business p...
 
IoTMeetupGuildford#15: Steven Clarke - Generate revenue from energy intensiv...
IoTMeetupGuildford#15: Steven Clarke - Generate revenue from energy  intensiv...IoTMeetupGuildford#15: Steven Clarke - Generate revenue from energy  intensiv...
IoTMeetupGuildford#15: Steven Clarke - Generate revenue from energy intensiv...
 
Michele Nati - Digital Catapult viewpoint on Industrie 4.0 - Digital Technolo...
Michele Nati - Digital Catapult viewpoint on Industrie 4.0 - Digital Technolo...Michele Nati - Digital Catapult viewpoint on Industrie 4.0 - Digital Technolo...
Michele Nati - Digital Catapult viewpoint on Industrie 4.0 - Digital Technolo...
 
IoTMeetupGuildford#14: Mark Hill - http://thethingsnetwork.org - OpenTRV
IoTMeetupGuildford#14: Mark Hill - http://thethingsnetwork.org - OpenTRVIoTMeetupGuildford#14: Mark Hill - http://thethingsnetwork.org - OpenTRV
IoTMeetupGuildford#14: Mark Hill - http://thethingsnetwork.org - OpenTRV
 
UNICOM Conference on Digital Transformation - The Trust Framework Initiative ...
UNICOM Conference on Digital Transformation - The Trust Framework Initiative ...UNICOM Conference on Digital Transformation - The Trust Framework Initiative ...
UNICOM Conference on Digital Transformation - The Trust Framework Initiative ...
 
IoTMeetupGuildford#13: Michele Nati - Open Innovation in the UK - Digital Cat...
IoTMeetupGuildford#13: Michele Nati - Open Innovation in the UK - Digital Cat...IoTMeetupGuildford#13: Michele Nati - Open Innovation in the UK - Digital Cat...
IoTMeetupGuildford#13: Michele Nati - Open Innovation in the UK - Digital Cat...
 
IoTMeetupGuildford#13: Michael Caste - Finding a business model for IoT
IoTMeetupGuildford#13: Michael Caste - Finding a business model for IoTIoTMeetupGuildford#13: Michael Caste - Finding a business model for IoT
IoTMeetupGuildford#13: Michael Caste - Finding a business model for IoT
 
Collaborative Working @ Digital Catapult - Digital Catapult - Michele Nati
Collaborative Working @ Digital Catapult - Digital Catapult - Michele NatiCollaborative Working @ Digital Catapult - Digital Catapult - Michele Nati
Collaborative Working @ Digital Catapult - Digital Catapult - Michele Nati
 
Open Innovation in the UK - Digital Catapult - Michele Nati
Open Innovation in the UK - Digital Catapult - Michele NatiOpen Innovation in the UK - Digital Catapult - Michele Nati
Open Innovation in the UK - Digital Catapult - Michele Nati
 
IoTMeetupGuildford#12: James Moulding - OpenSensors.io - OpenSensors.io
IoTMeetupGuildford#12: James Moulding - OpenSensors.io - OpenSensors.ioIoTMeetupGuildford#12: James Moulding - OpenSensors.io - OpenSensors.io
IoTMeetupGuildford#12: James Moulding - OpenSensors.io - OpenSensors.io
 

Último

Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Victor Rentea
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Victor Rentea
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Último (20)

ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Cyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfCyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdf
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 

GDPR and IoT: What do you need to know?

  • 1. GDPR and IoT: What do you need to know? IoT Guildford Meetup February 27th, Guildford Michele Nati Lead Technologist for Digital Trust Digital Catapult, London @michelenati https://www.linkedin.com/in/michelenati/
  • 2. House keeping • Need to increase participation • Rewards participants, hosts, speakers • Reputation based ecosystem • Community Engagement List (CEL) • ERC20 token to build meetup-ers reputation
  • 4. Disclaimer: I am oversimplifying and giving my personal interpretation!!
  • 5. What is GDPR? A regulation for the treatment of personal data in Europe, superseding previous DPA (in force on May 25th 2018, after a two years grace period) Whose personal data: All EU citizen Who has to comply: All organizations processing data of EU citizens
  • 6. Personal Data – WTF? According to GDPR: ‘Personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person IoT data are most likely personal • If in doubt, be conservative!
  • 7. Data Protection basics Data Subject: the person whom data are collected and processed for the provisioning of a service Data Controller: who sets the purpose of the processing (either collected directly or acquired from other sources) Data Processor: who processes the data for the purpose of providing a service (might be the same as the Controller)
  • 8. The Data Economy: The opportunity • More companies are embracing digital transformation • With more data used to: • Improve in Artificial Intelligence and Machine Learning algorithms • Deliver more personalised services and attract new customers • With IoT increasing availability of data • Most of them being personal
  • 10. GDPR: Transparency Article 12-14, Information notice concise, transparent, intelligible and easily accessible” and “clear and in plain language • Should avoid information fatigue • Name the recipients of personal data • Keep up-to-date
  • 11. IoT Challenges Some concepts might be difficult to convey • Privacy Policies complexity > automated decision • Layered privacy policy • Unlikely names of the recipients but detailed categories • How to maintain this dynamic and personalised? • Exceptions might exist
  • 12. GDPR: Accountability Article 4 and 7, Consent Consent would not legitimise collection of data which is not necessary in relation… Other legal basis: performance of a contract, legal obligation, legitimate interest “any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her“
  • 13. Consent requirements Freely given • Cannot prevent the provisioning of a service • No data for free app Specific • For different data and purpose, and different recipients Informed An unambiguous indication of wishes • No pre-ticked boxes, no opt-out Explicit Consent • Sensitive data Proof of consent and possibility to remove
  • 14. How to manage consent: Solutions Landscape Consent Management Platforms PIMSTransparency (e.g.,PDRs) Service ProvisioningCustomer on-boarding Standards
  • 15. IoT Challenges • How to obtain consent through IoT device? • How to remove consent through IoT device? • How to keep consent updated? • E.g. triggering new sensors, collecting new data • How to obtain consent in shared space? Or for shared devices? (cars, home assistants)
  • 16. GDPR: Level of control Article 17-19 The right to be informed -> provide information notice The right of access -> free of charge, within a month The right to rectification -> within one (or two months) The right to erasure -> some exceptions are possible The right to restrict processing -> retain information but stop processing The right to data portability -> free of charge, within a month, no hindrance The right to object -> marketing and research unless legal basis Rights in relation to automated decision making and profiling.
  • 17. IoT Challenges • Need to know all the collected data • Be able to link data from different data sources • Track who you shared the data with • Track and keep up to date retention period • Interoperable, machine-readable formats
  • 18. The risks for IoT • Understand what data are personal • You are most likely profiling your customers (tell them) - Article • You are most likely combining data • Do you know where this data comes and how you obtained them? (Consent) • Is there risk of de-anonymization?
  • 19. How to build Digital Trust Measureable properties TrustworthinessTrust - Transparency (Article 12-14, Information notice) - Accountability (Article 4 and 7, Consent) - Level of Control (Article 17-19, Data erasure and portability)
  • 21. The transparency risk • Consumers are becoming savvy • And demands for trustworthy apps (33%), with simple privacy statements (source: MEF Consumer Trust Report 2017) • While hidden business models and lack of transparency might hinder this growth
  • 22. Measurable transparency Transparency TrustworthinessTrust First step: Transparency Savvy consumers demand • Simple privacy statements • Clarity on collected data and access to them • Better user experience - Transparency (Article 12-14, Information notice)
  • 24. Consumers pain points • Lie & Agree • Takes too long to read and understand • Want to access the service • (Often) No choice offered • Agree & Forget • Lack of record • Difficult to retrieve • Static information • Lack of interaction
  • 25. How to redesign Privacy Policies? Problem Statement: How to increase consumers’ trust and businesses’ transparency by developing a GDPR compliant solution that takes into account the user experience and help to reduce consumers pain points and organizations compliance burden related to the provisioning of digital services using personal data? Personal Data Receipts (PDRs), a human-readable record summarizing in a simple and clear way what personal data an organization is collecting about an individual, for what purpose, how they are stored and for how long and if any third party sharing is allowed.
  • 26. Personal Data Receipts • How it was built • Multidisciplinary team: UX lead, Marketing expert, Tech Lead, Lawyer • Customer-centric approach • Transparency can be measured, ASK the Customers • The categories of data • The purpose, including 3rd party sharing • The where, how and how long • The contact details of the Data Controller • What else consumers wants • Simple, non technical, plain text • Icons only as support
  • 27. PDRs and GDPR compliance • Article 12-14, Information notice • Use of icons and simple text to explain: what, how and for what purpose • (could be personalized to target different demographic groups) • Article 4 and 7, Consent • Includes data collected under consent • Provides a record for both individual and organization • Article 17-19, Data erasure and portability • Provides a direct channel with the contact Data Controller • Educates business to discover their customers data (in particular IoT and third parties) and simplify cascade updates • Privacy by Design and DPIA
  • 28. PDRs: The benefits For individuals (“Savvy consumers”): • Privacy Policies become human and simplified • Track and control on personal data sharing is simplified (and possible!!) • Reassurance that data will not end in the wrong hands is possible (3rd party sharing highlighted) Services and apps become more trustworthy and more data are shared with more control For organizations: • Attitude to personal data become user-centric • Open new personal comm channel with their uses Consumers trust increases and churn is avoided, while more data are accessed
  • 29. Where are PDRs are useful: Patient data collection BMS Backend PDR Hospital/Imaging Centres Visitor BMS website Data Collected → ← Response PostgreSQL Booking Confirmation NEW PDR Application Data Points for PDR: Email, Full Name, DoB, Phone Number, Address, Post Code Added possibility to manage individual rights
  • 30. Want to know more? • White paper available in March • Recommendations and blueprint on how integrate PDRs • Templates for PDRs available
  • 32. GDPR and AI Transparency Article 4 (4) & 22 - Automate decision making and profiling 1. is either provided by the law, such as in the case of fraud prevention or money laundering checks, 2. or is necessary for the performance of or entering into a contract, 3. or is based on the individual’s prior consent This requires to explain: 1. the usage of such technologies; 2. the significance and envisaged consequences for the individual; and 3. “meaningful information about the logic involved“ This is a challenge not only for IoT data
  • 33. AI: Transparency challenges • Algorithms are becoming too complex • In particular when using Deep Learning • Not easy to explain to general public • Privacy Policies are statics and might need to evolve as the algorithms evolve or the subject change (PDRs can help instead) • You want to protect IP of your model • You can try to: • Give access to the data you use as input • Tell how many see the same as you, show fairness (lack of bias in training sets)
  • 34. Be careful using AI • Research? • Be careful with anonymization • Personalised service? • Ask for consent and maintain pseudonimity • Want more efficiency? Combine more data? • Be transparent, Ask consent, Don’t share Always be transparent about use of AI and ask for consent
  • 35. The complexity of AI ecosystem Individuals (Data Subjects) Algorithm Controllers (Data Controllers ) Algorithm Executors (Data Processors ) Algorithm Creators
  • 36. The role of AI Governance
  • 38. Blockchain properties • Transactional data are personal • Anonymization -> Hashing is not anonymization • Pseudonymization -> Keys are not anonymous • Unpermissioned vs permissioned • Decentralized network, who runs it? • Append-only • High-redundancy of data
  • 39. GDRP compliance • Personal data • What data to store? • Jurisdiction • Who is the data controller? • Digital rights enforcement • Minimization? • Erasure? • Update? What update means? • Access request? To who? • Possible solutions? • Think about your network first • Think about what you store • Consider off-chain data store, store consent but consider carefully meta-data
  • 40. Other things to consider Data breaches • Report within 72 hours (in UK to the ICO) • Communicate to data subject • Require to map data (including processors) Privacy by Design and DPIA • Risk-based approach • Might result difficult in case of HW and SW • Lawyers, with DPO and CIO Data Retention • Pre-determined, explicit • For the duration of the service • Need frequent review
  • 41. Get involved • Resolve more consumers and businesses tensions • Risk of cybercrime • Lack of control • Fear of surveillance • Identify achievable trustworthy measures • Stimulate debate, Generate recommendation for EU • Co-create a DTRL (Digital Trust Readiness Level) https://truessec.eu
  • 42. Other resources – initiatives IoT Mark: https://iotmark.wordpress.com Recommendation and a mark for SMEs IoTSF: https://iotsecurityfoundation.org Focus on security of IoT systems Tech Lawyer interpretation: http://www.gamingtechlaw.com ICO recommendations: https://ico.org.uk/for-organisations/guide- to-the-general-data-protection-regulation-gdpr/ Digital Catapult workshop: https://www.eventbrite.co.uk/e/innovation-opportunity-of-the-gdpr- for-ai-and-ml-workshop-registration-42793145450
  • 43. EU Recommendations – Article WP29 Article 29 WP on Consent: https://iapp.org/media/pdf/resource_center/wp29_consent -12-12-17.pdf Article 29 WP on Transparency: https://iapp.org/media/pdf/resource_center/wp29- transparency-12-12-17.pdf Article 29 WP on Data Portability: https://iapp.org/media/pdf/resource_center/WP29-2017- 04-data-portability-guidance.pdf
  • 44. THANK YOU! #DigiCatapult info@digicatapult.org.uk 0300 1233 101 Digital Catapult digicatapult.org.uk /DigitalCatapult @DigitalCatapult Questions?