Are your data ready for GDPR Compliance?

Similar documents
Getting personal with your customers and GDPR

Do you handle EU residents personal data? The GDPR update is coming May 25, Are you ready?

WHITE PAPER. The General Data Protection Regulation: What Title It Means and How SAS Data Management Can Help

General Data Protection Regulation (GDPR) and the Implications for IT Service Management

Data Management and Security in the GDPR Era

Data Governance & Privacy Compliance: 16 Practical Steps towards GDPR Compliance with Talend

Altitude Software. Data Protection Heading 2018

G DATA Whitepaper. The new EU General Data Protection Regulation - What businesses need to know

Managing Privacy Risk & Compliance in Financial Services. Brett Hamilton Advisory Solutions Consultant ServiceNow

Accelerate GDPR compliance with the Microsoft Cloud

Emergency Compliance DG Special Case DAMA INDIANA

EU GDPR and . The complete text of the EU GDPR can be found at What is GDPR?

GDPR compliance. GDPR preparedness with OpenText InfoArchive. White paper

Hot Topics in Privacy

Hot Topics in Privacy

Cybersecurity Considerations for GDPR

General Data Protection Regulation (GDPR) The impact of doing business in Asia

MAPR DATA GOVERNANCE WITHOUT COMPROMISE

Countdown to GDPR. Impact on the Security Ecosystem and How to Prepare

SOLUTION BRIEF HELPING BREACH RESPONSE FOR GDPR WITH RSA SECURITY ADDRESSING THE TICKING CLOCK OF GDPR COMPLIANCE

General Data Protection Regulation: Knowing your data. Title. Prepared by: Paul Barks, Managing Consultant

Laws and Regulations & Data Governance

EU General Data Protection Regulation (GDPR) Achieving compliance

GDPR: A QUICK OVERVIEW

Getting ready for GDPR. Philipp Hobler EMEA Field CTO Global Technology Office Dell EMC Data Protection Solutions

SOLUTION OVERVIEW: DATA CATALOGS FOR RISK AND COMPLIANCE

AMCs and. Does the new law apply to my organization?

GDPR AND WHAT IT MEANS FOR CRM AND CUSTOMER ENGAGEMENT MAY. A 7-step practical guide to achieving and maintaining GDPR compliance by 25 May 2018

HIPAA Compliance is not a Cybersecurity Strategy

General Data Protection Regulation (GDPR) Key Facts & FAQ s

What you must ensure. Next Page

GDPR COMPLIANCE REPORT

WHITE PAPER. Meeting GDPR Challenges with Delphix. KuppingerCole Report

How the GDPR will impact your software delivery processes

IEEE GDPR Implementation & NTC

General Data Protection Regulation April 3, Sarah Ackerman, Managing Director Ross Patz, Consultant

Cloud is the 'Only' Way Forward in Information Security. Leveraging Scale to Make the Unknown Known, in Dev, Sec & Ops.

1 Copyright 2011, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 7

MOBIUS + ARKIVY the enterprise solution for MIFID2 record keeping

A Checklist for Compliance in the Cloud 1. A Checklist for Compliance in the Cloud

COMPUTAMATRIX LIMITED T/A MATRICA Data Protection Policy September Table of Contents. 1. Scope, Purpose and Application to Employees 2

GDPR How to Comply in an HPE NonStop Environment. Steve Tcherchian GTUG Mai 2018

General Data Protection Regulation (GDPR) NEW RULES

Data Privacy and Protection GDPR Compliance for Databases

IBM Security Guardium Analyzer

The GDPR data just got personal

Village Software. Security Assessment Report

IBM Security technology and services for GDPR programs GIULIA CALIARI SECURITY ARCHITECT

General Data Protection Regulation Frequently Asked Questions (FAQ) General Questions

Meeting GDPR Requirements with GoAnywhere MFT

What is GDPR? Editorial: The Guardian: August 7th, EU Charter of Fundamental Rights, 2000

EY s data privacy service offering. How to transform your data privacy capabilities for an EU General Data Protection Regulation (GDPR) world

Data Privacy in Your Own Backyard

GDPR is here to stay. How prepared are you?

Understand & Prepare for EU GDPR Requirements

Tracking 101 DISCOVER HOW TRACKING HELPS YOU UNDERSTAND AND TRULY ENGAGE YOUR AUDIENCES, TURNING INTO RESULTS

CipherCloud CASB+ Connector for ServiceNow

The GDPR Are you ready?

Adtech and GDPR What to consider when choosing your partner

ISE Canada Executive Forum and Awards

Cybersecurity. Securely enabling transformation and change

This guide is for informational purposes only. Please do not treat it as a substitute of a professional legal

GDPR Compliance & The Elastic Stack

DATA PROTECTION BY DESIGN

Embedding Privacy by Design

Solving the Enterprise Data Dilemma

Aon Service Corporation Law Global Privacy Office. Aon Client Data Privacy Summary

Preparing for a Breach October 14, 2016

General Data Protection Regulation (GDPR) FAQ

Solving the Really Big Tech Problems with IoT Data Security and Privacy

FOR FINANCIAL SERVICES ORGANIZATIONS

How WhereScape Data Automation Ensures You Are GDPR Compliant

THE GDPR PCLOUD'S ROAD TO FULL COMPLIANCE

Google Cloud & the General Data Protection Regulation (GDPR)

Express Monitoring 2019

How icims Supports. Your Readiness for the European Union General Data Protection Regulation

The Role of the Data Protection Officer

EU GDPR & ISO Integrated Documentation Toolkit integrated-documentation-toolkit

GDPR: An Opportunity to Transform Your Security Operations

Islam21c.com Data Protection and Privacy Policy

How unified backup and cloud enable your digital transformation success

Cybersecurity in Higher Ed

NPP & Blockchain Have you thought about the data? Ken Krupa, CTO, MarkLogic

A practical guide to using ScheduleOnce in a GDPR compliant manner

Recommendations on How to Tackle the D in GDPR. White Paper

Top Privacy Issues for Infosec Professionals

Sword vs. Shield: Using Forensics Pre-Breach in a GDPR World. September 20, 2017

RSA Solution Brief. The RSA Solution for Cloud Security and Compliance

BUSINESS LECTURE TWO. Dr Henry Pearson. Cyber Security and Privacy - Threats and Opportunities.

GDPR Workflow White Paper

Commit to Privacy, Publicly. Privacy by Design Certification Program Ann Cavoukian, Ph.D. CERTIFIED

PRIVACY AND ONLINE DATA: CAN WE HAVE BOTH?

at Kaiser Permanente Mary Henderson HIPAA Program Director Kaiser Permanente

Processing Cyber Threat Data Through the GDPR Regulatory Lens: for Operational Compliance with GDPR

All you need to know and do to comply with the EU General Data Protection Regulation

Incentives for IoT Security. White Paper. May Author: Dr. Cédric LEVY-BENCHETON, CEO

CommuniGator. Your GDPR. Compliance Checklist

GDPR: A technical perspective from Arkivum

Fact Or Fiction: The State Of GDPR Compliance

EU GDPR & NEW YORK CYBERSECURITY REQUIREMENTS 3 KEYS TO SUCCESS

Transcription:

Are your data ready for GDPR Compliance? USING A DATA HUB TO PROTECT PERSONAL DATA Track & Trace Capture & Connect Secure & Protect Certify & Curate Publish & Share 2017 Talend 1

Rémi Forest Solution Engineer Jean-Michel Franco Sr Product Mkt Director Track & Trace Capture & Connect Secure & Protect Certify & Curate Publish & Share 2017 Talend 2

Agenda GDPR and Data Governance: why, and why now? Drawing the Roadmap for GDPR Setting up the GDPR foundations with a Data Hub Establishing the 5 pillars for GDPR compliance with MAPR and Talend What s next on your GDPR journey? 3

Let s talk about personal data What I want to share Jean-Michel Franco, X2 years old, passionate about running Sr Director for Data Governance Products at Talend 2X experience in data management Engaged citizen in a data driven world (@jmichel_franco) Want to know More? Ask Google for my Physical/Digital journeys Ask Garmin for my physical & Experian for my financial health Ask Amazon for my buying & Waze for my driving behavior Ask Facebook for my personal & LinkedIn for my professional details But don t ask my doctor, he has taken the Hippocratic Oath 4

Beyond GDPR: it s all about Trust and Transparency Data Leaks BREAKING NEWS, Privacy Violations and Data Flaws Last Dieselgate Equifax year s breach forces privacy exposed German fines would data carmakers for be 143 79 times to million rethink higher consumers their under future GDPR Data Governance is no more an option 5

GDPR starts in 220 days: Will you be ready? 4% of global revenue 0.004% of global revenue 50% won t meet deadline Potential cost of for non compliance Budget devoted to data protection The pressure is on IT Source: European Commission, TeachPrivacy, Gartner 6

GDPR (General Data Protection Regulation) in a nutshell Protects privacy for individuals Goes into effect in 2018 (May, 25th). Increase powers of authorities to take action against non compliant business. Tough penalties: Fines up to 4% of annual global revenue or 20 million (whichever is greater) Worldwide Regulation also applies to non EU companies that process personal data of individuals in the EU. Broad definition: Personal data includes identifiers such as digital/online, genetic, mental, cultural, biometric Cross Border Data transfer : The international transfer of data will continue to be governed under EU GDPR rules. Affirmative Consent: obtaining consent for processing personal data must be clear, context based and must seek an affirmative response. Data Subjects Access Rights : Data Subjects have the right to be forgotten and erased from records. Users may request a copy of personal data in a portable format 7

Global Data Privacy is Multi-Dimensional Multiple subject areas Customer, Employee, Prospect, Citizen, Vendor Emerging data types Internet of Things, Logs, Biometrics Multiple jurisdictions EU, Canada, Australia, U.S. Rapidly changing regulations GDPR, CASL, HIPAA 8

GDPR Helicopter Positioning What s Involved Identify, know and track your personal data Make sure your Data is compliant Protect your Data and foster accountability Unleash your data for the data subject access rights? 9

What does GDPR mean for your Data Management practices? Goal Inventory your personal data Establish policies Protect your data Track and trace consent Engage your workforce Open your data to your data subjects 10

Draw your Roadmap for GDPR Compliance Engage Compliance Initiatives Consent Management Anonymization Rights of the data subject 3 2 Build your Personal Data Hub Know your Data Reconcile your data Regain control Assess your Capabilities Identify gaps Assess risks Define priorities and milestones 1 11

Assess your capabilities With http://talend.gdprevaluation.com/ Connect Fill-up a 20 questionnaire Get your readiness assessment 13

What is expected? Know where to find every data about every person (customer or employee) Collect and Store compliance related data (i.e. Consent status) Control who can access these data Trace who accessed these data Make sure you don t lose this data Matching all this on a distributed environment is at least very challenging 14

The case for a Personal Data Hub Physical or virtual consolidation of every person s data Data can be enriched with compliance related information Single place to control and trace access Automatically updated based on legacy source systems Can be used as data source for new applications 15

5 pillars for GDPR governance with MAPR & Talend Manage Data Location, Movement & Portability Map your Personal Data Delegate Accountalities Build your Data Subject 360 Protect your most Sensitive Data 16

Create a Data Inventory for Compliance GDPR article 4, 9 and 30 Define your Personal Data Connect them to your data sets Track & trace across the information chain 17

Build the 360 view of the data subject Based on data inventory, consolidate all data in a single place Document Databases are the perfect tool Referential integrity is mandatory : avoid manual processes ETL Change data capture Streaming/Real Time Closing the loop with source system might be needed for rights to be forgotten/rectification 18

Protect personal data at infrastructure level Protecting data is an holistic approach Ensure that no data can be lost Protect against attacks or errors : MapR Snapshots Protect against disaster : MapR Remote Replication Ensure that only authorized people have access to data: Logical access control : ACEs and auditing Physical access control : in-flight and at-rest encryption 19

Protect Personal data with Data Masking Article 5, 6, 11 and 32 Capture personal footprints in your datasets Apply Data Masking everywhere Obfuscate data for analytics 20

Foster accountability with Talend Data Preparation & Stewardship Articles 4, 5, 6, 24, 25, 27 Discover datasets and prepare data for integration Orchestrate collaborative Governance Certify Data with Self-Service Data Curation 21

Respect the right of the data subject Article 12, 13, 14, 15, 16, 17, 18, 19, 20, 21 Deliver data on request, in batch mode or deliver data services, in real time 22

Manage Data Location Your business is global, so are your data Your governance has to be global too MapR Data Fabric gives you global control over your data 23

Poll #2: Your priorities for compliance? Multiple responses 24

The issue of security is addressed with Talend Data Quality since we process some of our clients personal data and this data needs to be protected. In addition, Talend Metadata Manager can determine returned ten times faster than before where the data is located, when it is coming from, and where it is going. Air France-KLM aims delight customers with personalized experience, Air France KLM creates a complete 360 view of the customer. Damien Trinité, CRM Big Data Project Manager, Air France KLM Over 80% of lost items 25

MapR + Talend architecture in a nutshell Actions Social Media Search Medical Info Banking Info Ingest Track & Trace Capture & Connect Secure & Protect Certify & Curate Publish & Share Native Connectivity for the MapR Platform with Spark & Machine Learning MapR-FS MapR-DB MapR Data Platform MapR Streams Data Map Other PII Converged Data Platform Raise Alerts 26

What s next in your GDPR journey? Self-assess your readiness: http://talend.gdprevaluation.com/ Learn more on our joint solution : https://mapr.com/resources/maprtalend-gdpr-solution-brief/ Populate your personal data hub Set accountabilities & orchestrate collaborative data governance Operationalize GDPR governance (Consent, Data Subject Access Rights, Data Protection and Anonymization ) Questions? 27

Are your data ready for GDPR Compliance? USING A DATA HUB TO PROTECT PERSONAL DATA Track & Trace Capture & Connect Secure & Protect Certify & Curate Publish & Share 2017 Talend 28