SlideShare ist ein Scribd-Unternehmen logo
1 von 35
@aureliepols Stockholm –March 2015#outfox2015
Responsible Data Uses:
Privacy, Security, Ethics & Compliance
Aurélie Pols
Pan-European digital analytics
veteran & Privacy geek
Board Member @MyPermissions
@aureliepols Stockholm –March 2015#outfox2015
Before frictionless sharing
@aureliepols Stockholm –March 2015#outfox2015
We did optimize “stuff”
@aureliepols Stockholm –March 2015#outfox2015
The era of Data Hoarding
@aureliepols Stockholm –March 2015#outfox2015
DATA LEECHING
While some refer to Data Puking, this is about
@aureliepols Stockholm –March 2015#outfox2015
Data = New Asset Class
• Economic asset:
– if it’s worth something,
who owns it?
• Ownership means
property:
– Property law, contract law,
etc.
• But
@aureliepols Stockholm –March 2015#outfox2015
DATA IS INFINITELY TRANSFERABLE
WITHOUT DECAY
#1. The specifics of Data as an Economic Asset
@aureliepols Stockholm –March 2015#outfox2015
Familiar property types
• House, mortgage &
cadaster
• A car looses 50% of it’s
value the day after the
purchase
• But data? What is it really?
HYPOTEK Fastighetsregistret
@aureliepols Stockholm –March 2015#outfox2015
Infinitely transferable without decay
• Interesting type of property
• The legal world is not ready for
• Yet harm is imaginable:
– Deaths of dissidents
– Algorithmic discrimination
– Tunneled world vision
– Identity thefts
– Cyber bullying
@aureliepols Stockholm –March 2015#outfox2015
DEFINING & RECOGNIZING DATA
HARMS
#2. Often forgotten legislative challenges
@aureliepols Stockholm –March 2015#outfox2015
Involved actors
• Legislators & governments:
– make the laws & want to be re-elected
• Businesses (employee, partner & customer data):
– growth strategies, max shareholder value
(not always)
• Citizens:
– consuming technology,
are the product if free,
co-owners of the data?
Governments
Legislators
(FTC, FCC,
FDA, EU)
Consumers
Voters Citizens
OUR
GLOBAL
SOCIETY
Businesses:
Brands
Data Service
Providers
@aureliepols Stockholm –March 2015#outfox2015
Data ownership? The Dutch
KPN is a
Dutch Telco
Operations
are in the
Netherlands,
Belgium &
Germany
Brands: Hi,
Simyo, Telfort
& KPN,
XS4ALL, E-
Plus & Base
(sold to
Telefonica)
@aureliepols Stockholm –March 2015#outfox2015
Patchworks of legislation
@aureliepols Stockholm –March 2015#outfox2015
Legislation about
• Data-breaches!!! <- security
• Copyright
• Intellectual property <- algorithms
• Net-neutrality
• …
Anonymity |Biometrics |CALEA |Cell Tracking |Cyber Security Legislation |Digital Books
Do Not Track (DNT) |Encrypting the Web |International Privacy Standards |Locational Privacy
Mandatory Data Retention |Mass Surveillance Technologies |Medical Privacy |National Security Letters
NSA Spying |Online Behavioral Targeting (OBA) |Open Wireless |PATRIOT Act |Pen Trap |Printers |Real ID
RFID |Search Engines |Search Incident to Arrest |Social Networks |Surveillance Drones |Travel Screening
@aureliepols Stockholm –March 2015#outfox2015
4 topics
1. Security
2. Compliance
3. Privacy
4. Ethics
@aureliepols Stockholm –March 2015#outfox2015
Europe: Data Protection
@aureliepols Stockholm –March 2015#outfox2015
Security for digital analytics
Mainly for (not mutually exclusive):
– Access: employees, partners, APIs, … <- control &
revoke procedures? Strong passwords?
– Data transfers: between tools & devices, between
companies <- level of encryption? Liability?
– Data merging: which data set goes (or is copied)
where? <- data breach notification requirements
@aureliepols Stockholm –March 2015#outfox2015
COMPLIANCE IS A RISK EXERCISE
#3. Related to evolving Privacy legislation
@aureliepols Stockholm –March 2015#outfox2015
Privacy & Annoying Europeans
@aureliepols Stockholm –March 2015#outfox2015
PII: ah but we don’t collect it!
Medical information as PII
California
Arkansas
Missouri
New Hampshire
North Dakota
Texas
Virginia
Financial information as PII
Alaska North Carolina
Iowa North Dakota
Kansas Oregon
Massachusetts South Carolina
Missouri Vermont
Nevada Wisconsin
New York* Wyoming
Passwords as PII
Georgia
Maine
Nebraska
Biometric information as PII
Iowa
Nebraska
North Carolina
Wisconsin
Source: information based on
current continuous monitoring
(partial results)
@aureliepols Stockholm –March 2015#outfox2015
A Global Privacy Perspective
US & UK EU ASIA
Common Law Continental Law Partially
continental
law
influenced
Class actions Fines
(by DPAs: Data Protection Agencies)
Amended New
Privacy Personal Data Protection (PDP)
Business focused Citizen focused: data belongs to the
visitor/prospect/consumer/citizen
Patchwork of sector based
legislations: HIPAA, COPPA,
VPPA, …
Over-arching EU Directives &
Regulations
PII: varies per US
state
“Personal Data” => Risk levels:
low, medium, high, extremely
high
@aureliepols Stockholm –March 2015#outfox2015
Low Risk
Medium Risk
(profiling)
High Risk
(sensitive)
R
i
s
k
L
e
v
e
l
Data type
Information Security Measures
Extremely High Risk
(profiling of sensitive data)PII
PII vs. Risk Levels
@aureliepols Stockholm –March 2015#outfox2015
Data Science concerns?
• As a Data Scientist: doing the best analysis
• As an employee: not getting my company into
trouble
• As a citizen:
– Lack of transparency <- loss of control
that could lead to discrimination
– Identity theft
– Tunneled view of the world
@aureliepols Stockholm –March 2015#outfox2015
What do analytics tools propose?
Let’s take Google Analytics:
• Anonymizing IP addresses
• Implementing opt-out mechanisms
• Not using cookies
• Complying with DNT
• Forcing SSL
• Disabling data sharing
Source: http://gu.illau.me/posts/privacy-and-google-analytics/
@aureliepols Stockholm –March 2015#outfox2015
Source:
http://dynamical.biz/
blog/technical-
analytics/collecting-
ga-userid-into-ga-can-
violate-google-
analytics-tos-75.html
@aureliepols Stockholm –March 2015#outfox2015
Data tension due to data leeching
Analytics capabilities
Customer feelings
of creepiness
Harm?
Data quality?
@aureliepols Stockholm –March 2015#outfox2015
Privacy Role Playing in the EU
@aureliepols Stockholm –March 2015#outfox2015
Rights & obligations
Roles and responsibilities Data controller must:
• Process legally &
fairly
• Collect for explicit
& legitimate
purposes
• Not excessively
• Keep data accurate
& updated
• Allow for
rectification
• Respect data
retention periods
• Protect personal
data, appropriate
to the type of data
held
@aureliepols Stockholm –March 2015#outfox2015
UNDERSTAND YOUR LIABILITY
WITHIN THE DATA ECOSYSTEM
#4. Minimizing Privacy related Risks?
@aureliepols Stockholm –March 2015#outfox2015
Who is liable here?
@aureliepols Stockholm –March 2015#outfox2015
iBeacons, Mondelez: Creepy?
@aureliepols Stockholm –March 2015#outfox2015
EU GDPR affecting Data Science
• Collaboration & Responsibility (not only legal)
– Privacy training & escalation procedures
• Data lineage & consent management
– Understanding where
the data comes from
– Manage individual
choices & consent
@aureliepols Stockholm –March 2015#outfox2015
EU GDPR affecting Data Science
• Change to the data value exchange
– Maintaining quality of data collected & analyzed
• Commercial advantages
– Increased Trust; reduced Brand Erosion due to
unsystematic Privacy management
– Better data governance, optimized use of Data
Science
@aureliepols Stockholm –March 2015#outfox2015
1 legal concept to rule them all
FIPPs: Fair information Practice Principles
Transparency
Choice
Information
review &
correction
Information
protection
Accountability
@aureliepols Stockholm –March 2015#outfox2015
Open discussion
Aurélie Pols

Weitere ähnliche Inhalte

Andere mochten auch

The State of End-User Security—Global Data from 30,000+ Websites
The State of End-User Security—Global Data from 30,000+ WebsitesThe State of End-User Security—Global Data from 30,000+ Websites
The State of End-User Security—Global Data from 30,000+ WebsitesPriyanka Aash
 
Academic Uses For Data Collection And Graphing
Academic Uses For Data Collection And GraphingAcademic Uses For Data Collection And Graphing
Academic Uses For Data Collection And GraphingAmy Wiesler
 
Smart Uses of Data: How to Learn More About Your Audience and Target Individu...
Smart Uses of Data: How to Learn More About Your Audience and Target Individu...Smart Uses of Data: How to Learn More About Your Audience and Target Individu...
Smart Uses of Data: How to Learn More About Your Audience and Target Individu...PerformanceIN
 
Building Digital Trust : The role of data ethics in the digital age
Building Digital Trust: The role of data ethics in the digital ageBuilding Digital Trust: The role of data ethics in the digital age
Building Digital Trust : The role of data ethics in the digital ageAccenture Technology
 
Heavy Metal PowerPivot Remastered
Heavy Metal PowerPivot RemasteredHeavy Metal PowerPivot Remastered
Heavy Metal PowerPivot RemasteredJason Himmelstein
 
R Statistics With MongoDB
R Statistics With MongoDBR Statistics With MongoDB
R Statistics With MongoDBMongoDB
 
Amadeus big data
Amadeus big dataAmadeus big data
Amadeus big data승필 고
 
Secret Life of a Weather Datum end of project event
Secret Life of a Weather Datum end of project eventSecret Life of a Weather Datum end of project event
Secret Life of a Weather Datum end of project eventlifeofdata
 
Science Communication 2.0: changing University attitude through Science resea...
Science Communication 2.0: changing University attitude through Science resea...Science Communication 2.0: changing University attitude through Science resea...
Science Communication 2.0: changing University attitude through Science resea...Miquel Duran
 
Cartagena Data Festival | Telling Stories with Data 2015 04-21
Cartagena Data Festival | Telling Stories with Data 2015 04-21Cartagena Data Festival | Telling Stories with Data 2015 04-21
Cartagena Data Festival | Telling Stories with Data 2015 04-21ulrichatz
 
USJBF Overview Presentation
USJBF Overview PresentationUSJBF Overview Presentation
USJBF Overview Presentationkdieckgraeff
 
Migrating to git
Migrating to gitMigrating to git
Migrating to gitXpand IT
 
Revving Up Revenue By Replenishing
Revving Up Revenue By ReplenishingRevving Up Revenue By Replenishing
Revving Up Revenue By ReplenishingWhatConts
 
Av capabilities presentation
Av capabilities presentationAv capabilities presentation
Av capabilities presentationNAISales2
 
Grow Customer Retention with Predictive Marketing and User-Generated Content
Grow Customer Retention with Predictive Marketing and User-Generated ContentGrow Customer Retention with Predictive Marketing and User-Generated Content
Grow Customer Retention with Predictive Marketing and User-Generated ContentWhatConts
 
Leinster college dublin - brochure web
Leinster college   dublin - brochure webLeinster college   dublin - brochure web
Leinster college dublin - brochure webThiago Pimentel
 
Challenges in opening up qualitative research data
Challenges in opening up qualitative research dataChallenges in opening up qualitative research data
Challenges in opening up qualitative research datalifeofdata
 

Andere mochten auch (20)

The State of End-User Security—Global Data from 30,000+ Websites
The State of End-User Security—Global Data from 30,000+ WebsitesThe State of End-User Security—Global Data from 30,000+ Websites
The State of End-User Security—Global Data from 30,000+ Websites
 
Academic Uses For Data Collection And Graphing
Academic Uses For Data Collection And GraphingAcademic Uses For Data Collection And Graphing
Academic Uses For Data Collection And Graphing
 
Smart Uses of Data: How to Learn More About Your Audience and Target Individu...
Smart Uses of Data: How to Learn More About Your Audience and Target Individu...Smart Uses of Data: How to Learn More About Your Audience and Target Individu...
Smart Uses of Data: How to Learn More About Your Audience and Target Individu...
 
Building Digital Trust : The role of data ethics in the digital age
Building Digital Trust: The role of data ethics in the digital ageBuilding Digital Trust: The role of data ethics in the digital age
Building Digital Trust : The role of data ethics in the digital age
 
Heavy Metal PowerPivot Remastered
Heavy Metal PowerPivot RemasteredHeavy Metal PowerPivot Remastered
Heavy Metal PowerPivot Remastered
 
R Statistics With MongoDB
R Statistics With MongoDBR Statistics With MongoDB
R Statistics With MongoDB
 
Special project
Special projectSpecial project
Special project
 
Amadeus big data
Amadeus big dataAmadeus big data
Amadeus big data
 
Secret Life of a Weather Datum end of project event
Secret Life of a Weather Datum end of project eventSecret Life of a Weather Datum end of project event
Secret Life of a Weather Datum end of project event
 
Science Communication 2.0: changing University attitude through Science resea...
Science Communication 2.0: changing University attitude through Science resea...Science Communication 2.0: changing University attitude through Science resea...
Science Communication 2.0: changing University attitude through Science resea...
 
Cartagena Data Festival | Telling Stories with Data 2015 04-21
Cartagena Data Festival | Telling Stories with Data 2015 04-21Cartagena Data Festival | Telling Stories with Data 2015 04-21
Cartagena Data Festival | Telling Stories with Data 2015 04-21
 
USJBF Overview Presentation
USJBF Overview PresentationUSJBF Overview Presentation
USJBF Overview Presentation
 
GIT Best Practices V 0.1
GIT Best Practices V 0.1GIT Best Practices V 0.1
GIT Best Practices V 0.1
 
Migrating to git
Migrating to gitMigrating to git
Migrating to git
 
Revving Up Revenue By Replenishing
Revving Up Revenue By ReplenishingRevving Up Revenue By Replenishing
Revving Up Revenue By Replenishing
 
Creative Overview
Creative OverviewCreative Overview
Creative Overview
 
Av capabilities presentation
Av capabilities presentationAv capabilities presentation
Av capabilities presentation
 
Grow Customer Retention with Predictive Marketing and User-Generated Content
Grow Customer Retention with Predictive Marketing and User-Generated ContentGrow Customer Retention with Predictive Marketing and User-Generated Content
Grow Customer Retention with Predictive Marketing and User-Generated Content
 
Leinster college dublin - brochure web
Leinster college   dublin - brochure webLeinster college   dublin - brochure web
Leinster college dublin - brochure web
 
Challenges in opening up qualitative research data
Challenges in opening up qualitative research dataChallenges in opening up qualitative research data
Challenges in opening up qualitative research data
 

Ähnlich wie Responsible Data Uses: Privacy, Security, Ethics & Compliance

Big Data Big Ideas: Data is the New Oil, Privacy is the New Green
Big Data Big Ideas: Data is the New Oil, Privacy is the New GreenBig Data Big Ideas: Data is the New Oil, Privacy is the New Green
Big Data Big Ideas: Data is the New Oil, Privacy is the New GreenAurélie Pols
 
IAPP Data Protection Intensive London - Transparency in Marketing (AP part III)
IAPP Data Protection Intensive London - Transparency in Marketing (AP part III)IAPP Data Protection Intensive London - Transparency in Marketing (AP part III)
IAPP Data Protection Intensive London - Transparency in Marketing (AP part III)Aurélie Pols
 
Enabling the workforce of the future Aug2015
Enabling the workforce of the future   Aug2015Enabling the workforce of the future   Aug2015
Enabling the workforce of the future Aug2015Rick Holgate
 
Who Goes There? Demystifying Digital Identity for All (1/2)
Who Goes There? Demystifying Digital Identity for All (1/2)Who Goes There? Demystifying Digital Identity for All (1/2)
Who Goes There? Demystifying Digital Identity for All (1/2)Aurélie Pols
 
Bringing IoT ideas to life: start from the user ... not the API! - API days 2...
Bringing IoT ideas to life: start from the user ... not the API! - API days 2...Bringing IoT ideas to life: start from the user ... not the API! - API days 2...
Bringing IoT ideas to life: start from the user ... not the API! - API days 2...Claro Partners Inc.
 
Tallium demo Jan 18
Tallium demo Jan 18Tallium demo Jan 18
Tallium demo Jan 18AquaSPE AG
 
Data Accountability & Consumer Trust
Data Accountability & Consumer TrustData Accountability & Consumer Trust
Data Accountability & Consumer TrustAurélie Pols
 
Itag usama bigdata-6-2015-full
Itag usama bigdata-6-2015-fullItag usama bigdata-6-2015-full
Itag usama bigdata-6-2015-fullUsama Fayyad
 
Metadata Matters: Business Critical Metadata
Metadata Matters: Business Critical MetadataMetadata Matters: Business Critical Metadata
Metadata Matters: Business Critical MetadataConcept Searching, Inc
 
eMetrics Summit Boston 2014 - Big Data Marketing - From Über Creepy to Over ...
 eMetrics Summit Boston 2014 - Big Data Marketing - From Über Creepy to Over ... eMetrics Summit Boston 2014 - Big Data Marketing - From Über Creepy to Over ...
eMetrics Summit Boston 2014 - Big Data Marketing - From Über Creepy to Over ...Aurélie Pols
 
"Cerved - A business perspective"
"Cerved - A business perspective" "Cerved - A business perspective"
"Cerved - A business perspective" dapaasproject
 
The rise of privacy & personal data in the IT business - Claudia Jelea
The rise of privacy & personal data in the IT business - Claudia JeleaThe rise of privacy & personal data in the IT business - Claudia Jelea
The rise of privacy & personal data in the IT business - Claudia JeleaITCamp
 
ITCamp 2016: The rise of privacy and personal data in the IT business
ITCamp 2016: The rise of privacy and personal data in the IT businessITCamp 2016: The rise of privacy and personal data in the IT business
ITCamp 2016: The rise of privacy and personal data in the IT businessclaudiajelea
 
The competitive landscape of IoT - Global IoT Day Conference Vienna 9 April 2015
The competitive landscape of IoT - Global IoT Day Conference Vienna 9 April 2015The competitive landscape of IoT - Global IoT Day Conference Vienna 9 April 2015
The competitive landscape of IoT - Global IoT Day Conference Vienna 9 April 2015Knud Lasse Lueth
 
The competitive landscape of the Internet of Things
The competitive landscape of the Internet of ThingsThe competitive landscape of the Internet of Things
The competitive landscape of the Internet of ThingsIoTAnalytics
 
TLabs - deutsche telekom
TLabs -  deutsche telekomTLabs -  deutsche telekom
TLabs - deutsche telekomChristina Azzam
 
Privacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital SetupPrivacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital SetupPiwik PRO
 
The 3 ‘R’s of Research
The 3 ‘R’s of ResearchThe 3 ‘R’s of Research
The 3 ‘R’s of Research MRS
 
2015 Leonardo Martucci - Sentors frukostseminarium om dataskydd
2015 Leonardo Martucci - Sentors frukostseminarium om dataskydd2015 Leonardo Martucci - Sentors frukostseminarium om dataskydd
2015 Leonardo Martucci - Sentors frukostseminarium om dataskyddsentormss
 
Office 365 Data Leakage Protection, DLP, Data Loss Prevention, Privacy, Comp...
Office 365  Data Leakage Protection, DLP, Data Loss Prevention, Privacy, Comp...Office 365  Data Leakage Protection, DLP, Data Loss Prevention, Privacy, Comp...
Office 365 Data Leakage Protection, DLP, Data Loss Prevention, Privacy, Comp...Edge Pereira
 

Ähnlich wie Responsible Data Uses: Privacy, Security, Ethics & Compliance (20)

Big Data Big Ideas: Data is the New Oil, Privacy is the New Green
Big Data Big Ideas: Data is the New Oil, Privacy is the New GreenBig Data Big Ideas: Data is the New Oil, Privacy is the New Green
Big Data Big Ideas: Data is the New Oil, Privacy is the New Green
 
IAPP Data Protection Intensive London - Transparency in Marketing (AP part III)
IAPP Data Protection Intensive London - Transparency in Marketing (AP part III)IAPP Data Protection Intensive London - Transparency in Marketing (AP part III)
IAPP Data Protection Intensive London - Transparency in Marketing (AP part III)
 
Enabling the workforce of the future Aug2015
Enabling the workforce of the future   Aug2015Enabling the workforce of the future   Aug2015
Enabling the workforce of the future Aug2015
 
Who Goes There? Demystifying Digital Identity for All (1/2)
Who Goes There? Demystifying Digital Identity for All (1/2)Who Goes There? Demystifying Digital Identity for All (1/2)
Who Goes There? Demystifying Digital Identity for All (1/2)
 
Bringing IoT ideas to life: start from the user ... not the API! - API days 2...
Bringing IoT ideas to life: start from the user ... not the API! - API days 2...Bringing IoT ideas to life: start from the user ... not the API! - API days 2...
Bringing IoT ideas to life: start from the user ... not the API! - API days 2...
 
Tallium demo Jan 18
Tallium demo Jan 18Tallium demo Jan 18
Tallium demo Jan 18
 
Data Accountability & Consumer Trust
Data Accountability & Consumer TrustData Accountability & Consumer Trust
Data Accountability & Consumer Trust
 
Itag usama bigdata-6-2015-full
Itag usama bigdata-6-2015-fullItag usama bigdata-6-2015-full
Itag usama bigdata-6-2015-full
 
Metadata Matters: Business Critical Metadata
Metadata Matters: Business Critical MetadataMetadata Matters: Business Critical Metadata
Metadata Matters: Business Critical Metadata
 
eMetrics Summit Boston 2014 - Big Data Marketing - From Über Creepy to Over ...
 eMetrics Summit Boston 2014 - Big Data Marketing - From Über Creepy to Over ... eMetrics Summit Boston 2014 - Big Data Marketing - From Über Creepy to Over ...
eMetrics Summit Boston 2014 - Big Data Marketing - From Über Creepy to Over ...
 
"Cerved - A business perspective"
"Cerved - A business perspective" "Cerved - A business perspective"
"Cerved - A business perspective"
 
The rise of privacy & personal data in the IT business - Claudia Jelea
The rise of privacy & personal data in the IT business - Claudia JeleaThe rise of privacy & personal data in the IT business - Claudia Jelea
The rise of privacy & personal data in the IT business - Claudia Jelea
 
ITCamp 2016: The rise of privacy and personal data in the IT business
ITCamp 2016: The rise of privacy and personal data in the IT businessITCamp 2016: The rise of privacy and personal data in the IT business
ITCamp 2016: The rise of privacy and personal data in the IT business
 
The competitive landscape of IoT - Global IoT Day Conference Vienna 9 April 2015
The competitive landscape of IoT - Global IoT Day Conference Vienna 9 April 2015The competitive landscape of IoT - Global IoT Day Conference Vienna 9 April 2015
The competitive landscape of IoT - Global IoT Day Conference Vienna 9 April 2015
 
The competitive landscape of the Internet of Things
The competitive landscape of the Internet of ThingsThe competitive landscape of the Internet of Things
The competitive landscape of the Internet of Things
 
TLabs - deutsche telekom
TLabs -  deutsche telekomTLabs -  deutsche telekom
TLabs - deutsche telekom
 
Privacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital SetupPrivacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital Setup
 
The 3 ‘R’s of Research
The 3 ‘R’s of ResearchThe 3 ‘R’s of Research
The 3 ‘R’s of Research
 
2015 Leonardo Martucci - Sentors frukostseminarium om dataskydd
2015 Leonardo Martucci - Sentors frukostseminarium om dataskydd2015 Leonardo Martucci - Sentors frukostseminarium om dataskydd
2015 Leonardo Martucci - Sentors frukostseminarium om dataskydd
 
Office 365 Data Leakage Protection, DLP, Data Loss Prevention, Privacy, Comp...
Office 365  Data Leakage Protection, DLP, Data Loss Prevention, Privacy, Comp...Office 365  Data Leakage Protection, DLP, Data Loss Prevention, Privacy, Comp...
Office 365 Data Leakage Protection, DLP, Data Loss Prevention, Privacy, Comp...
 

Mehr von Aurélie Pols

AI Roles and Risk for election year 2024
AI Roles and Risk for election year 2024AI Roles and Risk for election year 2024
AI Roles and Risk for election year 2024Aurélie Pols
 
Preparing for the AI Act - 5 years into GDPR enforcement
Preparing for the AI Act - 5 years into GDPR enforcementPreparing for the AI Act - 5 years into GDPR enforcement
Preparing for the AI Act - 5 years into GDPR enforcementAurélie Pols
 
Creative destruction & Privacy Whitewashing: where does risk lie?
Creative destruction & Privacy Whitewashing: where does risk lie? Creative destruction & Privacy Whitewashing: where does risk lie?
Creative destruction & Privacy Whitewashing: where does risk lie? Aurélie Pols
 
ePrivacy Directive, a 10 steps framework to be as compliant as possible for m...
ePrivacy Directive, a 10 steps framework to be as compliant as possible for m...ePrivacy Directive, a 10 steps framework to be as compliant as possible for m...
ePrivacy Directive, a 10 steps framework to be as compliant as possible for m...Aurélie Pols
 
IAPP - Skills For Minimizing Privacy Risk in Data Science Product and Service...
IAPP - Skills For Minimizing Privacy Risk in Data Science Product and Service...IAPP - Skills For Minimizing Privacy Risk in Data Science Product and Service...
IAPP - Skills For Minimizing Privacy Risk in Data Science Product and Service...Aurélie Pols
 
Women in STEM for IE Girl Up Club
Women in STEM for IE Girl Up Club Women in STEM for IE Girl Up Club
Women in STEM for IE Girl Up Club Aurélie Pols
 
For Superweek 2022: discussing risk using IAB's TCF
For Superweek 2022: discussing risk using IAB's TCFFor Superweek 2022: discussing risk using IAB's TCF
For Superweek 2022: discussing risk using IAB's TCFAurélie Pols
 
Interoperability in Digital will take a Global Village
Interoperability in Digital will take a Global VillageInteroperability in Digital will take a Global Village
Interoperability in Digital will take a Global VillageAurélie Pols
 
The GDPR is here. So do you know what the courts are saying?
The GDPR is here. So do you know what the courts are saying?The GDPR is here. So do you know what the courts are saying?
The GDPR is here. So do you know what the courts are saying?Aurélie Pols
 
CPDP: Data ownership, Innovation and Privacy: looking for an approach on both...
CPDP: Data ownership, Innovation and Privacy: looking for an approach on both...CPDP: Data ownership, Innovation and Privacy: looking for an approach on both...
CPDP: Data ownership, Innovation and Privacy: looking for an approach on both...Aurélie Pols
 
GDPR and the aftermath: what are we building towards?
GDPR and the aftermath: what are we building towards?GDPR and the aftermath: what are we building towards?
GDPR and the aftermath: what are we building towards?Aurélie Pols
 
Data is the new infrastructure, Privacy is the new green, Trust is the new cu...
Data is the new infrastructure, Privacy is the new green, Trust is the new cu...Data is the new infrastructure, Privacy is the new green, Trust is the new cu...
Data is the new infrastructure, Privacy is the new green, Trust is the new cu...Aurélie Pols
 
How digitization challenges our values as citizens
How digitization challenges our values as citizens How digitization challenges our values as citizens
How digitization challenges our values as citizens Aurélie Pols
 
Technical Consequences of the Data Subject's Rights
Technical Consequences of the Data Subject's RightsTechnical Consequences of the Data Subject's Rights
Technical Consequences of the Data Subject's RightsAurélie Pols
 
From GDPR to ePrivacy: what does it mean to the advertising sector?
From GDPR to ePrivacy: what does it mean to the advertising sector?From GDPR to ePrivacy: what does it mean to the advertising sector?
From GDPR to ePrivacy: what does it mean to the advertising sector?Aurélie Pols
 
State of EU legislation: GDPR & ePrivacy for Superweek
State of EU legislation: GDPR & ePrivacy for SuperweekState of EU legislation: GDPR & ePrivacy for Superweek
State of EU legislation: GDPR & ePrivacy for SuperweekAurélie Pols
 
The Great GDPR MyData Debate - Aurelie Pols - Keynote
The Great GDPR MyData Debate - Aurelie Pols - KeynoteThe Great GDPR MyData Debate - Aurelie Pols - Keynote
The Great GDPR MyData Debate - Aurelie Pols - KeynoteAurélie Pols
 
The Data Subject First? Decoding the GDPR at StrataData
The Data Subject First? Decoding the GDPR at StrataDataThe Data Subject First? Decoding the GDPR at StrataData
The Data Subject First? Decoding the GDPR at StrataDataAurélie Pols
 
Brussels data science - Privacy Engineering for Big Data & Data Science
Brussels data science - Privacy Engineering for Big Data & Data ScienceBrussels data science - Privacy Engineering for Big Data & Data Science
Brussels data science - Privacy Engineering for Big Data & Data ScienceAurélie Pols
 
Sibos INNOTRIBE Digital Ethics
Sibos INNOTRIBE Digital EthicsSibos INNOTRIBE Digital Ethics
Sibos INNOTRIBE Digital EthicsAurélie Pols
 

Mehr von Aurélie Pols (20)

AI Roles and Risk for election year 2024
AI Roles and Risk for election year 2024AI Roles and Risk for election year 2024
AI Roles and Risk for election year 2024
 
Preparing for the AI Act - 5 years into GDPR enforcement
Preparing for the AI Act - 5 years into GDPR enforcementPreparing for the AI Act - 5 years into GDPR enforcement
Preparing for the AI Act - 5 years into GDPR enforcement
 
Creative destruction & Privacy Whitewashing: where does risk lie?
Creative destruction & Privacy Whitewashing: where does risk lie? Creative destruction & Privacy Whitewashing: where does risk lie?
Creative destruction & Privacy Whitewashing: where does risk lie?
 
ePrivacy Directive, a 10 steps framework to be as compliant as possible for m...
ePrivacy Directive, a 10 steps framework to be as compliant as possible for m...ePrivacy Directive, a 10 steps framework to be as compliant as possible for m...
ePrivacy Directive, a 10 steps framework to be as compliant as possible for m...
 
IAPP - Skills For Minimizing Privacy Risk in Data Science Product and Service...
IAPP - Skills For Minimizing Privacy Risk in Data Science Product and Service...IAPP - Skills For Minimizing Privacy Risk in Data Science Product and Service...
IAPP - Skills For Minimizing Privacy Risk in Data Science Product and Service...
 
Women in STEM for IE Girl Up Club
Women in STEM for IE Girl Up Club Women in STEM for IE Girl Up Club
Women in STEM for IE Girl Up Club
 
For Superweek 2022: discussing risk using IAB's TCF
For Superweek 2022: discussing risk using IAB's TCFFor Superweek 2022: discussing risk using IAB's TCF
For Superweek 2022: discussing risk using IAB's TCF
 
Interoperability in Digital will take a Global Village
Interoperability in Digital will take a Global VillageInteroperability in Digital will take a Global Village
Interoperability in Digital will take a Global Village
 
The GDPR is here. So do you know what the courts are saying?
The GDPR is here. So do you know what the courts are saying?The GDPR is here. So do you know what the courts are saying?
The GDPR is here. So do you know what the courts are saying?
 
CPDP: Data ownership, Innovation and Privacy: looking for an approach on both...
CPDP: Data ownership, Innovation and Privacy: looking for an approach on both...CPDP: Data ownership, Innovation and Privacy: looking for an approach on both...
CPDP: Data ownership, Innovation and Privacy: looking for an approach on both...
 
GDPR and the aftermath: what are we building towards?
GDPR and the aftermath: what are we building towards?GDPR and the aftermath: what are we building towards?
GDPR and the aftermath: what are we building towards?
 
Data is the new infrastructure, Privacy is the new green, Trust is the new cu...
Data is the new infrastructure, Privacy is the new green, Trust is the new cu...Data is the new infrastructure, Privacy is the new green, Trust is the new cu...
Data is the new infrastructure, Privacy is the new green, Trust is the new cu...
 
How digitization challenges our values as citizens
How digitization challenges our values as citizens How digitization challenges our values as citizens
How digitization challenges our values as citizens
 
Technical Consequences of the Data Subject's Rights
Technical Consequences of the Data Subject's RightsTechnical Consequences of the Data Subject's Rights
Technical Consequences of the Data Subject's Rights
 
From GDPR to ePrivacy: what does it mean to the advertising sector?
From GDPR to ePrivacy: what does it mean to the advertising sector?From GDPR to ePrivacy: what does it mean to the advertising sector?
From GDPR to ePrivacy: what does it mean to the advertising sector?
 
State of EU legislation: GDPR & ePrivacy for Superweek
State of EU legislation: GDPR & ePrivacy for SuperweekState of EU legislation: GDPR & ePrivacy for Superweek
State of EU legislation: GDPR & ePrivacy for Superweek
 
The Great GDPR MyData Debate - Aurelie Pols - Keynote
The Great GDPR MyData Debate - Aurelie Pols - KeynoteThe Great GDPR MyData Debate - Aurelie Pols - Keynote
The Great GDPR MyData Debate - Aurelie Pols - Keynote
 
The Data Subject First? Decoding the GDPR at StrataData
The Data Subject First? Decoding the GDPR at StrataDataThe Data Subject First? Decoding the GDPR at StrataData
The Data Subject First? Decoding the GDPR at StrataData
 
Brussels data science - Privacy Engineering for Big Data & Data Science
Brussels data science - Privacy Engineering for Big Data & Data ScienceBrussels data science - Privacy Engineering for Big Data & Data Science
Brussels data science - Privacy Engineering for Big Data & Data Science
 
Sibos INNOTRIBE Digital Ethics
Sibos INNOTRIBE Digital EthicsSibos INNOTRIBE Digital Ethics
Sibos INNOTRIBE Digital Ethics
 

Kürzlich hochgeladen

Week-01-2.ppt BBB human Computer interaction
Week-01-2.ppt BBB human Computer interactionWeek-01-2.ppt BBB human Computer interaction
Week-01-2.ppt BBB human Computer interactionfulawalesam
 
Call Girls Bannerghatta Road Just Call 👗 7737669865 👗 Top Class Call Girl Ser...
Call Girls Bannerghatta Road Just Call 👗 7737669865 👗 Top Class Call Girl Ser...Call Girls Bannerghatta Road Just Call 👗 7737669865 👗 Top Class Call Girl Ser...
Call Girls Bannerghatta Road Just Call 👗 7737669865 👗 Top Class Call Girl Ser...amitlee9823
 
Edukaciniai dropshipping via API with DroFx
Edukaciniai dropshipping via API with DroFxEdukaciniai dropshipping via API with DroFx
Edukaciniai dropshipping via API with DroFxolyaivanovalion
 
FESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdfFESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdfMarinCaroMartnezBerg
 
Vip Model Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...
Vip Model  Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...Vip Model  Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...
Vip Model Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...shivangimorya083
 
Schema on read is obsolete. Welcome metaprogramming..pdf
Schema on read is obsolete. Welcome metaprogramming..pdfSchema on read is obsolete. Welcome metaprogramming..pdf
Schema on read is obsolete. Welcome metaprogramming..pdfLars Albertsson
 
Carero dropshipping via API with DroFx.pptx
Carero dropshipping via API with DroFx.pptxCarero dropshipping via API with DroFx.pptx
Carero dropshipping via API with DroFx.pptxolyaivanovalion
 
VidaXL dropshipping via API with DroFx.pptx
VidaXL dropshipping via API with DroFx.pptxVidaXL dropshipping via API with DroFx.pptx
VidaXL dropshipping via API with DroFx.pptxolyaivanovalion
 
Best VIP Call Girls Noida Sector 39 Call Me: 8448380779
Best VIP Call Girls Noida Sector 39 Call Me: 8448380779Best VIP Call Girls Noida Sector 39 Call Me: 8448380779
Best VIP Call Girls Noida Sector 39 Call Me: 8448380779Delhi Call girls
 
BigBuy dropshipping via API with DroFx.pptx
BigBuy dropshipping via API with DroFx.pptxBigBuy dropshipping via API with DroFx.pptx
BigBuy dropshipping via API with DroFx.pptxolyaivanovalion
 
Call me @ 9892124323 Cheap Rate Call Girls in Vashi with Real Photo 100% Secure
Call me @ 9892124323  Cheap Rate Call Girls in Vashi with Real Photo 100% SecureCall me @ 9892124323  Cheap Rate Call Girls in Vashi with Real Photo 100% Secure
Call me @ 9892124323 Cheap Rate Call Girls in Vashi with Real Photo 100% SecurePooja Nehwal
 
Discover Why Less is More in B2B Research
Discover Why Less is More in B2B ResearchDiscover Why Less is More in B2B Research
Discover Why Less is More in B2B Researchmichael115558
 
Data-Analysis for Chicago Crime Data 2023
Data-Analysis for Chicago Crime Data  2023Data-Analysis for Chicago Crime Data  2023
Data-Analysis for Chicago Crime Data 2023ymrp368
 
Ravak dropshipping via API with DroFx.pptx
Ravak dropshipping via API with DroFx.pptxRavak dropshipping via API with DroFx.pptx
Ravak dropshipping via API with DroFx.pptxolyaivanovalion
 
Determinants of health, dimensions of health, positive health and spectrum of...
Determinants of health, dimensions of health, positive health and spectrum of...Determinants of health, dimensions of health, positive health and spectrum of...
Determinants of health, dimensions of health, positive health and spectrum of...shambhavirathore45
 
BabyOno dropshipping via API with DroFx.pptx
BabyOno dropshipping via API with DroFx.pptxBabyOno dropshipping via API with DroFx.pptx
BabyOno dropshipping via API with DroFx.pptxolyaivanovalion
 
Chintamani Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore ...
Chintamani Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore ...Chintamani Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore ...
Chintamani Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore ...amitlee9823
 

Kürzlich hochgeladen (20)

Week-01-2.ppt BBB human Computer interaction
Week-01-2.ppt BBB human Computer interactionWeek-01-2.ppt BBB human Computer interaction
Week-01-2.ppt BBB human Computer interaction
 
Call Girls Bannerghatta Road Just Call 👗 7737669865 👗 Top Class Call Girl Ser...
Call Girls Bannerghatta Road Just Call 👗 7737669865 👗 Top Class Call Girl Ser...Call Girls Bannerghatta Road Just Call 👗 7737669865 👗 Top Class Call Girl Ser...
Call Girls Bannerghatta Road Just Call 👗 7737669865 👗 Top Class Call Girl Ser...
 
CHEAP Call Girls in Saket (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Saket (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICECHEAP Call Girls in Saket (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
CHEAP Call Girls in Saket (-DELHI )🔝 9953056974🔝(=)/CALL GIRLS SERVICE
 
Edukaciniai dropshipping via API with DroFx
Edukaciniai dropshipping via API with DroFxEdukaciniai dropshipping via API with DroFx
Edukaciniai dropshipping via API with DroFx
 
FESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdfFESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdf
 
Vip Model Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...
Vip Model  Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...Vip Model  Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...
Vip Model Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...
 
Schema on read is obsolete. Welcome metaprogramming..pdf
Schema on read is obsolete. Welcome metaprogramming..pdfSchema on read is obsolete. Welcome metaprogramming..pdf
Schema on read is obsolete. Welcome metaprogramming..pdf
 
Carero dropshipping via API with DroFx.pptx
Carero dropshipping via API with DroFx.pptxCarero dropshipping via API with DroFx.pptx
Carero dropshipping via API with DroFx.pptx
 
Call Girls In Shalimar Bagh ( Delhi) 9953330565 Escorts Service
Call Girls In Shalimar Bagh ( Delhi) 9953330565 Escorts ServiceCall Girls In Shalimar Bagh ( Delhi) 9953330565 Escorts Service
Call Girls In Shalimar Bagh ( Delhi) 9953330565 Escorts Service
 
VidaXL dropshipping via API with DroFx.pptx
VidaXL dropshipping via API with DroFx.pptxVidaXL dropshipping via API with DroFx.pptx
VidaXL dropshipping via API with DroFx.pptx
 
Best VIP Call Girls Noida Sector 39 Call Me: 8448380779
Best VIP Call Girls Noida Sector 39 Call Me: 8448380779Best VIP Call Girls Noida Sector 39 Call Me: 8448380779
Best VIP Call Girls Noida Sector 39 Call Me: 8448380779
 
BigBuy dropshipping via API with DroFx.pptx
BigBuy dropshipping via API with DroFx.pptxBigBuy dropshipping via API with DroFx.pptx
BigBuy dropshipping via API with DroFx.pptx
 
Call me @ 9892124323 Cheap Rate Call Girls in Vashi with Real Photo 100% Secure
Call me @ 9892124323  Cheap Rate Call Girls in Vashi with Real Photo 100% SecureCall me @ 9892124323  Cheap Rate Call Girls in Vashi with Real Photo 100% Secure
Call me @ 9892124323 Cheap Rate Call Girls in Vashi with Real Photo 100% Secure
 
Discover Why Less is More in B2B Research
Discover Why Less is More in B2B ResearchDiscover Why Less is More in B2B Research
Discover Why Less is More in B2B Research
 
Data-Analysis for Chicago Crime Data 2023
Data-Analysis for Chicago Crime Data  2023Data-Analysis for Chicago Crime Data  2023
Data-Analysis for Chicago Crime Data 2023
 
Ravak dropshipping via API with DroFx.pptx
Ravak dropshipping via API with DroFx.pptxRavak dropshipping via API with DroFx.pptx
Ravak dropshipping via API with DroFx.pptx
 
Determinants of health, dimensions of health, positive health and spectrum of...
Determinants of health, dimensions of health, positive health and spectrum of...Determinants of health, dimensions of health, positive health and spectrum of...
Determinants of health, dimensions of health, positive health and spectrum of...
 
Delhi 99530 vip 56974 Genuine Escort Service Call Girls in Kishangarh
Delhi 99530 vip 56974 Genuine Escort Service Call Girls in  KishangarhDelhi 99530 vip 56974 Genuine Escort Service Call Girls in  Kishangarh
Delhi 99530 vip 56974 Genuine Escort Service Call Girls in Kishangarh
 
BabyOno dropshipping via API with DroFx.pptx
BabyOno dropshipping via API with DroFx.pptxBabyOno dropshipping via API with DroFx.pptx
BabyOno dropshipping via API with DroFx.pptx
 
Chintamani Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore ...
Chintamani Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore ...Chintamani Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore ...
Chintamani Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore ...
 

Responsible Data Uses: Privacy, Security, Ethics & Compliance

  • 1. @aureliepols Stockholm –March 2015#outfox2015 Responsible Data Uses: Privacy, Security, Ethics & Compliance Aurélie Pols Pan-European digital analytics veteran & Privacy geek Board Member @MyPermissions
  • 2. @aureliepols Stockholm –March 2015#outfox2015 Before frictionless sharing
  • 3. @aureliepols Stockholm –March 2015#outfox2015 We did optimize “stuff”
  • 4. @aureliepols Stockholm –March 2015#outfox2015 The era of Data Hoarding
  • 5. @aureliepols Stockholm –March 2015#outfox2015 DATA LEECHING While some refer to Data Puking, this is about
  • 6. @aureliepols Stockholm –March 2015#outfox2015 Data = New Asset Class • Economic asset: – if it’s worth something, who owns it? • Ownership means property: – Property law, contract law, etc. • But
  • 7. @aureliepols Stockholm –March 2015#outfox2015 DATA IS INFINITELY TRANSFERABLE WITHOUT DECAY #1. The specifics of Data as an Economic Asset
  • 8. @aureliepols Stockholm –March 2015#outfox2015 Familiar property types • House, mortgage & cadaster • A car looses 50% of it’s value the day after the purchase • But data? What is it really? HYPOTEK Fastighetsregistret
  • 9. @aureliepols Stockholm –March 2015#outfox2015 Infinitely transferable without decay • Interesting type of property • The legal world is not ready for • Yet harm is imaginable: – Deaths of dissidents – Algorithmic discrimination – Tunneled world vision – Identity thefts – Cyber bullying
  • 10. @aureliepols Stockholm –March 2015#outfox2015 DEFINING & RECOGNIZING DATA HARMS #2. Often forgotten legislative challenges
  • 11. @aureliepols Stockholm –March 2015#outfox2015 Involved actors • Legislators & governments: – make the laws & want to be re-elected • Businesses (employee, partner & customer data): – growth strategies, max shareholder value (not always) • Citizens: – consuming technology, are the product if free, co-owners of the data? Governments Legislators (FTC, FCC, FDA, EU) Consumers Voters Citizens OUR GLOBAL SOCIETY Businesses: Brands Data Service Providers
  • 12. @aureliepols Stockholm –March 2015#outfox2015 Data ownership? The Dutch KPN is a Dutch Telco Operations are in the Netherlands, Belgium & Germany Brands: Hi, Simyo, Telfort & KPN, XS4ALL, E- Plus & Base (sold to Telefonica)
  • 13. @aureliepols Stockholm –March 2015#outfox2015 Patchworks of legislation
  • 14. @aureliepols Stockholm –March 2015#outfox2015 Legislation about • Data-breaches!!! <- security • Copyright • Intellectual property <- algorithms • Net-neutrality • … Anonymity |Biometrics |CALEA |Cell Tracking |Cyber Security Legislation |Digital Books Do Not Track (DNT) |Encrypting the Web |International Privacy Standards |Locational Privacy Mandatory Data Retention |Mass Surveillance Technologies |Medical Privacy |National Security Letters NSA Spying |Online Behavioral Targeting (OBA) |Open Wireless |PATRIOT Act |Pen Trap |Printers |Real ID RFID |Search Engines |Search Incident to Arrest |Social Networks |Surveillance Drones |Travel Screening
  • 15. @aureliepols Stockholm –March 2015#outfox2015 4 topics 1. Security 2. Compliance 3. Privacy 4. Ethics
  • 16. @aureliepols Stockholm –March 2015#outfox2015 Europe: Data Protection
  • 17. @aureliepols Stockholm –March 2015#outfox2015 Security for digital analytics Mainly for (not mutually exclusive): – Access: employees, partners, APIs, … <- control & revoke procedures? Strong passwords? – Data transfers: between tools & devices, between companies <- level of encryption? Liability? – Data merging: which data set goes (or is copied) where? <- data breach notification requirements
  • 18. @aureliepols Stockholm –March 2015#outfox2015 COMPLIANCE IS A RISK EXERCISE #3. Related to evolving Privacy legislation
  • 19. @aureliepols Stockholm –March 2015#outfox2015 Privacy & Annoying Europeans
  • 20. @aureliepols Stockholm –March 2015#outfox2015 PII: ah but we don’t collect it! Medical information as PII California Arkansas Missouri New Hampshire North Dakota Texas Virginia Financial information as PII Alaska North Carolina Iowa North Dakota Kansas Oregon Massachusetts South Carolina Missouri Vermont Nevada Wisconsin New York* Wyoming Passwords as PII Georgia Maine Nebraska Biometric information as PII Iowa Nebraska North Carolina Wisconsin Source: information based on current continuous monitoring (partial results)
  • 21. @aureliepols Stockholm –March 2015#outfox2015 A Global Privacy Perspective US & UK EU ASIA Common Law Continental Law Partially continental law influenced Class actions Fines (by DPAs: Data Protection Agencies) Amended New Privacy Personal Data Protection (PDP) Business focused Citizen focused: data belongs to the visitor/prospect/consumer/citizen Patchwork of sector based legislations: HIPAA, COPPA, VPPA, … Over-arching EU Directives & Regulations PII: varies per US state “Personal Data” => Risk levels: low, medium, high, extremely high
  • 22. @aureliepols Stockholm –March 2015#outfox2015 Low Risk Medium Risk (profiling) High Risk (sensitive) R i s k L e v e l Data type Information Security Measures Extremely High Risk (profiling of sensitive data)PII PII vs. Risk Levels
  • 23. @aureliepols Stockholm –March 2015#outfox2015 Data Science concerns? • As a Data Scientist: doing the best analysis • As an employee: not getting my company into trouble • As a citizen: – Lack of transparency <- loss of control that could lead to discrimination – Identity theft – Tunneled view of the world
  • 24. @aureliepols Stockholm –March 2015#outfox2015 What do analytics tools propose? Let’s take Google Analytics: • Anonymizing IP addresses • Implementing opt-out mechanisms • Not using cookies • Complying with DNT • Forcing SSL • Disabling data sharing Source: http://gu.illau.me/posts/privacy-and-google-analytics/
  • 25. @aureliepols Stockholm –March 2015#outfox2015 Source: http://dynamical.biz/ blog/technical- analytics/collecting- ga-userid-into-ga-can- violate-google- analytics-tos-75.html
  • 26. @aureliepols Stockholm –March 2015#outfox2015 Data tension due to data leeching Analytics capabilities Customer feelings of creepiness Harm? Data quality?
  • 27. @aureliepols Stockholm –March 2015#outfox2015 Privacy Role Playing in the EU
  • 28. @aureliepols Stockholm –March 2015#outfox2015 Rights & obligations Roles and responsibilities Data controller must: • Process legally & fairly • Collect for explicit & legitimate purposes • Not excessively • Keep data accurate & updated • Allow for rectification • Respect data retention periods • Protect personal data, appropriate to the type of data held
  • 29. @aureliepols Stockholm –March 2015#outfox2015 UNDERSTAND YOUR LIABILITY WITHIN THE DATA ECOSYSTEM #4. Minimizing Privacy related Risks?
  • 30. @aureliepols Stockholm –March 2015#outfox2015 Who is liable here?
  • 31. @aureliepols Stockholm –March 2015#outfox2015 iBeacons, Mondelez: Creepy?
  • 32. @aureliepols Stockholm –March 2015#outfox2015 EU GDPR affecting Data Science • Collaboration & Responsibility (not only legal) – Privacy training & escalation procedures • Data lineage & consent management – Understanding where the data comes from – Manage individual choices & consent
  • 33. @aureliepols Stockholm –March 2015#outfox2015 EU GDPR affecting Data Science • Change to the data value exchange – Maintaining quality of data collected & analyzed • Commercial advantages – Increased Trust; reduced Brand Erosion due to unsystematic Privacy management – Better data governance, optimized use of Data Science
  • 34. @aureliepols Stockholm –March 2015#outfox2015 1 legal concept to rule them all FIPPs: Fair information Practice Principles Transparency Choice Information review & correction Information protection Accountability
  • 35. @aureliepols Stockholm –March 2015#outfox2015 Open discussion Aurélie Pols

Hinweis der Redaktion

  1. Aurélie would explain the differences between the 4th amendment and article 8
  2. Aurélie would explain this slide and then Simon to take over and ask the crowd: what are you guys worried about?
  3. Aurélie would explain the roles of data controllers & processors + go through the current obligations
  4. Aurélie to explain this one
  5. Simon to lead on here