SlideShare ist ein Scribd-Unternehmen logo
1 von 31
Downloaden Sie, um offline zu lesen
© 2017 ForgeRock. All rights reserved.
GDPR Is Coming In Hot: Top Burning Questions
Answered To Help You Keep Your Cool
Eve Maler @xmlgrrl
VP Innovation & Emerging Technology,
ForgeRock
Sean Doherty @SeanD0herty
Analyst, Workforce Productivity &
Compliance Channel, 451 Research
July 25, 2017
© 2017 ForgeRock. All rights reserved.
Eve Maler @xmlgrrl
VP Innovation & Emerging Technology,
ForgeRock
Sean Doherty @SeanD0herty
Analyst, Workforce Productivity &
Compliance Channel, 451 Research
451 Research is an information
technology research & advisory company
Founded	in	2000
300+	employees,	including	over	100	analysts
1,000+	clients:	Technology	&	Service	providers,	corporate	
advisory,	finance,	professional	services,	and	IT	decision	makers
50,000+	senior	IT	professionals	in	our	research	community
Over	52	million	data	points	each	quarter
4,500+	reports	published	each	year	covering	2,000+	
innovative	technology	&	service	providers
451	Research	and	its	sister	company	Uptime	Institute	
comprise	the	two	divisions	of	The	451	Group
Headquartered	in	New	York	City	with	offices	in	London,	
Boston,	San	Francisco,	Washington	D.C.,	Mexico,	Costa	Rica,	Brazil,	Spain,	
U.A.E.,	Russia,	Taiwan,	Singapore,	and	Malaysia	
Research	&	Data
Advisory	Services
Events
GDPR: when and where?
• Effective	and	enforced	on	May	25,	2018,	replacing	the	1998	Data	Protection	Directive	(95/46/EC).
• The	regulation	requires	member	countries	to	follow	and	enforce	the	GDPR	without	passing	local	legislation.
• The	regulation	applies	to:
1. The	processing	of	personal	data	from	the	activities	of	an	establishment	of	a	controller	or	processor	in	the	EU;	
or
2. A	controller	or	processor	not	established	in	the	EU,	where	personal	data	collection	and	processing	is	related	to	
the	offering	of	goods	or	services	to	data	subjects	in	the	EU	or	the	processing	monitors	data	subjects	behavior	
in	the	EU.
GDPR definitions
Personal	data	means	any	information	relating	to	an	identifiable	natural	person	(data	subject),	i.e.,	one	that	can	be	
identified,	directly	or	indirectly,	from	a	name,	identification	number,	location	data,	online	identifier	or	other	factors	
specific	to	physical,	genetic,	economic,	or	social	identity	of	the	data	subject.	Art.	4(1).
Processing means	any	operation	performed	on	personal	data,	such	as	collection,	recording,	organizing,	and	storing.	
Art.	4(2).
A	controller is	a	person	or	organization	that	determines	the	purposes	and	means	of	processing	personal	data.	Art.	
4(7).
A	processor is	a	person	or	organization	that	processes	personal	data	on	behalf	of	a	controller.	Art.	4(8).
5
GDPR effect: not a butterfly but a bee
Violations	of	the	GDPR	can	cost	up	to	€20m	in	fines	or	up	to	4%	of	a	controller’s	or	processor’s	previous	year’s	
worldwide	revenue.
Requires	data	controllers	and	processors	to	hire	a	data	protection	officer	for
regular	and	systematic	monitoring	of	data	subjects	on	a	large	scale.
Mandatory	data	breach	notifications	to	data	subjects	within	72	hours	of	the	breach.
Gives	EU	residents	more	control	of	their	personal	data
• Prohibit	data	processing	beyond	its	specified	purpose.
• The	right	to	correct	(rectify)	and	delete	(erasure)	or	be	forgotten.
• Withdraw	consent	to	data	processing.
Data	subjects	and	nonprofit	organizations	on	behalf	of	data	subjects	can	bring	actions	directly	against	data	
controllers	and	processors	for	GDPR	violations.
6
© Teguh Mujiono
© 2017 ForgeRock. All rights reserved.
The EU General Data Protection
Regulation: It’s different this time
• Firm deadline, big penalties, high
aspirations…and viral
• “Data protection” encompasses a wide variety
of data transparency and data control
requirements
© 2017 ForgeRock. All rights reserved.
https://www.flickr.com/photos/adpowers/16808090/	|	CC	BY	2.0
Take steps
Identify intersections
between digital transformation
opportunities and user trust risks
Conceive of personal data as a joint
asset
Lean in to consent
Take advantage of identity and
access management for building
trust
© 2017 ForgeRock. All rights reserved.
We asked what you wanted to know –
and you let us have it
https://www.flickr.com/photos/infomastern/11459954985/	|	CC	BY-SA	2.0
© 2017 ForgeRock. All rights reserved.
My company interacts with end-users directly and holds
user account data. When sending such data from
Australia to, say, the US, what regulation applies:
Australia, US, EU...?
Q1
© 2017 ForgeRock. All rights reserved.
What is the relation of Privacy Shield to GDPR?
Q2
© 2017 ForgeRock. All rights reserved.
Does GDPR require that I store data
about my customers in the country it
was collected in?
How does it work in the ForgeRock
Identity Platform to store identity
profile data within a specific region?
Q3b
Q3a
© 2017 ForgeRock. All rights reserved.
The ForgeRock Identity Platform
DIRECTORY SERVICES
ACCESS MANAGEMENT IDENTITY MANAGEMENT IDENTITY GATEWAYCOMMON SERVICES
IDM IG
DS
AM
Authentication Authorization Provisioning Reconciliation Authentication OIDC/OAuth
Federation
Adaptive Risk
Stateless &
Stateful
UMA Provider Mobile App
User Self Service
Workflow
Engine
Registration
Single View of
Customer
Synchronization
Password
Management
Password
Replay
SAML
Token
Transformation
UMA
Protector
API Security Throttling
Common Scripting
Common
Audit/Logging
Common User
Interface
Common REST API
LDAPv3
Replication
REST/JSON
Access
Control
Schema
Management
Caching
Auditing
Monitoring
Groups
Password
Policy
AD Pass
Through
Reporting
CS
© 2017 ForgeRock. All rights reserved.
Data sovereignty and fractional
replication
Global User Profile
(has all user attributes)
• Contains subset
of complete user
profile
• Fractional
replication within
each jurisdiction
© 2017 ForgeRock. All rights reserved.
If a US employee of my organization uses a VPN
connection back to the home office while in another
office that’s located in the EU, what regulation applies:
US, EU…?
Q4
© 2017 ForgeRock. All rights reserved.
What do data encryption techniques
have to do with GDPR?
How does it work in the ForgeRock
Identity Platform to encrypt and
protect identity attributes?
Q5b
Q5a
© 2017 ForgeRock. All rights reserved.
DIRECTORY SERVICES
Many layers of protection for personal
data
ACCESS MANAGEMENT IDENTITY MANAGEMENT IDENTITY GATEWAYCOMMON SERVICES
IDM IG
DS
AM
CS
• On-disk encryption of data and indexes
• Access controls to prevent unauthorized users from reading data
• Encrypted backups
• Tamper-
proofed audit
logging,
depending on
the “sink”
chosen
• Logging only
of the user
identifier, not
of profile
content
• Token proof of
possession available to
ensure the bearer is the
rightful owner
• Signing and encryption
for JWTs, id_tokens,
SAML assertions,
UserInfo responses
• Contextual authorization
• Encryption of
credentials and profile
attributes
• Encryption or hashing
of data during
synchronization
• Contextual authorization
• Message header
encryption
© 2017 ForgeRock. All rights reserved.
Does an individual have a “right to update” data?
Q6
© 2017 ForgeRock. All rights reserved.
If my organization has shared end-user data with a
third party, and our end-user asks for it to be deleted,
whose responsibility is it to delete it?
Q7
© 2017 ForgeRock. All rights reserved.
When does GDPR say I have to go
back to an end-user and ask for their
consent to process their data again
after collecting it a first time?
When is it possible to ask for an end-
user’s consent using the ForgeRock
Identity Platform?
Q8b
Q8a
© 2017 ForgeRock. All rights reserved.
Moments of consent
Registration time Authentication time
Access approval
(asynchronous)
© 2017 ForgeRock. All rights reserved.
I’ve heard my organization will have to
change all of our consent collection
practices because of GDPR – is that
true?
What consent lifecycle management
capabilities does the ForgeRock
Identity Platform have?
Q9b
Q9a
© 2017 ForgeRock. All rights reserved.
Single view of the
consumer
Giving the consumer a
single view of their
consents
Giving the consumer
control over their
consents
● Lifecycle
management of a
user profile and their
data sharing
preferences
● Secure storage of
profile data
● Anonymized syncing
of profile data and
connector-based
integration to third-
party systems
● Terms of service and
privacy policy capture
● Social sign-in
● Social registration
● Social consent
management
● Interoperable, user-
driven, proactive and
reactive sharing flows
The holistic view of consent
lifecycle management
© 2017 ForgeRock. All rights reserved.
Patient selectively sharing IoT health data with doctors
and other caregivers with User-Managed Access (UMA)
Patient view Doctor view
© 2017 ForgeRock. All rights reserved.
Granular consented access by accountant to bank
customer’s account data and transactions
25
© 2017 ForgeRock. All rights reserved.
What does GDPR say about parental
consent, and what is the age of
majority?
What are the capabilities of the
ForgeRock Identity Platform regarding
parental consent?
Q10b
Q10a
© 2017 ForgeRock. All rights reserved.
Typical parent/child account
relationship and capabilities
Parent/Guardian Account
• Can self-register
• Can create and
manage age-
constrained accounts
• Full schema and
permissions
• Access approval
options, e.g. through
UMA constrained
delegation
Child Account
• Not allowed to self-
register
• Jurisdictionally
defined age-
constrained account
• Limited schema and
permissions
© 2017 ForgeRock. All rights reserved.
We’d like to show
you what we’ve got
cooking
https://www.flickr.com/photos/carree/2502801336/	|	CC	BY-ND	2.0
© 2017 ForgeRock. All rights reserved.
Profile and Privacy
Management Dashboard:
It’s all about self-service
for…
• The right to be informed
• The right of access
• The right to rectification
• The right to erasure
• The right to restrict processing
• The right to data portability
• The right to object
• Convenient and centralized data
protection, transparency, and
control
demo
© 2017 ForgeRock. All rights reserved.
Thank You!
Questions?Eve Maler
VP Innovation & Emerging
Technology, ForgeRock
@xmlgrrl
Sean Doherty
Analyst, Workforce
Productivity & Compliance
Channel, 451 Research
@SeanD0herty
© 2017 ForgeRock. All rights reserved.
summits.forgerock.com

Weitere ähnliche Inhalte

Was ist angesagt?

Was ist angesagt? (20)

Identity Live Sydney 2017 - Ashley Stevenson
Identity Live Sydney 2017 - Ashley StevensonIdentity Live Sydney 2017 - Ashley Stevenson
Identity Live Sydney 2017 - Ashley Stevenson
 
Identity Live London 2017 | Ashley Stevenson
Identity Live London 2017 | Ashley StevensonIdentity Live London 2017 | Ashley Stevenson
Identity Live London 2017 | Ashley Stevenson
 
Identity Live Paris 2017 | Mike Ellis
Identity Live Paris 2017 | Mike EllisIdentity Live Paris 2017 | Mike Ellis
Identity Live Paris 2017 | Mike Ellis
 
Amer Sports - ForgeRock Identity Live - Dusseldorf
Amer Sports - ForgeRock Identity Live - DusseldorfAmer Sports - ForgeRock Identity Live - Dusseldorf
Amer Sports - ForgeRock Identity Live - Dusseldorf
 
IAM for the Masses: Managing Consumer Identities
IAM for the Masses: Managing Consumer Identities IAM for the Masses: Managing Consumer Identities
IAM for the Masses: Managing Consumer Identities
 
ForgeRock Gartner 2016 Security & Risk Management Summit
ForgeRock Gartner 2016 Security & Risk Management Summit ForgeRock Gartner 2016 Security & Risk Management Summit
ForgeRock Gartner 2016 Security & Risk Management Summit
 
Connected Car: Putting Digital Identity Behind the Wheel
Connected Car: Putting Digital Identity Behind the WheelConnected Car: Putting Digital Identity Behind the Wheel
Connected Car: Putting Digital Identity Behind the Wheel
 
Identity Live Sydney 2017 - Ian Sorbello
Identity Live Sydney 2017 - Ian SorbelloIdentity Live Sydney 2017 - Ian Sorbello
Identity Live Sydney 2017 - Ian Sorbello
 
Identity Live Sydney: Building Trust and Privacy in a Connected Society
Identity Live  Sydney:  Building Trust and Privacy in a Connected SocietyIdentity Live  Sydney:  Building Trust and Privacy in a Connected Society
Identity Live Sydney: Building Trust and Privacy in a Connected Society
 
Sydney Identity Summit: Compound Eye: An Approach To A National Identity Ecos...
Sydney Identity Summit: Compound Eye: An Approach To A National Identity Ecos...Sydney Identity Summit: Compound Eye: An Approach To A National Identity Ecos...
Sydney Identity Summit: Compound Eye: An Approach To A National Identity Ecos...
 
IoT Wonderland: Understanding the Magic of OAuth2 Device Registration Flow
IoT Wonderland: Understanding the Magic of OAuth2 Device Registration FlowIoT Wonderland: Understanding the Magic of OAuth2 Device Registration Flow
IoT Wonderland: Understanding the Magic of OAuth2 Device Registration Flow
 
2015 Identity Summit - CTO Innovation Center
2015 Identity Summit - CTO Innovation Center2015 Identity Summit - CTO Innovation Center
2015 Identity Summit - CTO Innovation Center
 
Securing Access to SaaS Apps with WSO2 Identity Server
Securing Access to SaaS Apps with WSO2 Identity ServerSecuring Access to SaaS Apps with WSO2 Identity Server
Securing Access to SaaS Apps with WSO2 Identity Server
 
Hermann Wimmer - ForgeRock Identity Live 2017 - Dusseldorf
Hermann Wimmer - ForgeRock Identity Live 2017 - DusseldorfHermann Wimmer - ForgeRock Identity Live 2017 - Dusseldorf
Hermann Wimmer - ForgeRock Identity Live 2017 - Dusseldorf
 
Victor Ake and Chris Kawalek - ForgeRock Identity Live 2017 - Dusseldorf
Victor Ake and Chris Kawalek - ForgeRock Identity Live 2017 - DusseldorfVictor Ake and Chris Kawalek - ForgeRock Identity Live 2017 - Dusseldorf
Victor Ake and Chris Kawalek - ForgeRock Identity Live 2017 - Dusseldorf
 
Identity Objects in Mirror Are Closer Than They Appear - Identity Live 2017 -...
Identity Objects in Mirror Are Closer Than They Appear - Identity Live 2017 -...Identity Objects in Mirror Are Closer Than They Appear - Identity Live 2017 -...
Identity Objects in Mirror Are Closer Than They Appear - Identity Live 2017 -...
 
2015 Identity Summit - Stepping Up to New Data Protection Challenges
2015 Identity Summit - Stepping Up to New Data Protection Challenges2015 Identity Summit - Stepping Up to New Data Protection Challenges
2015 Identity Summit - Stepping Up to New Data Protection Challenges
 
The Future of Digital Identity in the Age of the Internet of Things
The Future of Digital Identity in the Age of the Internet of ThingsThe Future of Digital Identity in the Age of the Internet of Things
The Future of Digital Identity in the Age of the Internet of Things
 
Identity Live Paris 2017 | Monetising Digital Customer Relationships
Identity Live Paris 2017 | Monetising Digital Customer RelationshipsIdentity Live Paris 2017 | Monetising Digital Customer Relationships
Identity Live Paris 2017 | Monetising Digital Customer Relationships
 
Optimize Your Zero Trust Infrastructure
Optimize Your Zero Trust InfrastructureOptimize Your Zero Trust Infrastructure
Optimize Your Zero Trust Infrastructure
 

Andere mochten auch

Analyst Keynote: Putting Customers First Requires Innovation and Identity - P...
Analyst Keynote: Putting Customers First Requires Innovation and Identity - P...Analyst Keynote: Putting Customers First Requires Innovation and Identity - P...
Analyst Keynote: Putting Customers First Requires Innovation and Identity - P...
ForgeRock
 

Andere mochten auch (18)

The ForgeRock Identity Platform Extends CIAM, Fall 2017 Release
The ForgeRock Identity Platform Extends CIAM, Fall 2017 ReleaseThe ForgeRock Identity Platform Extends CIAM, Fall 2017 Release
The ForgeRock Identity Platform Extends CIAM, Fall 2017 Release
 
Identity Live Sydney 2017 - Allan Foster & Eve Maler
Identity Live Sydney 2017 - Allan Foster & Eve MalerIdentity Live Sydney 2017 - Allan Foster & Eve Maler
Identity Live Sydney 2017 - Allan Foster & Eve Maler
 
Identity Live London 2017 | Kenneth May
Identity Live London 2017 | Kenneth MayIdentity Live London 2017 | Kenneth May
Identity Live London 2017 | Kenneth May
 
T-Systems. Automating ForgeRock Full Stack Deployments to a Magenta Cloud.
T-Systems. Automating ForgeRock Full Stack Deployments to a Magenta Cloud.T-Systems. Automating ForgeRock Full Stack Deployments to a Magenta Cloud.
T-Systems. Automating ForgeRock Full Stack Deployments to a Magenta Cloud.
 
OpenAM - An Introduction
OpenAM - An IntroductionOpenAM - An Introduction
OpenAM - An Introduction
 
Implications of GDPR in Conjunction with UMA
Implications of GDPR in Conjunction with UMAImplications of GDPR in Conjunction with UMA
Implications of GDPR in Conjunction with UMA
 
Keynote: Tech, Trust, and Transformation - Paris Identity Summit 2016
Keynote: Tech, Trust, and Transformation - Paris Identity Summit 2016Keynote: Tech, Trust, and Transformation - Paris Identity Summit 2016
Keynote: Tech, Trust, and Transformation - Paris Identity Summit 2016
 
The Business Ecosystem is a Neighborhood - ForgeRock Identity Live Austin 2017
The Business Ecosystem is a Neighborhood - ForgeRock Identity Live Austin 2017The Business Ecosystem is a Neighborhood - ForgeRock Identity Live Austin 2017
The Business Ecosystem is a Neighborhood - ForgeRock Identity Live Austin 2017
 
HSBC - ForgeRock Identity Summit 2017 Dusseldorf
HSBC - ForgeRock Identity Summit 2017 DusseldorfHSBC - ForgeRock Identity Summit 2017 Dusseldorf
HSBC - ForgeRock Identity Summit 2017 Dusseldorf
 
OpenAM: An Introduction
OpenAM: An IntroductionOpenAM: An Introduction
OpenAM: An Introduction
 
Keynote : Customer Identity Builds Digital Trust - Paris Identity Summit
Keynote : Customer Identity Builds Digital Trust - Paris Identity SummitKeynote : Customer Identity Builds Digital Trust - Paris Identity Summit
Keynote : Customer Identity Builds Digital Trust - Paris Identity Summit
 
DevOps Unleashed: Strategies that Speed Deployments
DevOps Unleashed: Strategies that Speed DeploymentsDevOps Unleashed: Strategies that Speed Deployments
DevOps Unleashed: Strategies that Speed Deployments
 
Winning with GDPR: How to Win Customer Loyalty and Trust
Winning with GDPR: How to Win Customer Loyalty and TrustWinning with GDPR: How to Win Customer Loyalty and Trust
Winning with GDPR: How to Win Customer Loyalty and Trust
 
Identity Live Sydney 2017 - Tim Sheedy
Identity Live Sydney 2017 - Tim SheedyIdentity Live Sydney 2017 - Tim Sheedy
Identity Live Sydney 2017 - Tim Sheedy
 
A Backstage Tour of Identity - Paris Identity Summit 2016
A Backstage Tour of Identity - Paris Identity Summit 2016A Backstage Tour of Identity - Paris Identity Summit 2016
A Backstage Tour of Identity - Paris Identity Summit 2016
 
Analyst Keynote: Putting Customers First Requires Innovation and Identity - P...
Analyst Keynote: Putting Customers First Requires Innovation and Identity - P...Analyst Keynote: Putting Customers First Requires Innovation and Identity - P...
Analyst Keynote: Putting Customers First Requires Innovation and Identity - P...
 
The Future is Now: The ForgeRock Identity Platform, Early 2017 Release
The Future is Now: The ForgeRock Identity Platform, Early 2017 ReleaseThe Future is Now: The ForgeRock Identity Platform, Early 2017 Release
The Future is Now: The ForgeRock Identity Platform, Early 2017 Release
 
The digital pains of retail
The digital pains of retailThe digital pains of retail
The digital pains of retail
 

Ähnlich wie GDPR is coming in Hot. Top Burning Questions Answered to Help You Keep Your Cool.

Ähnlich wie GDPR is coming in Hot. Top Burning Questions Answered to Help You Keep Your Cool. (20)

How Cloudera SDX can aid GDPR compliance
How Cloudera SDX can aid GDPR complianceHow Cloudera SDX can aid GDPR compliance
How Cloudera SDX can aid GDPR compliance
 
Digital Trust: How Identity Tackles the Privacy, Security and IoT Challenge
Digital Trust: How Identity Tackles the Privacy, Security and IoT ChallengeDigital Trust: How Identity Tackles the Privacy, Security and IoT Challenge
Digital Trust: How Identity Tackles the Privacy, Security and IoT Challenge
 
The Road to Intelligent Authentication Journeys
The Road to Intelligent Authentication JourneysThe Road to Intelligent Authentication Journeys
The Road to Intelligent Authentication Journeys
 
Smart Contracts and Blockchain: Separating Hype from Reality
Smart Contracts and Blockchain: Separating Hype from RealitySmart Contracts and Blockchain: Separating Hype from Reality
Smart Contracts and Blockchain: Separating Hype from Reality
 
The Value of User and Data Centricity Beyond IoT Devices: Stein Myrseth and G...
The Value of User and Data Centricity Beyond IoT Devices: Stein Myrseth and G...The Value of User and Data Centricity Beyond IoT Devices: Stein Myrseth and G...
The Value of User and Data Centricity Beyond IoT Devices: Stein Myrseth and G...
 
The Future is Now: What’s New in ForgeRock Identity Management
The Future is Now: What’s New in ForgeRock Identity Management The Future is Now: What’s New in ForgeRock Identity Management
The Future is Now: What’s New in ForgeRock Identity Management
 
Ping Identity: Corporate Overview Financial Services
Ping Identity: Corporate Overview Financial ServicesPing Identity: Corporate Overview Financial Services
Ping Identity: Corporate Overview Financial Services
 
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
 
Applying Innovative Tools for GDPR Success
Applying Innovative Tools for GDPR SuccessApplying Innovative Tools for GDPR Success
Applying Innovative Tools for GDPR Success
 
lendingQB: A Mortgage Loan Origination System by MeridianLink
lendingQB: A Mortgage Loan Origination System by MeridianLinklendingQB: A Mortgage Loan Origination System by MeridianLink
lendingQB: A Mortgage Loan Origination System by MeridianLink
 
The Super Broken Story of the True Digital Identity
The Super Broken Story of the True Digital IdentityThe Super Broken Story of the True Digital Identity
The Super Broken Story of the True Digital Identity
 
Tivi - Tunnistautuminen - 2020
Tivi - Tunnistautuminen - 2020Tivi - Tunnistautuminen - 2020
Tivi - Tunnistautuminen - 2020
 
Intelligent Authentication (Identity Live Berlin 2018)
Intelligent Authentication  (Identity Live Berlin 2018)Intelligent Authentication  (Identity Live Berlin 2018)
Intelligent Authentication (Identity Live Berlin 2018)
 
File Sharing Use Cases in Financial Services
File Sharing Use Cases in Financial ServicesFile Sharing Use Cases in Financial Services
File Sharing Use Cases in Financial Services
 
Doing Authorisation, Consent, and Delegation Right with UMA - Paris Identity ...
Doing Authorisation, Consent, and Delegation Right with UMA - Paris Identity ...Doing Authorisation, Consent, and Delegation Right with UMA - Paris Identity ...
Doing Authorisation, Consent, and Delegation Right with UMA - Paris Identity ...
 
Driving Digital Transformation through Big Data Analytics and Machine Learning
Driving Digital Transformation through Big Data Analytics and Machine LearningDriving Digital Transformation through Big Data Analytics and Machine Learning
Driving Digital Transformation through Big Data Analytics and Machine Learning
 
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
 
Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs S...
Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs S...Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs S...
Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs S...
 
Security in the Hybrid Cloud at Liberty Mutual
Security in the Hybrid Cloud at Liberty MutualSecurity in the Hybrid Cloud at Liberty Mutual
Security in the Hybrid Cloud at Liberty Mutual
 
Rethinking Trust in Data
Rethinking Trust in Data Rethinking Trust in Data
Rethinking Trust in Data
 

Mehr von ForgeRock

Mehr von ForgeRock (20)

Get the Exact Identity Solution You Need - In the Cloud - AWS and Beyond
Get the Exact Identity Solution You Need - In the Cloud - AWS and BeyondGet the Exact Identity Solution You Need - In the Cloud - AWS and Beyond
Get the Exact Identity Solution You Need - In the Cloud - AWS and Beyond
 
Identity Live Sydney: Identity Management - A Strategic Opportunity
Identity Live Sydney: Identity Management  - A Strategic OpportunityIdentity Live Sydney: Identity Management  - A Strategic Opportunity
Identity Live Sydney: Identity Management - A Strategic Opportunity
 
Identity Live Singapore: Transform Your Cybersecurity Capability
Identity Live Singapore: Transform Your Cybersecurity CapabilityIdentity Live Singapore: Transform Your Cybersecurity Capability
Identity Live Singapore: Transform Your Cybersecurity Capability
 
Identity Live Singapore 2018 Keynote Presentation
Identity Live Singapore 2018 Keynote PresentationIdentity Live Singapore 2018 Keynote Presentation
Identity Live Singapore 2018 Keynote Presentation
 
Identity Live Sydney 2018 Keynote Presentation
Identity Live Sydney 2018 Keynote PresentationIdentity Live Sydney 2018 Keynote Presentation
Identity Live Sydney 2018 Keynote Presentation
 
Identity Live Singapore: Just Ask 'Em
Identity Live Singapore: Just Ask 'EmIdentity Live Singapore: Just Ask 'Em
Identity Live Singapore: Just Ask 'Em
 
Identity Live Singapore: Building Trust & Privacy in a Connected Society
Identity Live Singapore: Building Trust & Privacy in a Connected SocietyIdentity Live Singapore: Building Trust & Privacy in a Connected Society
Identity Live Singapore: Building Trust & Privacy in a Connected Society
 
Get the Exact Identity Solution you Need in the Cloud - Deep Dive
Get the Exact Identity Solution you Need in the Cloud - Deep DiveGet the Exact Identity Solution you Need in the Cloud - Deep Dive
Get the Exact Identity Solution you Need in the Cloud - Deep Dive
 
Get the Exact Identity Solution You Need - In the Cloud - Overview
Get the Exact Identity Solution You Need - In the Cloud - OverviewGet the Exact Identity Solution You Need - In the Cloud - Overview
Get the Exact Identity Solution You Need - In the Cloud - Overview
 
Opening Keynote (Identity Live Berlin 2018)
Opening Keynote (Identity Live Berlin 2018)Opening Keynote (Identity Live Berlin 2018)
Opening Keynote (Identity Live Berlin 2018)
 
Steinberg - Customer identity as the cornerstone of our approach to digitaliz...
Steinberg - Customer identity as the cornerstone of our approach to digitaliz...Steinberg - Customer identity as the cornerstone of our approach to digitaliz...
Steinberg - Customer identity as the cornerstone of our approach to digitaliz...
 
BMW Group - Identity Enables the Next 100 Years.. (Identity Live Berlin 2018)
BMW Group - Identity Enables the Next 100 Years..  (Identity Live Berlin 2018)BMW Group - Identity Enables the Next 100 Years..  (Identity Live Berlin 2018)
BMW Group - Identity Enables the Next 100 Years.. (Identity Live Berlin 2018)
 
Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...
Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...
Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...
 
Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...
Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...
Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...
 
Shift from GDPR readiness to sustained compliance to improve your business an...
Shift from GDPR readiness to sustained compliance to improve your business an...Shift from GDPR readiness to sustained compliance to improve your business an...
Shift from GDPR readiness to sustained compliance to improve your business an...
 
Customer Safeguarding, Fraud and GDPR: Manah Khalil
Customer Safeguarding, Fraud and GDPR: Manah KhalilCustomer Safeguarding, Fraud and GDPR: Manah Khalil
Customer Safeguarding, Fraud and GDPR: Manah Khalil
 
What the Internet of Things Means for Consumer Privacy: Veronica Lara
What the Internet of Things Means for Consumer Privacy: Veronica LaraWhat the Internet of Things Means for Consumer Privacy: Veronica Lara
What the Internet of Things Means for Consumer Privacy: Veronica Lara
 
Identity Live in Austin Keynote
Identity Live in Austin Keynote Identity Live in Austin Keynote
Identity Live in Austin Keynote
 
Where Biometrics, Blockchains, and Bots are Taking Digital Identity: David Birch
Where Biometrics, Blockchains, and Bots are Taking Digital Identity: David BirchWhere Biometrics, Blockchains, and Bots are Taking Digital Identity: David Birch
Where Biometrics, Blockchains, and Bots are Taking Digital Identity: David Birch
 
Go Beyond PSD2 Compliance with Digital Identity
Go Beyond PSD2 Compliance with Digital Identity Go Beyond PSD2 Compliance with Digital Identity
Go Beyond PSD2 Compliance with Digital Identity
 

Kürzlich hochgeladen

Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Victor Rentea
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

Kürzlich hochgeladen (20)

Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
Six Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal OntologySix Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal Ontology
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital Adaptability
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 

GDPR is coming in Hot. Top Burning Questions Answered to Help You Keep Your Cool.

  • 1. © 2017 ForgeRock. All rights reserved. GDPR Is Coming In Hot: Top Burning Questions Answered To Help You Keep Your Cool Eve Maler @xmlgrrl VP Innovation & Emerging Technology, ForgeRock Sean Doherty @SeanD0herty Analyst, Workforce Productivity & Compliance Channel, 451 Research July 25, 2017
  • 2. © 2017 ForgeRock. All rights reserved. Eve Maler @xmlgrrl VP Innovation & Emerging Technology, ForgeRock Sean Doherty @SeanD0herty Analyst, Workforce Productivity & Compliance Channel, 451 Research
  • 3. 451 Research is an information technology research & advisory company Founded in 2000 300+ employees, including over 100 analysts 1,000+ clients: Technology & Service providers, corporate advisory, finance, professional services, and IT decision makers 50,000+ senior IT professionals in our research community Over 52 million data points each quarter 4,500+ reports published each year covering 2,000+ innovative technology & service providers 451 Research and its sister company Uptime Institute comprise the two divisions of The 451 Group Headquartered in New York City with offices in London, Boston, San Francisco, Washington D.C., Mexico, Costa Rica, Brazil, Spain, U.A.E., Russia, Taiwan, Singapore, and Malaysia Research & Data Advisory Services Events
  • 4. GDPR: when and where? • Effective and enforced on May 25, 2018, replacing the 1998 Data Protection Directive (95/46/EC). • The regulation requires member countries to follow and enforce the GDPR without passing local legislation. • The regulation applies to: 1. The processing of personal data from the activities of an establishment of a controller or processor in the EU; or 2. A controller or processor not established in the EU, where personal data collection and processing is related to the offering of goods or services to data subjects in the EU or the processing monitors data subjects behavior in the EU.
  • 6. GDPR effect: not a butterfly but a bee Violations of the GDPR can cost up to €20m in fines or up to 4% of a controller’s or processor’s previous year’s worldwide revenue. Requires data controllers and processors to hire a data protection officer for regular and systematic monitoring of data subjects on a large scale. Mandatory data breach notifications to data subjects within 72 hours of the breach. Gives EU residents more control of their personal data • Prohibit data processing beyond its specified purpose. • The right to correct (rectify) and delete (erasure) or be forgotten. • Withdraw consent to data processing. Data subjects and nonprofit organizations on behalf of data subjects can bring actions directly against data controllers and processors for GDPR violations. 6 © Teguh Mujiono
  • 7. © 2017 ForgeRock. All rights reserved. The EU General Data Protection Regulation: It’s different this time • Firm deadline, big penalties, high aspirations…and viral • “Data protection” encompasses a wide variety of data transparency and data control requirements
  • 8. © 2017 ForgeRock. All rights reserved. https://www.flickr.com/photos/adpowers/16808090/ | CC BY 2.0 Take steps Identify intersections between digital transformation opportunities and user trust risks Conceive of personal data as a joint asset Lean in to consent Take advantage of identity and access management for building trust
  • 9. © 2017 ForgeRock. All rights reserved. We asked what you wanted to know – and you let us have it https://www.flickr.com/photos/infomastern/11459954985/ | CC BY-SA 2.0
  • 10. © 2017 ForgeRock. All rights reserved. My company interacts with end-users directly and holds user account data. When sending such data from Australia to, say, the US, what regulation applies: Australia, US, EU...? Q1
  • 11. © 2017 ForgeRock. All rights reserved. What is the relation of Privacy Shield to GDPR? Q2
  • 12. © 2017 ForgeRock. All rights reserved. Does GDPR require that I store data about my customers in the country it was collected in? How does it work in the ForgeRock Identity Platform to store identity profile data within a specific region? Q3b Q3a
  • 13. © 2017 ForgeRock. All rights reserved. The ForgeRock Identity Platform DIRECTORY SERVICES ACCESS MANAGEMENT IDENTITY MANAGEMENT IDENTITY GATEWAYCOMMON SERVICES IDM IG DS AM Authentication Authorization Provisioning Reconciliation Authentication OIDC/OAuth Federation Adaptive Risk Stateless & Stateful UMA Provider Mobile App User Self Service Workflow Engine Registration Single View of Customer Synchronization Password Management Password Replay SAML Token Transformation UMA Protector API Security Throttling Common Scripting Common Audit/Logging Common User Interface Common REST API LDAPv3 Replication REST/JSON Access Control Schema Management Caching Auditing Monitoring Groups Password Policy AD Pass Through Reporting CS
  • 14. © 2017 ForgeRock. All rights reserved. Data sovereignty and fractional replication Global User Profile (has all user attributes) • Contains subset of complete user profile • Fractional replication within each jurisdiction
  • 15. © 2017 ForgeRock. All rights reserved. If a US employee of my organization uses a VPN connection back to the home office while in another office that’s located in the EU, what regulation applies: US, EU…? Q4
  • 16. © 2017 ForgeRock. All rights reserved. What do data encryption techniques have to do with GDPR? How does it work in the ForgeRock Identity Platform to encrypt and protect identity attributes? Q5b Q5a
  • 17. © 2017 ForgeRock. All rights reserved. DIRECTORY SERVICES Many layers of protection for personal data ACCESS MANAGEMENT IDENTITY MANAGEMENT IDENTITY GATEWAYCOMMON SERVICES IDM IG DS AM CS • On-disk encryption of data and indexes • Access controls to prevent unauthorized users from reading data • Encrypted backups • Tamper- proofed audit logging, depending on the “sink” chosen • Logging only of the user identifier, not of profile content • Token proof of possession available to ensure the bearer is the rightful owner • Signing and encryption for JWTs, id_tokens, SAML assertions, UserInfo responses • Contextual authorization • Encryption of credentials and profile attributes • Encryption or hashing of data during synchronization • Contextual authorization • Message header encryption
  • 18. © 2017 ForgeRock. All rights reserved. Does an individual have a “right to update” data? Q6
  • 19. © 2017 ForgeRock. All rights reserved. If my organization has shared end-user data with a third party, and our end-user asks for it to be deleted, whose responsibility is it to delete it? Q7
  • 20. © 2017 ForgeRock. All rights reserved. When does GDPR say I have to go back to an end-user and ask for their consent to process their data again after collecting it a first time? When is it possible to ask for an end- user’s consent using the ForgeRock Identity Platform? Q8b Q8a
  • 21. © 2017 ForgeRock. All rights reserved. Moments of consent Registration time Authentication time Access approval (asynchronous)
  • 22. © 2017 ForgeRock. All rights reserved. I’ve heard my organization will have to change all of our consent collection practices because of GDPR – is that true? What consent lifecycle management capabilities does the ForgeRock Identity Platform have? Q9b Q9a
  • 23. © 2017 ForgeRock. All rights reserved. Single view of the consumer Giving the consumer a single view of their consents Giving the consumer control over their consents ● Lifecycle management of a user profile and their data sharing preferences ● Secure storage of profile data ● Anonymized syncing of profile data and connector-based integration to third- party systems ● Terms of service and privacy policy capture ● Social sign-in ● Social registration ● Social consent management ● Interoperable, user- driven, proactive and reactive sharing flows The holistic view of consent lifecycle management
  • 24. © 2017 ForgeRock. All rights reserved. Patient selectively sharing IoT health data with doctors and other caregivers with User-Managed Access (UMA) Patient view Doctor view
  • 25. © 2017 ForgeRock. All rights reserved. Granular consented access by accountant to bank customer’s account data and transactions 25
  • 26. © 2017 ForgeRock. All rights reserved. What does GDPR say about parental consent, and what is the age of majority? What are the capabilities of the ForgeRock Identity Platform regarding parental consent? Q10b Q10a
  • 27. © 2017 ForgeRock. All rights reserved. Typical parent/child account relationship and capabilities Parent/Guardian Account • Can self-register • Can create and manage age- constrained accounts • Full schema and permissions • Access approval options, e.g. through UMA constrained delegation Child Account • Not allowed to self- register • Jurisdictionally defined age- constrained account • Limited schema and permissions
  • 28. © 2017 ForgeRock. All rights reserved. We’d like to show you what we’ve got cooking https://www.flickr.com/photos/carree/2502801336/ | CC BY-ND 2.0
  • 29. © 2017 ForgeRock. All rights reserved. Profile and Privacy Management Dashboard: It’s all about self-service for… • The right to be informed • The right of access • The right to rectification • The right to erasure • The right to restrict processing • The right to data portability • The right to object • Convenient and centralized data protection, transparency, and control demo
  • 30. © 2017 ForgeRock. All rights reserved. Thank You! Questions?Eve Maler VP Innovation & Emerging Technology, ForgeRock @xmlgrrl Sean Doherty Analyst, Workforce Productivity & Compliance Channel, 451 Research @SeanD0herty
  • 31. © 2017 ForgeRock. All rights reserved. summits.forgerock.com