SlideShare a Scribd company logo
1 of 40
Download to read offline
© Copyright 2017 TopQuadrant Inc. Slide 1
Semantic	Data	Governance	for	Regulatory	Compliance
Ralph	Hodgson,	CTO	and	co-founder	of	TopQuadrant	Inc.
September	12,	2017
SEMANTiCS 2017
Theater	de	Meervaart
Meer	en Vaart 300
1068	LE	Amsterdam,	Netherlands
v2
© Copyright 2017 TopQuadrant Inc. Slide 2
Semantic	Data	Governance	for	Regulatory	Compliance
§ Introductions
§ RECO	– Regulatory	Compliance	Ontology
§ GDPR	– and	a	GDPR	Ontology
§ TopBraid EDG	Asset	Governance	and	Lineage	Ontologies
– How	TopBraid EDG	addresses	the	hard	problems	in	GDPR?
§ Demo
§ Concluding	Remarks
§ Q&A
!	20	minutes	?	on	…
© Copyright 2017 TopQuadrant Inc. Slide 3
TOPQUADRANT	COMPANY
TOPQUADRANT	COMPANY
FOUNDATION
• TopQuadrant was	founded	in	2001
• Strong	commitment	to	standards-based	approaches	to	data	semantics
MISSION
• Empower	people	and	drive	results	— by	making	enterprise	information	
meaningful
FOCUS
• Provide	comprehensive	data	governance	solutions
© Copyright 2017 TopQuadrant Inc. Slide 4
© Copyright 2017 TopQuadrant Inc. Slide 5
Who	are	my	data	partners?	
What	data	do	I	share	with	them?
What	countries	are	they	in?
Do	I	have	data	regulation	assets	in	my	
system	for	those	countries?
What	3rd	country	jurisdictions	have	regulatory	
authority	for	what	data	and/or	what	data	processing?
Regulatory	
Compliance
Enterprise	
Governance
GDPR	
Compliance
TopBraid EDG’s	Knowledge	Engine	answers	compliance	questions
What	problems	are	we	addressing?
© Copyright 2017 TopQuadrant Inc. Slide 6
…	Helps	understand
How	enterprise	contexts	for…
• Data	Assets
• Software	and	systems
• Processing	locations
• Third	party	processors
…	relate	to	compliance
• responsibilities	
• obligations
• actions	needed
TopBraid EDG	Knowledge	Base
© Copyright 2017 TopQuadrant Inc. Slide 7
RDF
SPARQL
OWL
RDFS
Statements:
Saying	things
Vocabulary:
Shared	terms	can
we	use
Classification:
What	is	this	thing?
Query:
What	did	you	say?
OWL SHACL
Rules:
Is	that	term	used	correctly?
What	do	you	need	to	know?	
You	can't	say	that	here!
*W3C	=	World	Wide	Web	Consortium			led	
by	Tim	Berners-Lee
TopBraid EDG	is	based	on	Semantic	Standards
© Copyright 2017 TopQuadrant Inc. Slide 8
RECO	- Regulatory	Compliance	Ontology
§ An	ontology	for:
–obligations,
–permissions,
–Prohibitions,
–Violations	and
–Waivers
reco:Norm
reco:Prescription
reco:Obligation
reco:DataObligation
reco:DataDisclosureObligation
© Copyright 2017 TopQuadrant Inc. Slide 9
Semantic	Models	for	Compliance:	Processing	EUR-Lex	–
32014R0600	into	TopBraid
From	Text:
To	Triples:
To	RECO	Ontology	of	Obligations,	Permissions	and	Prohibitions
Ref:	http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32014R0600&from=NL
© Copyright 2017 TopQuadrant Inc. Slide 10
Mandate:	Protect	Personally	Identifiable	Information	(PII)
ü 7	guiding	principles	and	83	pages	of	regulations	govern	the	protection	of	personal	
data.
ü Generally	applies	to	all	personal	data	of	EU	residents	or	handled	by	EU	companies.
ü Protection	”by	design”	requires	systems	for	compliance,	verification,	audit,	and	
notification
ü Full	compliance	required	by	May	25,	2018
General	Data	Protection	Regulations	
(GDPR)	as	an	example	and	demo
© Copyright 2017 TopQuadrant Inc. Slide 11
GDPR	is	Complex
GDPR	is	not	just	about	data-at-rest.
It’s	about:
• What	processing	is	involved:	transformations	and	software	systems
• Jurisdictions	concerning	where	data,	software	and	processing	are	hosted
• How	data	flows	through	systems,	jurisdictions	and	partner	relationships
• And	how,	requirements	that	need	to	be	met	change	situationally
© Copyright 2017 TopQuadrant Inc. Slide 12
Regulated	
Data	Actions
Regulatory
Obligations
Transport	Outside	EU
Consent	Request
Consent	Review
Consent	Withdrawal
Data	Erasure
Consent	Preservation
Adaptation
Alignment
Storage
Archiving
Backup
Alteration
Collection
Combination
Hosting
Disclosure	By	Transmission
Processing
Recording
Consent	in	Plain	Language
72	Hour	Notification
GDPR	- What	do	we	need	to	talk	about?
© Copyright 2017 TopQuadrant Inc. Slide 13
§ provide	a	common	language	of	meaning
§ reveal	dependencies
§ bridge	domains	of	discourse	for	insight
§ define	“line-of-sights”	for	decision	support	
§ place	GDPR	into	a	structured	framework
A	Publication	Ontology	
helps	and	the	semantics:
First	we	need	a	Graph	Representation of	GDPR
Things
Relationships
© Copyright 2017 TopQuadrant Inc. Slide 14
Using	TopBraid EDG	we	express	GDPR	using	a	
Regulatory	Compliance	Ontology	(RECO)
Regulatory	
Compliance	
Graph
Regulation
Regulatory
Things
Relationships
© Copyright 2017 TopQuadrant Inc. Slide 15
Collection
GDPR	Regulated	
Data	Activities
Data	Controller
Data	Subject
Data	Protection	Officer	(DPO)
Storage
Hosting
Transformation
GDPR	Regulation
GDPR	Regulated	
Roles
Now	we	can	relate	PII	to	concepts	in	GDPR
Personally	
Identifiable	
Information	(PII)
Country	Data	Regulations	?
Pacific	Data	Regulations	?
© Copyright 2017 TopQuadrant Inc. Slide 16
Next	we	need	ontologies	of	Data,	Technical	and	
Enterprise	Assets,	and	Governance
Data,	Technical	
and	Enterprise	
Knowledge	
Graphs
Governance Things
Relationships
Personally	Identifiable	
Information	(PII)
© Copyright 2017 TopQuadrant Inc. Slide 17
We	can	then	make	the	connections	across	
these	domains	for	compliance	analysis
Discovering	the	path	between	personal	data		…
…		and	specific	GDPR	obligations
© Copyright 2017 TopQuadrant Inc. Slide 18
GDPR	needs	support	for	“Situated	Processes”
GDPR	
Compliance	
Graph
A	Process	“in	Context”
GDPR Things
Relationships
© Copyright 2017 TopQuadrant Inc. Slide 19
GDPR	Regulation	in	TopBraid EDG
© Copyright 2017 TopQuadrant Inc. Slide 20
The	Power	of	TopBraid EDG	…
General	
Regulatory	
Compliance
… is	in	bringing	this	all	together	into	a	connected	knowledge	base	
that	can	be	queried	for	insights,	reports	and	decision	support
Enterprise
Governance
GDPR	
Compliance
+
+
© Copyright 2017 TopQuadrant Inc. Slide 21
GDPR	Demo	Example:	“Transmission	Outside	EU”
Regulatory	
Obligation
Data	
Elements
(PII)
Process-In-Context
(SituatedProcess)
GDPR		
Paragraph
1
2
3
4
© Copyright 2017 TopQuadrant Inc. Slide 22
TopBraid EDG	Lineage	for	Compliance	Reporting
Data	
Resources
Information	
Products
Inputs Data	Elements PipelinesSoftware Outputs
© Copyright 2017 TopQuadrant Inc. Slide 23
DEMO:
TopBraid EDG	Semantic	Data	Governance	for	
GDPR	Compliance
© Copyright 2017 TopQuadrant Inc. Slide 24
Machine-Process-able	Standards	for:
üpolicies,	methods,	procedures	and	workflows	for	
performance	of	required	actions/tasks
üinformational	resources	language,	documents,	
forms,	templates	used	in	workflows
üsupporting	systems	for	compliance	validation	&	
verification,	change	tracking,	audit,	etc.
TopBraid EDG	Knowledge	Engine
Helps	automate	GDPR	compliance;
assessments,	documentation,	discovery	of	obligations,	compliance	gaps	…
…	Questions?
Flexible	Connections	Enable:
© Copyright 2017 TopQuadrant Inc. Slide 26
To	Learn	More	…
Contact us: at	info@topquadrant.com to:
• Discuss	our	GDPR	compliance	solutions
• Request	a	more	targeted	demo	of	TopBraid EDG
• Ask	for	a	free	EDG	evaluation	account
EDG Product Info:
• http://www.topquadrant.com/products/topbraid-edg/
• http://www.topquadrant.com/products/topbraid-edg-gov-packs/
Other EDG demos/webinar recordings:
• http://www.topquadrant.com/knowledgeassets/videos/#edgoverviewdemo
Webinar:	Data	Governance	for	the	Connected	Enterprise:	TopBraid EDG	in	Action
• http://www.topquadrant.com/knowledge-assets/topquadrant-webinars/#TQ-EDG-metadata-mgt-webinar
Webinar:	Metadata	Management	is	Key	to	Data	Governance	Initiatives
Thank	You	!
© Copyright 2017 TopQuadrant Inc. Slide 27
Reference	Slides
© Copyright 2017 TopQuadrant Inc. Slide 28
§ Core	flexibility	and	extensibility
Add	user	defined	models,	assets	and	properties	as	needed	
(model-driven)
§ Models:	pre-built	and	user	defined
Support	multiple	types	of	governance	assets
§ Connections:
Can	be	made	between	any	types	of	assets
§ Flexible	Connections	Enable:
– People	(UI)	and	software	(APIs/web	services)	to	view,	
follow	and	query	the	connections	to	answer	core	
questions,	e.g.		“Where	did	this	come	from?”
– complete	data	governance	vs.	siloed data	governance,	
i.e “reference-ability”
TopBraid	EDG:	Summary	and	Benefits	for	GDPR
© Copyright 2017 TopQuadrant Inc. Slide 29
Key	Concepts:	Assets
§ Asset is	a	technical,	business,	or	operational	resource	governed	by	an	
organization	using	TopBraid EDG.
§ Asset	type:	Asset	type	is	a	class	in	an	ontology	(either	ontologies	shipped	with	
TopBraid EDG	or	customized/created	by	the	users)	that	formally	describes	
attributes	and	relationships	of	an	asset.	An	asset	could	have	multiple	types.	
– TopBraid EDG	includes	over	100	asset	types	such	as	Glossary	Term,	Requirement,	ETL	Script	and	
many	others.
Software	Executable
Data	Pipeline
Policy
Team Database
Capability
Server Organization Database	Table
DatasetReport
Datatype
Business	Area Glossary	TermObligation
© Copyright 2017 TopQuadrant Inc. Slide 30
RECO	Engine	Approach
1. Use	ontologies	to	express	a	“finance/macroeconomics	knowledge	base”:
uRECO	for	regulatory	compliance	ontology
uQUDT	for	quantity	kinds
uExtend	with	“deep”	terminology
2. Transform	regulatory	documents	to	a	machine-processable model
uScreen	scraping	HTML	to	an	RDF	document	model
u“Lifting”	the	RDF	document	model	to	a	RECO	representation	of	“Obligations”,	“Prohibitions”	and	
“Permissions”
uUse	of	machine-learning	techniques	for	auto-classification
uManual	steps
3. Integrate	with	an	Enterprise	Data	Governance	platform	(TopBraid EDG)	for	
specifying	lineage	models:
uSemantic	relations	from	reporting	and	data	policy	stipulations	to	asset	types
uTranslation	(mapping)	of	knowledge	representations	to	physical	data	specifications	and	
transforms
© Copyright 2017 TopQuadrant Inc. Slide 31
From CELEX	HTML	Pages
to CELEX	RECO	Models
Transform	to	
Semantic	XHTML
Transform	to	
oePUB
Transform	to	
RECO
XHTML
XHTML	
Ontology
SPIN	
Transforms
ePUB
Ontology
RECO	
Ontology
SPIN	
Transforms
Semantic	
XML
REGULATION	
(EU)	No	
600/2014	
http://eur-lex.europa.eu/legal-content/EN/TXT/?qid=1460832668231&uri=CELEX:32014R0600
© Copyright 2017 TopQuadrant Inc. Slide 32
From Document	references
to semantic	links
CELEX	600
Directive	Article Directive	Article
REGULATION	
(EU)	No	
600/2014	
normative	
reference
normative	
reference
© Copyright 2017 TopQuadrant Inc. Slide 33
How	a	RECO	Model	of	Regulatory	Compliance	
helps	Lineage	Models
Compliance	
Report
Traceability	to	Compliance	Regulation
Informs	Lineage	Model
RECO	model	of	Celex 600/2014	for	Article	10	Para	1
REGULATION	(EU)	No	600/2014
© Copyright 2017 TopQuadrant Inc. Slide 34
RECO	– Illustrative	Classes	and	Properties
34
~83	Classes ~62	Properties
reco:Norm
reco:Prescription
reco:Obligation
reco:DataObligation
reco:DataDisclosureObligation
© Copyright 2017 TopQuadrant Inc. Slide 35
RECO	– Regulation	Classe in	TopBraid Composer
35Confidential TopQuadrant, Inc. 2015
Example	classes	from	the	Regulatory	Compliance	Ontology	(RECO)
© Copyright 2017 TopQuadrant Inc. Slide 36
EUR-Lex	– 32014R0600	in	TopBraid EVN
36Confidential TopQuadrant, Inc. 2015
Paragraph	1	of	
article	13
Article	13	rendered	in	TopBraid EVN	using	SWP/SWA:
© Copyright 2017 TopQuadrant Inc. Slide 37
RECO:	Obligations	as	Prescriptions
© Copyright 2017 TopQuadrant Inc. Slide 38
7	Guiding	Principles	– Standard	of	Care
§ Lawful,	Fair	and	Transparent	Processing	…................................................................. Article	5.1a
§ Specified,	Fair	and	Legitimate	Purposes	…................................................................. Article	5.1b
§ Data	Minimization	– Adequate	,	Relevant,	Limited	to	Necessary	............................. Article	5.1c
§ Accurate	and	current	…............................................................................................... Article	5.1d
§ Minimize	duration	of	storage	….................................................................................. Article	5.1e
§ Secure	Processing	….................................................................................................... Article	5.1f
§ Accountability	….......................................................................................................... Article	5.2
GDPR	Facts
© Copyright 2017 TopQuadrant Inc. Slide 39
Violations	have	significant	consequences
§ 20MM	Euro	or	4%	of	Global	Turnover
§ Prohibited	from	processing	of	critical	data
§ Reputation	Exposure	and/or	Damage
§ Interruption	of	critical	data	supply	chain
§ Business	model	at	risk
GDPR	Facts
© Copyright 2017 TopQuadrant Inc. Slide 40
Ends

More Related Content

What's hot

3 keys to Digital transformation
3 keys to Digital transformation 3 keys to Digital transformation
3 keys to Digital transformation
Equinix
 

What's hot (20)

Introducing the Jisc National HPC Agreement
Introducing the Jisc National HPC AgreementIntroducing the Jisc National HPC Agreement
Introducing the Jisc National HPC Agreement
 
Session 1.1 dalicc - data licenses clearance center
Session 1.1   dalicc - data licenses clearance centerSession 1.1   dalicc - data licenses clearance center
Session 1.1 dalicc - data licenses clearance center
 
ICARUS @EASN 2019 - Industry 4.0 in Aeronautics Session (September 2019, Athens)
ICARUS @EASN 2019 - Industry 4.0 in Aeronautics Session (September 2019, Athens)ICARUS @EASN 2019 - Industry 4.0 in Aeronautics Session (September 2019, Athens)
ICARUS @EASN 2019 - Industry 4.0 in Aeronautics Session (September 2019, Athens)
 
Data Privacy, Security in personal data sharing
Data Privacy, Security in personal data sharingData Privacy, Security in personal data sharing
Data Privacy, Security in personal data sharing
 
FIWARE Global Summit - International Data Spaces - From Industry 4.0 to Data ...
FIWARE Global Summit - International Data Spaces - From Industry 4.0 to Data ...FIWARE Global Summit - International Data Spaces - From Industry 4.0 to Data ...
FIWARE Global Summit - International Data Spaces - From Industry 4.0 to Data ...
 
FIWARE Global Summit - The Digital Single Market - Benefits and Solutions for...
FIWARE Global Summit - The Digital Single Market - Benefits and Solutions for...FIWARE Global Summit - The Digital Single Market - Benefits and Solutions for...
FIWARE Global Summit - The Digital Single Market - Benefits and Solutions for...
 
IBM-ISSIP Presentation
IBM-ISSIP Presentation IBM-ISSIP Presentation
IBM-ISSIP Presentation
 
Service System Engineering
Service System EngineeringService System Engineering
Service System Engineering
 
Europe rules – making the fair data economy flourish
Europe rules – making the fair data economy flourishEurope rules – making the fair data economy flourish
Europe rules – making the fair data economy flourish
 
Pirkka frosti dli ihan testbed rise of the pilots 25.3.2021 print
Pirkka frosti dli ihan testbed rise of the pilots 25.3.2021 printPirkka frosti dli ihan testbed rise of the pilots 25.3.2021 print
Pirkka frosti dli ihan testbed rise of the pilots 25.3.2021 print
 
FIWARE Global Summit - Exploring a New Opportunity in Data Economy: A Case of...
FIWARE Global Summit - Exploring a New Opportunity in Data Economy: A Case of...FIWARE Global Summit - Exploring a New Opportunity in Data Economy: A Case of...
FIWARE Global Summit - Exploring a New Opportunity in Data Economy: A Case of...
 
One size doesn't fit all! - The NRB approach to data management (Ph. Rikir &...
One size doesn't fit all! -  The NRB approach to data management (Ph. Rikir &...One size doesn't fit all! -  The NRB approach to data management (Ph. Rikir &...
One size doesn't fit all! - The NRB approach to data management (Ph. Rikir &...
 
Setup a Data Science Pipeline in a Highly Regulated Environment
Setup a Data Science Pipeline in a Highly Regulated EnvironmentSetup a Data Science Pipeline in a Highly Regulated Environment
Setup a Data Science Pipeline in a Highly Regulated Environment
 
Big Data and Massive Analytics
Big Data and Massive AnalyticsBig Data and Massive Analytics
Big Data and Massive Analytics
 
3 keys to Digital transformation
3 keys to Digital transformation 3 keys to Digital transformation
3 keys to Digital transformation
 
Big Data Value Association (BDVA) - Intro Slide Pack
Big Data Value Association (BDVA) - Intro Slide PackBig Data Value Association (BDVA) - Intro Slide Pack
Big Data Value Association (BDVA) - Intro Slide Pack
 
IDS: Update on Reference Architecture and Ecosystem Design
IDS: Update on Reference Architecture and Ecosystem DesignIDS: Update on Reference Architecture and Ecosystem Design
IDS: Update on Reference Architecture and Ecosystem Design
 
WEBINAR: Emerging Technologies in Supply Chain
WEBINAR: Emerging Technologies in Supply ChainWEBINAR: Emerging Technologies in Supply Chain
WEBINAR: Emerging Technologies in Supply Chain
 
Heikki Ailisto: Combining AI technologies with our traditional strengths
Heikki Ailisto: Combining AI technologies with our traditional strengthsHeikki Ailisto: Combining AI technologies with our traditional strengths
Heikki Ailisto: Combining AI technologies with our traditional strengths
 
EDF2014: Dimitris Vassiliadis, Head of Unit, EXUS Innovation Attractor: From ...
EDF2014: Dimitris Vassiliadis, Head of Unit, EXUS Innovation Attractor: From ...EDF2014: Dimitris Vassiliadis, Head of Unit, EXUS Innovation Attractor: From ...
EDF2014: Dimitris Vassiliadis, Head of Unit, EXUS Innovation Attractor: From ...
 

Similar to Session 2.6 semantic data governance for regulatory compliance

Similar to Session 2.6 semantic data governance for regulatory compliance (20)

Jason Tooley – Welcome to Vision Solution Day EMEA
Jason Tooley – Welcome to Vision Solution Day EMEAJason Tooley – Welcome to Vision Solution Day EMEA
Jason Tooley – Welcome to Vision Solution Day EMEA
 
12th July GDPR event slides
12th July GDPR event slides12th July GDPR event slides
12th July GDPR event slides
 
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
 
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
 
Top 10 GDPR solution providers 2020
Top 10 GDPR solution providers 2020Top 10 GDPR solution providers 2020
Top 10 GDPR solution providers 2020
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
Enabling the Digital World
Enabling the Digital WorldEnabling the Digital World
Enabling the Digital World
 
GDPR - CISO Perspective
GDPR - CISO PerspectiveGDPR - CISO Perspective
GDPR - CISO Perspective
 
Tech Connect Live 30th May 2018 ,GDPR Summit Ken O'Connor
Tech Connect Live 30th May 2018 ,GDPR Summit Ken O'ConnorTech Connect Live 30th May 2018 ,GDPR Summit Ken O'Connor
Tech Connect Live 30th May 2018 ,GDPR Summit Ken O'Connor
 
GDPR: Where should you be right now? - Dennis Slattery, EDM Works
GDPR: Where should you be right now? - Dennis Slattery, EDM WorksGDPR: Where should you be right now? - Dennis Slattery, EDM Works
GDPR: Where should you be right now? - Dennis Slattery, EDM Works
 
CIO priorities and Data Virtualization: Balancing the Yin and Yang of the IT
CIO priorities and Data Virtualization: Balancing the Yin and Yang of the ITCIO priorities and Data Virtualization: Balancing the Yin and Yang of the IT
CIO priorities and Data Virtualization: Balancing the Yin and Yang of the IT
 
Jisc GDPR conference
Jisc GDPR conferenceJisc GDPR conference
Jisc GDPR conference
 
Ritz 4th-july-gdpr
Ritz 4th-july-gdprRitz 4th-july-gdpr
Ritz 4th-july-gdpr
 
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
 
Symantec Webinar Part 3 of 6 How to Tackle Data Protection Risk in Time for G...
Symantec Webinar Part 3 of 6 How to Tackle Data Protection Risk in Time for G...Symantec Webinar Part 3 of 6 How to Tackle Data Protection Risk in Time for G...
Symantec Webinar Part 3 of 6 How to Tackle Data Protection Risk in Time for G...
 
Using GDPR to Transform Customer Experience
Using GDPR to Transform Customer ExperienceUsing GDPR to Transform Customer Experience
Using GDPR to Transform Customer Experience
 
Chief Data Architect or Chief Data Officer: Connecting the Enterprise Data Ec...
Chief Data Architect or Chief Data Officer: Connecting the Enterprise Data Ec...Chief Data Architect or Chief Data Officer: Connecting the Enterprise Data Ec...
Chief Data Architect or Chief Data Officer: Connecting the Enterprise Data Ec...
 
Get doing GDPR right now! IRMS May 2018
Get doing GDPR right now!  IRMS May 2018Get doing GDPR right now!  IRMS May 2018
Get doing GDPR right now! IRMS May 2018
 
CWIN17 telford gdpr – threat, overhead or opportunity - doug davidson
CWIN17 telford   gdpr – threat, overhead or opportunity - doug davidsonCWIN17 telford   gdpr – threat, overhead or opportunity - doug davidson
CWIN17 telford gdpr – threat, overhead or opportunity - doug davidson
 
Symantec Webinar Part 2 of 6 GDPR Compliance
Symantec Webinar Part 2 of 6 GDPR ComplianceSymantec Webinar Part 2 of 6 GDPR Compliance
Symantec Webinar Part 2 of 6 GDPR Compliance
 

More from semanticsconference

More from semanticsconference (20)

Linear books to open world adventure
Linear books to open world adventureLinear books to open world adventure
Linear books to open world adventure
 
Session 1.2 high-precision, context-free entity linking exploiting unambigu...
Session 1.2   high-precision, context-free entity linking exploiting unambigu...Session 1.2   high-precision, context-free entity linking exploiting unambigu...
Session 1.2 high-precision, context-free entity linking exploiting unambigu...
 
Session 4.3 semantic annotation for enhancing collaborative ideation
Session 4.3   semantic annotation for enhancing collaborative ideationSession 4.3   semantic annotation for enhancing collaborative ideation
Session 4.3 semantic annotation for enhancing collaborative ideation
 
Session 0.0 aussenac semanticsnl-pwebsem2017-v4
Session 0.0   aussenac semanticsnl-pwebsem2017-v4Session 0.0   aussenac semanticsnl-pwebsem2017-v4
Session 0.0 aussenac semanticsnl-pwebsem2017-v4
 
Session 0.0 keynote sandeep sacheti - final hi res
Session 0.0   keynote sandeep sacheti - final hi resSession 0.0   keynote sandeep sacheti - final hi res
Session 0.0 keynote sandeep sacheti - final hi res
 
Session 1.2 enrich your knowledge graphs: linked data integration with pool...
Session 1.2   enrich your knowledge graphs: linked data integration with pool...Session 1.2   enrich your knowledge graphs: linked data integration with pool...
Session 1.2 enrich your knowledge graphs: linked data integration with pool...
 
Session 1.4 connecting information from legislation and datasets using a ca...
Session 1.4   connecting information from legislation and datasets using a ca...Session 1.4   connecting information from legislation and datasets using a ca...
Session 1.4 connecting information from legislation and datasets using a ca...
 
Session 1.4 a distributed network of heritage information
Session 1.4   a distributed network of heritage informationSession 1.4   a distributed network of heritage information
Session 1.4 a distributed network of heritage information
 
Session 0.0 media panel - matthias priem - gtuo - semantics 2017
Session 0.0   media panel - matthias priem - gtuo - semantics 2017Session 0.0   media panel - matthias priem - gtuo - semantics 2017
Session 0.0 media panel - matthias priem - gtuo - semantics 2017
 
Session 1.3 energy, smart homes & smart grids: towards interoperability...
Session 1.3   energy, smart homes & smart grids: towards interoperability...Session 1.3   energy, smart homes & smart grids: towards interoperability...
Session 1.3 energy, smart homes & smart grids: towards interoperability...
 
Session 1.2 improving access to digital content by semantic enrichment
Session 1.2   improving access to digital content by semantic enrichmentSession 1.2   improving access to digital content by semantic enrichment
Session 1.2 improving access to digital content by semantic enrichment
 
Session 2.5 semantic similarity based clustering of license excerpts for im...
Session 2.5   semantic similarity based clustering of license excerpts for im...Session 2.5   semantic similarity based clustering of license excerpts for im...
Session 2.5 semantic similarity based clustering of license excerpts for im...
 
Session 4.2 unleash the triple: leveraging a corporate discovery interface....
Session 4.2   unleash the triple: leveraging a corporate discovery interface....Session 4.2   unleash the triple: leveraging a corporate discovery interface....
Session 4.2 unleash the triple: leveraging a corporate discovery interface....
 
Session 1.6 slovak public metadata governance and management based on linke...
Session 1.6   slovak public metadata governance and management based on linke...Session 1.6   slovak public metadata governance and management based on linke...
Session 1.6 slovak public metadata governance and management based on linke...
 
Session 5.6 towards a semantic outlier detection framework in wireless sens...
Session 5.6   towards a semantic outlier detection framework in wireless sens...Session 5.6   towards a semantic outlier detection framework in wireless sens...
Session 5.6 towards a semantic outlier detection framework in wireless sens...
 
Session 2.2 ontology-guided job market demand analysis: a cross-sectional s...
Session 2.2   ontology-guided job market demand analysis: a cross-sectional s...Session 2.2   ontology-guided job market demand analysis: a cross-sectional s...
Session 2.2 ontology-guided job market demand analysis: a cross-sectional s...
 
Session 0.0 poster minutes madness
Session 0.0   poster minutes madnessSession 0.0   poster minutes madness
Session 0.0 poster minutes madness
 
Keynote new convergences between natural language processing and knowledge ...
Keynote   new convergences between natural language processing and knowledge ...Keynote   new convergences between natural language processing and knowledge ...
Keynote new convergences between natural language processing and knowledge ...
 
Session 3.4 developing a medicines catalogue using linked data sources
Session 3.4   developing a medicines catalogue using linked data sourcesSession 3.4   developing a medicines catalogue using linked data sources
Session 3.4 developing a medicines catalogue using linked data sources
 
Session 2.5 matching natural language relations to knowledge graph properti...
Session 2.5   matching natural language relations to knowledge graph properti...Session 2.5   matching natural language relations to knowledge graph properti...
Session 2.5 matching natural language relations to knowledge graph properti...
 

Recently uploaded

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 

Recently uploaded (20)

Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 

Session 2.6 semantic data governance for regulatory compliance

  • 1. © Copyright 2017 TopQuadrant Inc. Slide 1 Semantic Data Governance for Regulatory Compliance Ralph Hodgson, CTO and co-founder of TopQuadrant Inc. September 12, 2017 SEMANTiCS 2017 Theater de Meervaart Meer en Vaart 300 1068 LE Amsterdam, Netherlands v2
  • 2. © Copyright 2017 TopQuadrant Inc. Slide 2 Semantic Data Governance for Regulatory Compliance § Introductions § RECO – Regulatory Compliance Ontology § GDPR – and a GDPR Ontology § TopBraid EDG Asset Governance and Lineage Ontologies – How TopBraid EDG addresses the hard problems in GDPR? § Demo § Concluding Remarks § Q&A ! 20 minutes ? on …
  • 3. © Copyright 2017 TopQuadrant Inc. Slide 3 TOPQUADRANT COMPANY TOPQUADRANT COMPANY FOUNDATION • TopQuadrant was founded in 2001 • Strong commitment to standards-based approaches to data semantics MISSION • Empower people and drive results — by making enterprise information meaningful FOCUS • Provide comprehensive data governance solutions
  • 4. © Copyright 2017 TopQuadrant Inc. Slide 4
  • 5. © Copyright 2017 TopQuadrant Inc. Slide 5 Who are my data partners? What data do I share with them? What countries are they in? Do I have data regulation assets in my system for those countries? What 3rd country jurisdictions have regulatory authority for what data and/or what data processing? Regulatory Compliance Enterprise Governance GDPR Compliance TopBraid EDG’s Knowledge Engine answers compliance questions What problems are we addressing?
  • 6. © Copyright 2017 TopQuadrant Inc. Slide 6 … Helps understand How enterprise contexts for… • Data Assets • Software and systems • Processing locations • Third party processors … relate to compliance • responsibilities • obligations • actions needed TopBraid EDG Knowledge Base
  • 7. © Copyright 2017 TopQuadrant Inc. Slide 7 RDF SPARQL OWL RDFS Statements: Saying things Vocabulary: Shared terms can we use Classification: What is this thing? Query: What did you say? OWL SHACL Rules: Is that term used correctly? What do you need to know? You can't say that here! *W3C = World Wide Web Consortium led by Tim Berners-Lee TopBraid EDG is based on Semantic Standards
  • 8. © Copyright 2017 TopQuadrant Inc. Slide 8 RECO - Regulatory Compliance Ontology § An ontology for: –obligations, –permissions, –Prohibitions, –Violations and –Waivers reco:Norm reco:Prescription reco:Obligation reco:DataObligation reco:DataDisclosureObligation
  • 9. © Copyright 2017 TopQuadrant Inc. Slide 9 Semantic Models for Compliance: Processing EUR-Lex – 32014R0600 into TopBraid From Text: To Triples: To RECO Ontology of Obligations, Permissions and Prohibitions Ref: http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32014R0600&from=NL
  • 10. © Copyright 2017 TopQuadrant Inc. Slide 10 Mandate: Protect Personally Identifiable Information (PII) ü 7 guiding principles and 83 pages of regulations govern the protection of personal data. ü Generally applies to all personal data of EU residents or handled by EU companies. ü Protection ”by design” requires systems for compliance, verification, audit, and notification ü Full compliance required by May 25, 2018 General Data Protection Regulations (GDPR) as an example and demo
  • 11. © Copyright 2017 TopQuadrant Inc. Slide 11 GDPR is Complex GDPR is not just about data-at-rest. It’s about: • What processing is involved: transformations and software systems • Jurisdictions concerning where data, software and processing are hosted • How data flows through systems, jurisdictions and partner relationships • And how, requirements that need to be met change situationally
  • 12. © Copyright 2017 TopQuadrant Inc. Slide 12 Regulated Data Actions Regulatory Obligations Transport Outside EU Consent Request Consent Review Consent Withdrawal Data Erasure Consent Preservation Adaptation Alignment Storage Archiving Backup Alteration Collection Combination Hosting Disclosure By Transmission Processing Recording Consent in Plain Language 72 Hour Notification GDPR - What do we need to talk about?
  • 13. © Copyright 2017 TopQuadrant Inc. Slide 13 § provide a common language of meaning § reveal dependencies § bridge domains of discourse for insight § define “line-of-sights” for decision support § place GDPR into a structured framework A Publication Ontology helps and the semantics: First we need a Graph Representation of GDPR Things Relationships
  • 14. © Copyright 2017 TopQuadrant Inc. Slide 14 Using TopBraid EDG we express GDPR using a Regulatory Compliance Ontology (RECO) Regulatory Compliance Graph Regulation Regulatory Things Relationships
  • 15. © Copyright 2017 TopQuadrant Inc. Slide 15 Collection GDPR Regulated Data Activities Data Controller Data Subject Data Protection Officer (DPO) Storage Hosting Transformation GDPR Regulation GDPR Regulated Roles Now we can relate PII to concepts in GDPR Personally Identifiable Information (PII) Country Data Regulations ? Pacific Data Regulations ?
  • 16. © Copyright 2017 TopQuadrant Inc. Slide 16 Next we need ontologies of Data, Technical and Enterprise Assets, and Governance Data, Technical and Enterprise Knowledge Graphs Governance Things Relationships Personally Identifiable Information (PII)
  • 17. © Copyright 2017 TopQuadrant Inc. Slide 17 We can then make the connections across these domains for compliance analysis Discovering the path between personal data … … and specific GDPR obligations
  • 18. © Copyright 2017 TopQuadrant Inc. Slide 18 GDPR needs support for “Situated Processes” GDPR Compliance Graph A Process “in Context” GDPR Things Relationships
  • 19. © Copyright 2017 TopQuadrant Inc. Slide 19 GDPR Regulation in TopBraid EDG
  • 20. © Copyright 2017 TopQuadrant Inc. Slide 20 The Power of TopBraid EDG … General Regulatory Compliance … is in bringing this all together into a connected knowledge base that can be queried for insights, reports and decision support Enterprise Governance GDPR Compliance + +
  • 21. © Copyright 2017 TopQuadrant Inc. Slide 21 GDPR Demo Example: “Transmission Outside EU” Regulatory Obligation Data Elements (PII) Process-In-Context (SituatedProcess) GDPR Paragraph 1 2 3 4
  • 22. © Copyright 2017 TopQuadrant Inc. Slide 22 TopBraid EDG Lineage for Compliance Reporting Data Resources Information Products Inputs Data Elements PipelinesSoftware Outputs
  • 23. © Copyright 2017 TopQuadrant Inc. Slide 23 DEMO: TopBraid EDG Semantic Data Governance for GDPR Compliance
  • 24. © Copyright 2017 TopQuadrant Inc. Slide 24 Machine-Process-able Standards for: üpolicies, methods, procedures and workflows for performance of required actions/tasks üinformational resources language, documents, forms, templates used in workflows üsupporting systems for compliance validation & verification, change tracking, audit, etc. TopBraid EDG Knowledge Engine Helps automate GDPR compliance; assessments, documentation, discovery of obligations, compliance gaps …
  • 26. © Copyright 2017 TopQuadrant Inc. Slide 26 To Learn More … Contact us: at info@topquadrant.com to: • Discuss our GDPR compliance solutions • Request a more targeted demo of TopBraid EDG • Ask for a free EDG evaluation account EDG Product Info: • http://www.topquadrant.com/products/topbraid-edg/ • http://www.topquadrant.com/products/topbraid-edg-gov-packs/ Other EDG demos/webinar recordings: • http://www.topquadrant.com/knowledgeassets/videos/#edgoverviewdemo Webinar: Data Governance for the Connected Enterprise: TopBraid EDG in Action • http://www.topquadrant.com/knowledge-assets/topquadrant-webinars/#TQ-EDG-metadata-mgt-webinar Webinar: Metadata Management is Key to Data Governance Initiatives Thank You !
  • 27. © Copyright 2017 TopQuadrant Inc. Slide 27 Reference Slides
  • 28. © Copyright 2017 TopQuadrant Inc. Slide 28 § Core flexibility and extensibility Add user defined models, assets and properties as needed (model-driven) § Models: pre-built and user defined Support multiple types of governance assets § Connections: Can be made between any types of assets § Flexible Connections Enable: – People (UI) and software (APIs/web services) to view, follow and query the connections to answer core questions, e.g. “Where did this come from?” – complete data governance vs. siloed data governance, i.e “reference-ability” TopBraid EDG: Summary and Benefits for GDPR
  • 29. © Copyright 2017 TopQuadrant Inc. Slide 29 Key Concepts: Assets § Asset is a technical, business, or operational resource governed by an organization using TopBraid EDG. § Asset type: Asset type is a class in an ontology (either ontologies shipped with TopBraid EDG or customized/created by the users) that formally describes attributes and relationships of an asset. An asset could have multiple types. – TopBraid EDG includes over 100 asset types such as Glossary Term, Requirement, ETL Script and many others. Software Executable Data Pipeline Policy Team Database Capability Server Organization Database Table DatasetReport Datatype Business Area Glossary TermObligation
  • 30. © Copyright 2017 TopQuadrant Inc. Slide 30 RECO Engine Approach 1. Use ontologies to express a “finance/macroeconomics knowledge base”: uRECO for regulatory compliance ontology uQUDT for quantity kinds uExtend with “deep” terminology 2. Transform regulatory documents to a machine-processable model uScreen scraping HTML to an RDF document model u“Lifting” the RDF document model to a RECO representation of “Obligations”, “Prohibitions” and “Permissions” uUse of machine-learning techniques for auto-classification uManual steps 3. Integrate with an Enterprise Data Governance platform (TopBraid EDG) for specifying lineage models: uSemantic relations from reporting and data policy stipulations to asset types uTranslation (mapping) of knowledge representations to physical data specifications and transforms
  • 31. © Copyright 2017 TopQuadrant Inc. Slide 31 From CELEX HTML Pages to CELEX RECO Models Transform to Semantic XHTML Transform to oePUB Transform to RECO XHTML XHTML Ontology SPIN Transforms ePUB Ontology RECO Ontology SPIN Transforms Semantic XML REGULATION (EU) No 600/2014 http://eur-lex.europa.eu/legal-content/EN/TXT/?qid=1460832668231&uri=CELEX:32014R0600
  • 32. © Copyright 2017 TopQuadrant Inc. Slide 32 From Document references to semantic links CELEX 600 Directive Article Directive Article REGULATION (EU) No 600/2014 normative reference normative reference
  • 33. © Copyright 2017 TopQuadrant Inc. Slide 33 How a RECO Model of Regulatory Compliance helps Lineage Models Compliance Report Traceability to Compliance Regulation Informs Lineage Model RECO model of Celex 600/2014 for Article 10 Para 1 REGULATION (EU) No 600/2014
  • 34. © Copyright 2017 TopQuadrant Inc. Slide 34 RECO – Illustrative Classes and Properties 34 ~83 Classes ~62 Properties reco:Norm reco:Prescription reco:Obligation reco:DataObligation reco:DataDisclosureObligation
  • 35. © Copyright 2017 TopQuadrant Inc. Slide 35 RECO – Regulation Classe in TopBraid Composer 35Confidential TopQuadrant, Inc. 2015 Example classes from the Regulatory Compliance Ontology (RECO)
  • 36. © Copyright 2017 TopQuadrant Inc. Slide 36 EUR-Lex – 32014R0600 in TopBraid EVN 36Confidential TopQuadrant, Inc. 2015 Paragraph 1 of article 13 Article 13 rendered in TopBraid EVN using SWP/SWA:
  • 37. © Copyright 2017 TopQuadrant Inc. Slide 37 RECO: Obligations as Prescriptions
  • 38. © Copyright 2017 TopQuadrant Inc. Slide 38 7 Guiding Principles – Standard of Care § Lawful, Fair and Transparent Processing …................................................................. Article 5.1a § Specified, Fair and Legitimate Purposes …................................................................. Article 5.1b § Data Minimization – Adequate , Relevant, Limited to Necessary ............................. Article 5.1c § Accurate and current …............................................................................................... Article 5.1d § Minimize duration of storage ….................................................................................. Article 5.1e § Secure Processing ….................................................................................................... Article 5.1f § Accountability ….......................................................................................................... Article 5.2 GDPR Facts
  • 39. © Copyright 2017 TopQuadrant Inc. Slide 39 Violations have significant consequences § 20MM Euro or 4% of Global Turnover § Prohibited from processing of critical data § Reputation Exposure and/or Damage § Interruption of critical data supply chain § Business model at risk GDPR Facts
  • 40. © Copyright 2017 TopQuadrant Inc. Slide 40 Ends