SlideShare une entreprise Scribd logo
1  sur  42
Télécharger pour lire hors ligne
Using	
  Social	
  Business	
  So/ware	
  
and	
  being	
  compliant	
  with	
  EU	
  
data	
  protec9on	
  law	
  
Olaf	
  Boerner,	
  BCC	
  	
  
14.11.2014	
  	
  
Agenda:	
  	
  
Using	
  Social	
  Business	
  So/ware	
  and	
  being	
  
compliant	
  with	
  EU	
  data	
  protec9on	
  law	
  
1.  Short	
  Introduc9on	
  to	
  EU	
  Data	
  Protec9on	
  Law	
  
2.  Implica9ons	
  for	
  using	
  social	
  business	
  
so/ware	
  
3.  Data	
  protec9on	
  and	
  Cloud	
  based	
  social	
  
systems	
  
About me
•  Studied	
  Business	
  Administra9on	
  and	
  	
  
Computer	
  Science	
  
•  Notes	
  Administrator	
  /	
  Developer	
  since	
  1994	
  
•  CEO	
  and	
  Founder	
  of	
  BCC	
  in	
  1996	
  	
  
•  Working	
  as	
  project	
  manager	
  senior	
  architect	
  	
  
with	
  large	
  enterprise	
  customers	
  
–  Securing	
  IBM	
  Social	
  Business	
  infrastructures	
  	
  
–  reducing	
  Total	
  cost	
  of	
  Ownership	
  of	
  IBM	
  Social	
  Business	
  
Infrastructures	
  thru	
  automa9ng	
  Administra9on	
  	
  
•  IBM	
  Champion	
  in	
  2014	
  	
  
•  TwiVer:	
  @OlafBoerner	
  
Short	
  Disclaimer	
  J	
  	
  
I	
  am	
  not	
  a	
  lawyer	
  !	
  	
  
This	
  presenta9on	
  does	
  not	
  provide	
  
any	
  legal	
  advices	
  
Introduc9on	
  EU	
  Data	
  Protec9on	
  Law	
  	
  
•  Data	
  Protec9on	
  within	
  the	
  EU	
  is	
  not	
  op9onal	
  
– It’s	
  not	
  an	
  advice	
  	
  or	
  best	
  prac9ce	
  	
  
– It’s	
  not	
  a	
  silly	
  german	
  idea	
  	
  
– it´s	
  the	
  law	
  !	
  
– In	
  all	
  EU	
  Member	
  States	
  and	
  Non-­‐EU	
  Member	
  
States	
  that	
  are	
  part	
  of	
  the	
  European	
  Economic	
  
Area	
  	
  
Consequences	
  of	
  privacy	
  breaches	
  	
  
•  Consequences	
  depend	
  on	
  the	
  law	
  of	
  the	
  member	
  
state	
  
•  Examples	
  
–  Germany:	
  §	
  43	
  German	
  Federal	
  Protec9on	
  Act	
  up	
  to	
  
300.000	
  EURO	
  
–  UK:	
  ICO	
  up	
  to	
  £	
  500.000	
  	
  
•  Reputa9onal	
  damage	
  as	
  a	
  result	
  of	
  press	
  reports	
  
etc	
  
•  Many	
  contracts	
  allow	
  customers	
  and/or	
  supplier	
  
to	
  quit	
  contracts	
  	
  
Sony	
  fined	
  £250,000	
  a/er	
  millions	
  of	
  
UK	
  gamers’	
  personal	
  informa9on	
  
compromised	
  
	
  
•  PlaySta9on	
  Network	
  Plaeorm	
  was	
  hacked	
  in	
  April	
  
2011	
  	
  
•  An	
  ICO	
  inves9ga9on	
  found	
  that	
  the	
  aVack	
  could	
  
have	
  been	
  prevented	
  if	
  the	
  so/ware	
  had	
  been	
  
up-­‐to-­‐date,	
  while	
  technical	
  developments	
  also	
  
meant	
  passwords	
  were	
  not	
  secure.	
  
	
  
hVp://ico.org.uk/news/latest_news/2013/ico-­‐
news-­‐release-­‐2013	
  	
  
	
  
ICO	
  fines	
  Bank	
  of	
  Scotland	
  	
  
•  “ICO	
  fines	
  Bank	
  of	
  Scotland	
  for	
  “unforgivable”	
  
breach	
  of	
  Data	
  Protec9on	
  Act	
  in	
  August	
  2013,	
  
following	
  repeated	
  instances	
  of	
  customer	
  
details	
  being	
  sent	
  to	
  the	
  wrong	
  recipients.”	
  
•  h"p://www.compu,ng.co.uk/ctg/news/
2287087/ico-­‐fines-­‐bank-­‐of-­‐scotland-­‐for-­‐
unforgivable-­‐breach-­‐of-­‐data-­‐protec,on-­‐act	
  	
  
Reputa9onal	
  damage	
  	
  
hVp://brianpennington.co.uk/2012/08/16/who-­‐has-­‐breached-­‐the-­‐data-­‐protec9on-­‐act-­‐in-­‐2012-­‐find-­‐the-­‐
complete-­‐list-­‐here/	
  
Pharmacist	
  who	
  worked	
  for	
  West	
  
Essex	
  Primary	
  Care	
  Trust	
  
OK,	
  OK	
  	
  
please	
  explain	
  the	
  law	
  	
  
	
  
	
  	
  
The	
  difference	
  between	
  US	
  &	
  EU	
  	
  
•  Privacy	
  
–  ACT	
  Code	
  of	
  Fair	
  Informa9on	
  Prac9ce	
  that	
  governs	
  
the	
  collec9on,	
  maintenance,	
  use,	
  and	
  dissemina9on	
  
of	
  personally	
  iden9fiable	
  informa9on	
  about	
  
individuals	
  that	
  is	
  maintained	
  in	
  systems	
  of	
  	
  
•  Data	
  Protec,on	
  
–  law	
  on	
  the	
  processing	
  of	
  data	
  on	
  iden9fiable	
  living	
  
people.	
  It	
  is	
  the	
  main	
  piece	
  of	
  legisla9on	
  that	
  governs	
  
the	
  protec9on	
  of	
  personal	
  data	
  
Source:	
  wikepedia	
  	
  
Direc9ve	
  95/46	
  EC	
  
•  Member	
  states	
  must	
  transpose	
  direc9ve	
  
–  Germany:	
  Federal	
  Data	
  Protec9on	
  Act	
  
(Bundesdatenschutzgesetz)	
  
–  UK:	
  ICO	
  Data	
  Protec9on	
  Act	
  and	
  Privacy	
  and	
  
Electronic	
  Communica9ons	
  Regula9ons	
  2003	
  
•  Implementa9on	
  varies	
  from	
  member	
  state	
  to	
  
another	
  
	
  
•  EU	
  plans	
  to	
  unify	
  data	
  protec9on	
  with	
  a	
  single	
  
law	
  –	
  General	
  Data	
  Protec9on	
  Regula9on	
  
Legal	
  Scope	
  of	
  Direc9ve	
  95/46	
  EC	
  	
  
•  Territorial	
  scope:	
  	
  
–  EU	
  Member	
  States	
  and	
  	
  
–  Non-­‐EU	
  Member	
  States	
  that	
  are	
  part	
  of	
  the	
  European	
  
Economic	
  Area	
  	
  
•  Iceland,	
  	
  
•  Norway	
  and	
  	
  
•  Liechtenstein	
  
•  Material	
  scope:	
  	
  
–  processing	
  of	
  	
  
–  personal	
  data	
  
Processing	
  Personal	
  Data	
  	
  
•  Processing	
  =	
  „any	
  opera9on	
  ...	
  which	
  is	
  
performed	
  on	
  personal	
  data,	
  whether	
  or	
  not	
  
by	
  automa9c	
  means,	
  such	
  as	
  collec9on,	
  
recording,	
  organiza9on,	
  storage,	
  adap9on	
  or	
  
altera9on,	
  retrieval,	
  consulta9on,	
  ...(art	
  2b)	
  
•  So	
  what	
  is	
  personal	
  data	
  ?	
  	
  
Data	
  is	
  personal	
  	
  
if	
  they	
  relate	
  to	
  an	
  
iden9fied	
  or	
  at	
  least	
  
iden9fiable	
  person,	
  (data	
  
subject)	
  
if	
  addi9onal	
  informa9on	
  
can	
  be	
  obtained	
  without	
  
unreasonable	
  effort,	
  
allowing	
  the	
  iden9fica9on	
  
of	
  the	
  data	
  subject	
  
Examples	
  for	
  personal	
  data	
  
•  Name,	
  	
  	
  
•  Email	
  adress,	
  	
  
•  Postal	
  address,	
  	
  
•  bank	
  statements,	
  	
  
•  credit	
  card	
  numbers	
  …	
  
•  Dynamic	
  IP	
  Number	
  ?	
  	
  
Personal	
  or	
  not	
  personal	
  ?	
  
•  Data	
  is	
  anonymised	
  if	
  they	
  no	
  longer	
  contain	
  
any	
  iden9fiers	
  
•  Anonymised	
  data	
  are	
  not	
  personal	
  data	
  	
  
•  Therefore	
  no	
  data	
  protec9on	
  law	
  applicable	
  
•  Anonymise	
  Data	
  is	
  currently	
  this	
  only	
  best	
  
prac9ce	
  to	
  convert	
  personal	
  data	
  instead	
  of	
  
dele9ng	
  these	
  data	
  
Who	
  is	
  the	
  responsible	
  for	
  Data	
  
Protec9on	
  ?	
  
•  Responsible	
  party	
  is	
  called	
  „Controller“	
  	
  
–  Natural	
  or	
  ar9ficial	
  person,	
  	
  
–  public	
  authority,	
  	
  
–  agency	
  ..	
  	
  
–  which	
  determines	
  the	
  purposes	
  and	
  means	
  of	
  the	
  
processing	
  of	
  personal	
  data	
  
•  Must	
  be	
  related	
  to	
  EU	
  !	
  	
  
–  controller	
  is	
  established	
  or	
  operates	
  within	
  the	
  EU	
  
–  controller	
  uses	
  equipment	
  located	
  inside	
  the	
  EU	
  to	
  
process	
  personal	
  data	
  
Rules	
  for	
  processing	
  Personal	
  Data	
  	
  
Personal	
  Data	
  
should	
  not	
  be	
  
processed	
  	
  
except	
  certain	
  
condi9ons	
  are	
  
met:	
  
Transparency	
   Propor9onality	
  
Legi9mate	
  
purpose	
  	
  
Legi9mate	
  purpose	
  
Data	
  may	
  
be	
  
processed:	
  
When	
  the	
  processing	
  is	
  necessary	
  for	
  the	
  
performance	
  of	
  or	
  the	
  entering	
  into	
  a	
  contract	
  
When	
  the	
  processing	
  is	
  necessary	
  for	
  
compliance	
  with	
  a	
  legal	
  obliga9on	
  
When	
  processing	
  is	
  necessary	
  to	
  protect	
  the	
  
vital	
  interest	
  of	
  the	
  data	
  subject	
  or	
  	
  
The	
  data	
  subject	
  has	
  given	
  his	
  consent	
  
Summary	
  –	
  Data	
  Protec9on	
  	
  
•  In	
  prac9ce	
  the	
  issue	
  of	
  data	
  protec9on	
  refers	
  
to	
  all	
  businesses	
  which	
  electronically	
  process	
  
data,	
  
– from	
  wage	
  accoun9ng	
  of	
  their	
  own	
  employees,	
  	
  
– collec9ng	
  of	
  customer	
  data,	
  	
  
– storing	
  one	
  of	
  these	
  data	
  in	
  the	
  cloud	
  
•  mainly	
  legi9ma9on	
  based	
  	
  
– on	
  performance	
  of	
  a	
  (future)	
  contract	
  or	
  	
  
– on	
  a	
  given	
  consent	
  by	
  data	
  subject	
  
Part	
  II.	
  Implica9ons	
  for	
  using	
  social	
  
business	
  so/ware	
  	
  
•  Social	
  Business	
  So/ware	
  
– So/ware	
  systems	
  that	
  primarily	
  func9ons	
  to	
  allow	
  
SOCIAL	
  user	
  collabora9on	
  and	
  communica9on	
  	
  
•  Focus	
  to	
  people‘s	
  business	
  	
  networks	
  
– Profiles:	
  TINE	
  ‘s	
  Key	
  applica9on	
  colle9ng	
  HR	
  Data	
  
and	
  CVs	
  	
  
– Blogs	
  	
  
– Ac9vi9es	
  	
  
– Status	
  and	
  Open	
  Calendar’s	
  	
  
Social	
  „Intelligence“	
  	
  
	
  
Social	
  „Intelligence“	
  	
  	
  	
  
Best	
  prac9ces	
  for	
  social	
  business	
  
•  Balancing	
  of	
  enterprise	
  vs	
  personal	
  interests	
  is	
  
absolutely	
  mandatory	
  	
  
•  Consent	
  of	
  employees	
  might	
  be	
  required	
  	
  
–  German	
  legal	
  prac9ce:	
  simple	
  directory	
  of	
  experts	
  
containing	
  name,	
  job	
  descrip9on	
  etc	
  are	
  considered	
  
as	
  legi9mated	
  processing	
  
–  For	
  directories	
  with	
  extended	
  func9onali9es	
  the	
  
consent	
  of	
  each	
  data	
  subject	
  is	
  necessary	
  
– a	
  consent	
  is	
  valid	
  for	
  the	
  dura,on	
  of	
  the	
  
employment	
  only	
  
Best	
  Prac9ce:	
  Recommenda9on	
  	
  
•  You	
  need	
  a	
  legal	
  permission	
  or	
  consent	
  of	
  the	
  
data	
  subject	
  to	
  be	
  on	
  the	
  safe	
  side	
  
–  Employee	
  
–  External	
  users	
  
•  You	
  need	
  a	
  procedure	
  to	
  deal	
  with	
  users	
  leaving	
  
company	
  or	
  social	
  network	
  
–  They	
  might	
  leave	
  “peacefully”	
  BUT	
  	
  
–  Employee	
  consent	
  will	
  end	
  when	
  leaving	
  the	
  company	
  	
  
–  Ex	
  Employee	
  can	
  withdraw	
  their	
  consent	
  and/or	
  
request	
  for	
  data	
  dele9on	
  	
  
When	
  do	
  you	
  share	
  knowledge	
  ?	
  
„In	
  a	
  social	
  
enterprise,	
  your	
  
value	
  will	
  not	
  be	
  
what	
  you	
  know;	
  it	
  
will	
  be	
  what	
  you	
  
share.“	
  IBM	
  CEO	
  
Ginni	
  RomeVy	
  
You	
  need	
  
confidence	
  and	
  
trust	
  in	
  data	
  
protec9on	
  to	
  share	
  
knowledge	
  	
  
Part	
  III.	
  Social	
  Business	
  in	
  the	
  cloud	
  	
  	
  
•  Social	
  Business	
  Systems	
  are	
  moving	
  cloud	
  first	
  	
  
– IBM	
  Connec9ons	
  Cloud	
  	
  
– Office	
  365	
  	
  
Microso/	
  declared	
  to	
  stop	
  developing	
  On	
  
Premise	
  Collabora9on	
  Products	
  a/er	
  2015	
  	
  
IBM	
  is	
  s9ll	
  providing	
  On	
  Premise	
  but	
  would	
  love	
  
to	
  move	
  YOU	
  to	
  the	
  cloud	
  	
  
•  1.2	
  Billion	
  $	
  Investment	
  for	
  Cloud	
  business	
  	
  
Responsibility	
  for	
  data	
  protec9on	
  	
  
in	
  the	
  cloud	
  ?	
  
Data	
  processing	
  in	
  
cloud	
  services	
  is	
  
subject	
  to	
  European	
  
and	
  na,onal	
  data	
  
protec9on	
  law	
  
Responsibility	
  for	
  data	
  
protec9on	
  lies	
  with	
  
the	
  customer	
  using	
  
the	
  cloud	
  services	
  
What	
  are	
  customers	
  responsibili9es	
  ?	
  
	
  
WriVen	
  contract	
  for	
  
carrying	
  out	
  data	
  
processing	
  on	
  behalf	
  is	
  
mandatory	
  
Determina9on	
  where	
  the	
  
data	
  is	
  technically	
  
processed	
  
Cloud	
  provider	
  should	
  be	
  
obliged	
  to	
  use	
  technical	
  
infrastructure	
  within	
  the	
  
European	
  Economic	
  Area	
  
Processing	
  personal	
  data	
  in	
  the	
  cloud	
  
•  Processing	
  of	
  personal	
  data	
  needs	
  to	
  be	
  
legi9mated	
  either	
  	
  
–  by	
  a	
  legal	
  permission	
  or	
  	
  
–  by	
  consent	
  of	
  the	
  data	
  subject	
  
•  But	
  	
  
–  Legal	
  permission	
  is	
  limited	
  as	
  we	
  have	
  seen	
  already	
  	
  	
  
–  Individual	
  Consent	
  of	
  every	
  cloud	
  user	
  might	
  be	
  
difficult	
  to	
  obtain	
  
•  Solu9on	
  ?	
  	
  
Processing	
  personal	
  data	
  on	
  behalf	
  	
  
A	
  company	
  may	
  choose	
  another	
  organisa9on	
  to	
  process	
  
data	
  on	
  its	
  behalf	
  :	
  	
  data	
  processor	
  
Company	
  remains	
  responsible	
  for	
  ensuring	
  its	
  processing	
  
complies	
  with	
  data	
  protec9on	
  law	
  
Where	
  a	
  data	
  processor	
  is	
  used	
  the	
  data	
  controller	
  must	
  
ensure	
  that	
  suitable	
  arrangements	
  are	
  in	
  place	
  in	
  order	
  to	
  
comply	
  with	
  data	
  protec9on	
  law	
  
TRANSPARENCY	
  is	
  No1	
  issue	
  in	
  
the	
  cloud	
  	
  
	
  	
  
Personal	
  Data	
  
should	
  not	
  be	
  
processed	
  	
  
Transparency	
   Propor9onality	
  
Legi9mate	
  
purpose	
  	
  
So	
  how	
  to	
  deal	
  with	
  cloud	
  providers	
  ?	
  
•  Cloud	
  provider	
  must	
  disclose	
  where	
  data	
  
processing	
  takes	
  place	
  
•  Cloud	
  provider	
  must	
  implement	
  appropriate	
  
technical	
  and	
  organisa9onal	
  measures	
  in	
  order	
  to	
  
protect	
  personal	
  data	
  
•  Cloud	
  user	
  has	
  to	
  review	
  such	
  measures	
  
•  Agreement	
  whether	
  cloud	
  provider	
  may	
  assign	
  
subcontractors	
  
–  Where	
  is	
  the	
  subcontractor	
  located,	
  where	
  is	
  the	
  
data	
  ?	
  
Any	
  ques9ons	
  ?	
  
•  Olaf.Boerner@bcc.biz	
  
•  TwiVer:	
  @OlafBoerner	
  	
  
	
  
•  hVps://www.facebook.com/oboerner	
  	
  
Exkurs	
  Cloud	
  and	
  Data	
  Transfer	
  	
  
•  Direc9ve	
  95/46	
  EC	
  prohibits	
  transfer	
  of	
  personal	
  
data	
  to	
  Non-­‐EU	
  countries	
  that	
  do	
  not	
  meet	
  the	
  
EU´s	
  adequacy	
  standard	
  for	
  data	
  protec9on	
  
•  Within	
  the	
  EU	
  -­‐	
  adequate	
  level	
  of	
  data	
  protec9on	
  
•  Outside	
  of	
  Europe	
  it	
  depends	
  
–  Safe	
  third	
  countries:	
  
•  Switzerland,	
  Canada,	
  Israel,	
  Argen9na,	
  New	
  Zealand,	
  
Australia,	
  Uruguay	
  	
  
•  USA	
  (Safe	
  Harbor)	
  	
  
•  Andorra,	
  Faeroe	
  Islands,	
  Guernsey,	
  Isle	
  of	
  Man,	
  Jersey	
  
Data	
  Transfer	
  to	
  the	
  United	
  States	
  	
  
•  Safe	
  Harbor	
  Framework	
  
– Recognised	
  by	
  the	
  EU	
  Commission	
  as	
  providing	
  
adequate	
  protec9on	
  
– Cloud	
  providers	
  in	
  the	
  US	
  can	
  sign	
  up	
  to	
  the	
  Safe	
  
Harbor	
  Scheme	
  
– A	
  list	
  of	
  organisa9ons	
  that	
  have	
  joined	
  Safe	
  
Harbor	
  is	
  available	
  at	
  
hVp://www.export.gov/safeharbor/	
  
– It	
  may	
  be	
  advisable	
  to	
  combine	
  Safe	
  Harbor	
  and	
  
EU	
  Standard	
  Contractual	
  Clauses	
  in	
  cases	
  of	
  doubt	
  
Cloud	
  and	
  Data	
  Transfer	
  data	
  transfers	
  	
  
•  Countries	
  outside	
  EU	
  with	
  no	
  adequate	
  level	
  
of	
  data	
  protec9on:	
  	
  
– use	
  the	
  EU	
  Standard	
  Contractual	
  Clauses	
  	
  
•  hVp://ec.europa.eu/jus9ce/data-­‐protec9on/
document/interna9onal-­‐transfers/transfer/
index_en.htm	
  	
  
– Sufficient	
  safeguards	
  for	
  data	
  protec9on	
  such	
  as	
  
•  Binding	
  Corporate	
  Rules	
  (BCR)	
  
•  EU	
  Standard	
  contractual	
  clauses	
  (for	
  the	
  transport	
  of	
  
personal	
  data	
  to	
  processors	
  established	
  in	
  third	
  
countries)	
  
Any	
  ques9ons	
  ?	
  
•  Olaf.Boerner@bcc.biz	
  
•  TwiVer:	
  @OlafBoerner	
  	
  
	
  
•  hVps://www.facebook.com/oboerner	
  	
  
Using Social Business Software and being compliant with EU data protection law - presented by Olaf Boerner at Social Connections VII Sockholm

Contenu connexe

Tendances

DMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberDMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberRachel Aldighieri
 
GDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIGDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIKarel Holst
 
Interact 2018 - GDPR for digital publishers, digital agencies and advertisers
Interact 2018 -  GDPR for digital publishers, digital agencies and advertisersInteract 2018 -  GDPR for digital publishers, digital agencies and advertisers
Interact 2018 - GDPR for digital publishers, digital agencies and advertisersIAB Europe
 
GDPR will be the new regulation on may 2018
GDPR will be the new regulation on may 2018GDPR will be the new regulation on may 2018
GDPR will be the new regulation on may 2018Marjane Moghimi, ERP
 
DMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 decemberDMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 decemberRachel Aldighieri
 
EU General Data Protection: Implications for Smart Metering
EU General Data Protection: Implications for Smart MeteringEU General Data Protection: Implications for Smart Metering
EU General Data Protection: Implications for Smart Meteringnuances
 
Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPRPavol Balaj
 
Gdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seoGdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seoKeithBudden3
 
Sophie's Privacy - a story about GDPR
Sophie's Privacy - a story about GDPRSophie's Privacy - a story about GDPR
Sophie's Privacy - a story about GDPRHans Demeyer
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Aaron Banham
 
Wsgr eu data protection briefing march 20 2013 - final
Wsgr   eu data protection briefing march 20 2013 - finalWsgr   eu data protection briefing march 20 2013 - final
Wsgr eu data protection briefing march 20 2013 - finalValentin Korobkov
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
GDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONGDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONSaurabh Pandey
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and PrivacyVertex Holdings
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingIT Governance Ltd
 
Modelling the General Data Protection Regulation
Modelling the General Data Protection RegulationModelling the General Data Protection Regulation
Modelling the General Data Protection RegulationSabrina Kirrane
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsUlf Mattsson
 
General Data Protection Regulation for Ops
General Data Protection Regulation for OpsGeneral Data Protection Regulation for Ops
General Data Protection Regulation for OpsKamil Rextin
 

Tendances (20)

DMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberDMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 October
 
GDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIGDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORI
 
Interact 2018 - GDPR for digital publishers, digital agencies and advertisers
Interact 2018 -  GDPR for digital publishers, digital agencies and advertisersInteract 2018 -  GDPR for digital publishers, digital agencies and advertisers
Interact 2018 - GDPR for digital publishers, digital agencies and advertisers
 
GDPR will be the new regulation on may 2018
GDPR will be the new regulation on may 2018GDPR will be the new regulation on may 2018
GDPR will be the new regulation on may 2018
 
DMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 decemberDMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 december
 
EU General Data Protection: Implications for Smart Metering
EU General Data Protection: Implications for Smart MeteringEU General Data Protection: Implications for Smart Metering
EU General Data Protection: Implications for Smart Metering
 
Data protection
Data protectionData protection
Data protection
 
Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPR
 
Gdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seoGdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seo
 
Sophie's Privacy - a story about GDPR
Sophie's Privacy - a story about GDPRSophie's Privacy - a story about GDPR
Sophie's Privacy - a story about GDPR
 
GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0
 
Wsgr eu data protection briefing march 20 2013 - final
Wsgr   eu data protection briefing march 20 2013 - finalWsgr   eu data protection briefing march 20 2013 - final
Wsgr eu data protection briefing march 20 2013 - final
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
GDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONGDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATION
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and Privacy
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
 
Modelling the General Data Protection Regulation
Modelling the General Data Protection RegulationModelling the General Data Protection Regulation
Modelling the General Data Protection Regulation
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulations
 
General Data Protection Regulation for Ops
General Data Protection Regulation for OpsGeneral Data Protection Regulation for Ops
General Data Protection Regulation for Ops
 

En vedette

Mis mejore momentos felices de mi vida
Mis mejore momentos felices de mi vidaMis mejore momentos felices de mi vida
Mis mejore momentos felices de mi vidamilenacabrera06
 
Recopilación de afiches; Partido SI
Recopilación de afiches; Partido SIRecopilación de afiches; Partido SI
Recopilación de afiches; Partido SIjosefinavaldez2013
 
MMUKA VALENCE CV --UPDATED VERSION 2016
MMUKA VALENCE CV --UPDATED VERSION 2016MMUKA VALENCE CV --UPDATED VERSION 2016
MMUKA VALENCE CV --UPDATED VERSION 2016Valence Mmuka
 
Wimax : The Quintessential Answer to Broadband in India, Protiviti 09
Wimax : The Quintessential Answer to Broadband in India, Protiviti 09Wimax : The Quintessential Answer to Broadband in India, Protiviti 09
Wimax : The Quintessential Answer to Broadband in India, Protiviti 09Going Wimax
 
Tecnologias y vino en navarra anexo soluciones tic
Tecnologias y vino en navarra   anexo soluciones ticTecnologias y vino en navarra   anexo soluciones tic
Tecnologias y vino en navarra anexo soluciones ticCein
 
Ftk Wres Presentation Apr 2011 Agk
Ftk Wres Presentation Apr  2011 AgkFtk Wres Presentation Apr  2011 Agk
Ftk Wres Presentation Apr 2011 AgkAxel G. Kristiansen
 
Internet safety
Internet safetyInternet safety
Internet safetyzunker
 
Sedona Weekly Real Estate Transaction report
Sedona Weekly Real Estate Transaction reportSedona Weekly Real Estate Transaction report
Sedona Weekly Real Estate Transaction reportDamian Bruno
 
Rebuilt.la historia de mi vida...
Rebuilt.la historia de mi vida...Rebuilt.la historia de mi vida...
Rebuilt.la historia de mi vida...Paola Ruiz Sanchez
 
Campamentos verano loreto 2015
Campamentos verano loreto 2015Campamentos verano loreto 2015
Campamentos verano loreto 2015ActividadesAire
 
Decàleg de consells i indicacions de la Creu Roja
Decàleg de consells i indicacions de la Creu RojaDecàleg de consells i indicacions de la Creu Roja
Decàleg de consells i indicacions de la Creu RojaCreu Roja a Catalunya
 

En vedette (20)

Mis mejore momentos felices de mi vida
Mis mejore momentos felices de mi vidaMis mejore momentos felices de mi vida
Mis mejore momentos felices de mi vida
 
Recopilación de afiches; Partido SI
Recopilación de afiches; Partido SIRecopilación de afiches; Partido SI
Recopilación de afiches; Partido SI
 
matriz foda vensecar.
matriz foda vensecar. matriz foda vensecar.
matriz foda vensecar.
 
MMUKA VALENCE CV --UPDATED VERSION 2016
MMUKA VALENCE CV --UPDATED VERSION 2016MMUKA VALENCE CV --UPDATED VERSION 2016
MMUKA VALENCE CV --UPDATED VERSION 2016
 
Responsive wordpress
Responsive wordpressResponsive wordpress
Responsive wordpress
 
Wimax : The Quintessential Answer to Broadband in India, Protiviti 09
Wimax : The Quintessential Answer to Broadband in India, Protiviti 09Wimax : The Quintessential Answer to Broadband in India, Protiviti 09
Wimax : The Quintessential Answer to Broadband in India, Protiviti 09
 
Tecnologias y vino en navarra anexo soluciones tic
Tecnologias y vino en navarra   anexo soluciones ticTecnologias y vino en navarra   anexo soluciones tic
Tecnologias y vino en navarra anexo soluciones tic
 
tiendas mavila
tiendas mavila tiendas mavila
tiendas mavila
 
Ftk Wres Presentation Apr 2011 Agk
Ftk Wres Presentation Apr  2011 AgkFtk Wres Presentation Apr  2011 Agk
Ftk Wres Presentation Apr 2011 Agk
 
Evolucion de la historia de la comunicacion
Evolucion de la historia de la comunicacionEvolucion de la historia de la comunicacion
Evolucion de la historia de la comunicacion
 
Internet safety
Internet safetyInternet safety
Internet safety
 
Sedona Weekly Real Estate Transaction report
Sedona Weekly Real Estate Transaction reportSedona Weekly Real Estate Transaction report
Sedona Weekly Real Estate Transaction report
 
Rebuilt.la historia de mi vida...
Rebuilt.la historia de mi vida...Rebuilt.la historia de mi vida...
Rebuilt.la historia de mi vida...
 
Una travesía ambiental
Una travesía ambientalUna travesía ambiental
Una travesía ambiental
 
Scrum day post ch
Scrum day post chScrum day post ch
Scrum day post ch
 
Presentación paymony
Presentación paymonyPresentación paymony
Presentación paymony
 
Campamentos verano loreto 2015
Campamentos verano loreto 2015Campamentos verano loreto 2015
Campamentos verano loreto 2015
 
Decàleg de consells i indicacions de la Creu Roja
Decàleg de consells i indicacions de la Creu RojaDecàleg de consells i indicacions de la Creu Roja
Decàleg de consells i indicacions de la Creu Roja
 
CURRICULO BAS 2015
CURRICULO BAS 2015CURRICULO BAS 2015
CURRICULO BAS 2015
 
Zertifikato
ZertifikatoZertifikato
Zertifikato
 

Similaire à Using Social Business Software and being compliant with EU data protection law - presented by Olaf Boerner at Social Connections VII Sockholm

Your Big Data Opportunity
Your Big Data OpportunityYour Big Data Opportunity
Your Big Data OpportunityiCrossing
 
Kawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the CloudKawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the CloudGurbir Singh
 
Quick Guide: EU General Data Protection Regulation and Smart Metering
Quick Guide: EU General Data Protection Regulation and Smart MeteringQuick Guide: EU General Data Protection Regulation and Smart Metering
Quick Guide: EU General Data Protection Regulation and Smart Meteringnuances
 
Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Lumension
 
Tieto - Transfer of International Companies’ Corporate IT Systems to Russia a...
Tieto - Transfer of International Companies’ Corporate IT Systems to Russia a...Tieto - Transfer of International Companies’ Corporate IT Systems to Russia a...
Tieto - Transfer of International Companies’ Corporate IT Systems to Russia a...Accountor Russia and Ukraine
 
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...Brian Miller, Solicitor
 
Privacy by design for startups: legal and technology
Privacy by design for startups: legal and technologyPrivacy by design for startups: legal and technology
Privacy by design for startups: legal and technologyIshay Tentser
 
EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)Napier University
 
The Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t knowThe Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t knowSymantec
 
The GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for complianceThe GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for complianceIT Governance Ltd
 
Privacy by design for peerlyst meetup
Privacy by design for peerlyst meetupPrivacy by design for peerlyst meetup
Privacy by design for peerlyst meetupIshay Tentser
 
Ipswitch and cordery on the road " All you need to know about GDPR but are t...
Ipswitch and cordery on the road  " All you need to know about GDPR but are t...Ipswitch and cordery on the road  " All you need to know about GDPR but are t...
Ipswitch and cordery on the road " All you need to know about GDPR but are t...Sébastien Roques
 
What is GDPR?
What is GDPR?What is GDPR?
What is GDPR?Faidepro
 
Data Security Breach – knowing the risks and protecting your business
Data Security Breach – knowing the risks and protecting your businessData Security Breach – knowing the risks and protecting your business
Data Security Breach – knowing the risks and protecting your businessEversheds Sutherland
 
Jowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens ScownJowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens ScownAgile PR
 
Everything you need to know about the GDPR
Everything you need to know about the GDPREverything you need to know about the GDPR
Everything you need to know about the GDPRSpoon London
 
Data protection janine paterson - direct marketing association
Data protection   janine paterson - direct marketing associationData protection   janine paterson - direct marketing association
Data protection janine paterson - direct marketing associationiof_events
 

Similaire à Using Social Business Software and being compliant with EU data protection law - presented by Olaf Boerner at Social Connections VII Sockholm (20)

Your Big Data Opportunity
Your Big Data OpportunityYour Big Data Opportunity
Your Big Data Opportunity
 
Preparing for EU GDPR
Preparing for EU GDPRPreparing for EU GDPR
Preparing for EU GDPR
 
Kawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the CloudKawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the Cloud
 
Quick Guide: EU General Data Protection Regulation and Smart Metering
Quick Guide: EU General Data Protection Regulation and Smart MeteringQuick Guide: EU General Data Protection Regulation and Smart Metering
Quick Guide: EU General Data Protection Regulation and Smart Metering
 
Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?
 
Tieto - Transfer of International Companies’ Corporate IT Systems to Russia a...
Tieto - Transfer of International Companies’ Corporate IT Systems to Russia a...Tieto - Transfer of International Companies’ Corporate IT Systems to Russia a...
Tieto - Transfer of International Companies’ Corporate IT Systems to Russia a...
 
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...
Data Protection and the Cloud (Part 2) by Brian Miller Solicitor and Vicki Bo...
 
Privacy by design for startups: legal and technology
Privacy by design for startups: legal and technologyPrivacy by design for startups: legal and technology
Privacy by design for startups: legal and technology
 
EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)
 
The Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t knowThe Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t know
 
The GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for complianceThe GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for compliance
 
Privacy by design for peerlyst meetup
Privacy by design for peerlyst meetupPrivacy by design for peerlyst meetup
Privacy by design for peerlyst meetup
 
Ipswitch and cordery on the road " All you need to know about GDPR but are t...
Ipswitch and cordery on the road  " All you need to know about GDPR but are t...Ipswitch and cordery on the road  " All you need to know about GDPR but are t...
Ipswitch and cordery on the road " All you need to know about GDPR but are t...
 
What is GDPR?
What is GDPR?What is GDPR?
What is GDPR?
 
Data Security Breach – knowing the risks and protecting your business
Data Security Breach – knowing the risks and protecting your businessData Security Breach – knowing the risks and protecting your business
Data Security Breach – knowing the risks and protecting your business
 
GDPR Part 1: Quick Facts
GDPR Part 1: Quick FactsGDPR Part 1: Quick Facts
GDPR Part 1: Quick Facts
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
Jowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens ScownJowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens Scown
 
Everything you need to know about the GDPR
Everything you need to know about the GDPREverything you need to know about the GDPR
Everything you need to know about the GDPR
 
Data protection janine paterson - direct marketing association
Data protection   janine paterson - direct marketing associationData protection   janine paterson - direct marketing association
Data protection janine paterson - direct marketing association
 

Plus de BCC - Solutions for IBM Collaboration Software

Plus de BCC - Solutions for IBM Collaboration Software (20)

Connections 5.x to 6.0 migration
Connections 5.x to 6.0 migrationConnections 5.x to 6.0 migration
Connections 5.x to 6.0 migration
 
Systematisch: Von der alten in die neue Welt - Migrations-Szenarien
Systematisch: Von der alten in die neue Welt - Migrations-SzenarienSystematisch: Von der alten in die neue Welt - Migrations-Szenarien
Systematisch: Von der alten in die neue Welt - Migrations-Szenarien
 
MaRisk Andorderungen erfüllen - Analyse von Rechten und Rollen in IBM Domino ...
MaRisk Andorderungen erfüllen - Analyse von Rechten und Rollen in IBM Domino ...MaRisk Andorderungen erfüllen - Analyse von Rechten und Rollen in IBM Domino ...
MaRisk Andorderungen erfüllen - Analyse von Rechten und Rollen in IBM Domino ...
 
Protect your IBM Domino data from leaks with BCC DominoProtect
Protect your IBM Domino data from leaks with BCC DominoProtectProtect your IBM Domino data from leaks with BCC DominoProtect
Protect your IBM Domino data from leaks with BCC DominoProtect
 
IBM Connections Cloud Administration
IBM Connections Cloud AdministrationIBM Connections Cloud Administration
IBM Connections Cloud Administration
 
IBM Connect 2016: Speaker Session with Teresa Deane, Senior Developer, BCC
IBM Connect 2016: Speaker Session with Teresa Deane, Senior Developer, BCCIBM Connect 2016: Speaker Session with Teresa Deane, Senior Developer, BCC
IBM Connect 2016: Speaker Session with Teresa Deane, Senior Developer, BCC
 
Dr. Strangelove, or how I learned to love plug-in development - SNoUG 2014
Dr. Strangelove, or how I learned to love plug-in development - SNoUG 2014Dr. Strangelove, or how I learned to love plug-in development - SNoUG 2014
Dr. Strangelove, or how I learned to love plug-in development - SNoUG 2014
 
XPages Performance Master Class - Survive in the fast lane on the Autobahn (E...
XPages Performance Master Class - Survive in the fast lane on the Autobahn (E...XPages Performance Master Class - Survive in the fast lane on the Autobahn (E...
XPages Performance Master Class - Survive in the fast lane on the Autobahn (E...
 
Keine Kompromisse! Mehr Sicherheit & Compliance für IBM Domino
Keine Kompromisse! Mehr Sicherheit & Compliance für IBM DominoKeine Kompromisse! Mehr Sicherheit & Compliance für IBM Domino
Keine Kompromisse! Mehr Sicherheit & Compliance für IBM Domino
 
Honey, I shrunk the data - Mehr Platz am IBM Domino Server
Honey, I shrunk the data - Mehr Platz am IBM Domino ServerHoney, I shrunk the data - Mehr Platz am IBM Domino Server
Honey, I shrunk the data - Mehr Platz am IBM Domino Server
 
Wie schützen Sie Ihre Messaging- & Collaboration-Infrastruktur? Lessons learn...
Wie schützen Sie Ihre Messaging- & Collaboration-Infrastruktur? Lessons learn...Wie schützen Sie Ihre Messaging- & Collaboration-Infrastruktur? Lessons learn...
Wie schützen Sie Ihre Messaging- & Collaboration-Infrastruktur? Lessons learn...
 
IBM Connect 2014 SPOT114: No Compromise on Compliance: Streamline Administrat...
IBM Connect 2014 SPOT114: No Compromise on Compliance: Streamline Administrat...IBM Connect 2014 SPOT114: No Compromise on Compliance: Streamline Administrat...
IBM Connect 2014 SPOT114: No Compromise on Compliance: Streamline Administrat...
 
Platz schaffen auf dem Domino - Compact, Compress, De-Duplicate - Ulrich Krau...
Platz schaffen auf dem Domino - Compact, Compress, De-Duplicate - Ulrich Krau...Platz schaffen auf dem Domino - Compact, Compress, De-Duplicate - Ulrich Krau...
Platz schaffen auf dem Domino - Compact, Compress, De-Duplicate - Ulrich Krau...
 
XPages: Performance-Optimierung - Ulrich Krause (eknori) SNoUG 2013
XPages: Performance-Optimierung  - Ulrich Krause (eknori) SNoUG 2013XPages: Performance-Optimierung  - Ulrich Krause (eknori) SNoUG 2013
XPages: Performance-Optimierung - Ulrich Krause (eknori) SNoUG 2013
 
Deep Dive Domino Mail Routing - SMTP Cookbook - DNUG Herbstkonferenz 2013
Deep Dive Domino Mail Routing - SMTP Cookbook - DNUG Herbstkonferenz 2013Deep Dive Domino Mail Routing - SMTP Cookbook - DNUG Herbstkonferenz 2013
Deep Dive Domino Mail Routing - SMTP Cookbook - DNUG Herbstkonferenz 2013
 
Deep Dive AdminP Process - Admin and Infrastructure Track at UKLUG 2012
Deep Dive AdminP Process - Admin and Infrastructure Track at UKLUG 2012Deep Dive AdminP Process - Admin and Infrastructure Track at UKLUG 2012
Deep Dive AdminP Process - Admin and Infrastructure Track at UKLUG 2012
 
Platz da! Platz schaffen auf dem Domino Server - Vortrag von Ulrich Krause be...
Platz da! Platz schaffen auf dem Domino Server - Vortrag von Ulrich Krause be...Platz da! Platz schaffen auf dem Domino Server - Vortrag von Ulrich Krause be...
Platz da! Platz schaffen auf dem Domino Server - Vortrag von Ulrich Krause be...
 
Wie gewährleisten Sie die Einhaltung von Sicherheitsanforderungen an Ihre Mes...
Wie gewährleisten Sie die Einhaltung von Sicherheitsanforderungen an Ihre Mes...Wie gewährleisten Sie die Einhaltung von Sicherheitsanforderungen an Ihre Mes...
Wie gewährleisten Sie die Einhaltung von Sicherheitsanforderungen an Ihre Mes...
 
Wie schützen Sie Ihre E-Mail-Kommunikation? Kurzfristige Lösungsansätze bis z...
Wie schützen Sie Ihre E-Mail-Kommunikation? Kurzfristige Lösungsansätze bis z...Wie schützen Sie Ihre E-Mail-Kommunikation? Kurzfristige Lösungsansätze bis z...
Wie schützen Sie Ihre E-Mail-Kommunikation? Kurzfristige Lösungsansätze bis z...
 
BCC solutions for IBM Notes & Domino Infrastructure & Administration
BCC solutions for IBM Notes & Domino Infrastructure & AdministrationBCC solutions for IBM Notes & Domino Infrastructure & Administration
BCC solutions for IBM Notes & Domino Infrastructure & Administration
 

Dernier

Revolutionizing the Digital Transformation Office - Leveraging OnePlan’s AI a...
Revolutionizing the Digital Transformation Office - Leveraging OnePlan’s AI a...Revolutionizing the Digital Transformation Office - Leveraging OnePlan’s AI a...
Revolutionizing the Digital Transformation Office - Leveraging OnePlan’s AI a...OnePlan Solutions
 
Data modeling 101 - Basics - Software Domain
Data modeling 101 - Basics - Software DomainData modeling 101 - Basics - Software Domain
Data modeling 101 - Basics - Software DomainAbdul Ahad
 
SAM Training Session - How to use EXCEL ?
SAM Training Session - How to use EXCEL ?SAM Training Session - How to use EXCEL ?
SAM Training Session - How to use EXCEL ?Alexandre Beguel
 
Zer0con 2024 final share short version.pdf
Zer0con 2024 final share short version.pdfZer0con 2024 final share short version.pdf
Zer0con 2024 final share short version.pdfmaor17
 
UI5ers live - Custom Controls wrapping 3rd-party libs.pptx
UI5ers live - Custom Controls wrapping 3rd-party libs.pptxUI5ers live - Custom Controls wrapping 3rd-party libs.pptx
UI5ers live - Custom Controls wrapping 3rd-party libs.pptxAndreas Kunz
 
VictoriaMetrics Q1 Meet Up '24 - Community & News Update
VictoriaMetrics Q1 Meet Up '24 - Community & News UpdateVictoriaMetrics Q1 Meet Up '24 - Community & News Update
VictoriaMetrics Q1 Meet Up '24 - Community & News UpdateVictoriaMetrics
 
2024-04-09 - From Complexity to Clarity - AWS Summit AMS.pdf
2024-04-09 - From Complexity to Clarity - AWS Summit AMS.pdf2024-04-09 - From Complexity to Clarity - AWS Summit AMS.pdf
2024-04-09 - From Complexity to Clarity - AWS Summit AMS.pdfAndrey Devyatkin
 
Strategies for using alternative queries to mitigate zero results
Strategies for using alternative queries to mitigate zero resultsStrategies for using alternative queries to mitigate zero results
Strategies for using alternative queries to mitigate zero resultsJean Silva
 
OpenChain AI Study Group - Europe and Asia Recap - 2024-04-11 - Full Recording
OpenChain AI Study Group - Europe and Asia Recap - 2024-04-11 - Full RecordingOpenChain AI Study Group - Europe and Asia Recap - 2024-04-11 - Full Recording
OpenChain AI Study Group - Europe and Asia Recap - 2024-04-11 - Full RecordingShane Coughlan
 
OpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full Recording
OpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full RecordingOpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full Recording
OpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full RecordingShane Coughlan
 
Leveraging AI for Mobile App Testing on Real Devices | Applitools + Kobiton
Leveraging AI for Mobile App Testing on Real Devices | Applitools + KobitonLeveraging AI for Mobile App Testing on Real Devices | Applitools + Kobiton
Leveraging AI for Mobile App Testing on Real Devices | Applitools + KobitonApplitools
 
Tech Tuesday Slides - Introduction to Project Management with OnePlan's Work ...
Tech Tuesday Slides - Introduction to Project Management with OnePlan's Work ...Tech Tuesday Slides - Introduction to Project Management with OnePlan's Work ...
Tech Tuesday Slides - Introduction to Project Management with OnePlan's Work ...OnePlan Solutions
 
Understanding Flamingo - DeepMind's VLM Architecture
Understanding Flamingo - DeepMind's VLM ArchitectureUnderstanding Flamingo - DeepMind's VLM Architecture
Understanding Flamingo - DeepMind's VLM Architecturerahul_net
 
GraphSummit Madrid - Product Vision and Roadmap - Luis Salvador Neo4j
GraphSummit Madrid - Product Vision and Roadmap - Luis Salvador Neo4jGraphSummit Madrid - Product Vision and Roadmap - Luis Salvador Neo4j
GraphSummit Madrid - Product Vision and Roadmap - Luis Salvador Neo4jNeo4j
 
Amazon Bedrock in Action - presentation of the Bedrock's capabilities
Amazon Bedrock in Action - presentation of the Bedrock's capabilitiesAmazon Bedrock in Action - presentation of the Bedrock's capabilities
Amazon Bedrock in Action - presentation of the Bedrock's capabilitiesKrzysztofKkol1
 
Introduction to Firebase Workshop Slides
Introduction to Firebase Workshop SlidesIntroduction to Firebase Workshop Slides
Introduction to Firebase Workshop Slidesvaideheekore1
 
2024 DevNexus Patterns for Resiliency: Shuffle shards
2024 DevNexus Patterns for Resiliency: Shuffle shards2024 DevNexus Patterns for Resiliency: Shuffle shards
2024 DevNexus Patterns for Resiliency: Shuffle shardsChristopher Curtin
 
What’s New in VictoriaMetrics: Q1 2024 Updates
What’s New in VictoriaMetrics: Q1 2024 UpdatesWhat’s New in VictoriaMetrics: Q1 2024 Updates
What’s New in VictoriaMetrics: Q1 2024 UpdatesVictoriaMetrics
 
eSoftTools IMAP Backup Software and migration tools
eSoftTools IMAP Backup Software and migration toolseSoftTools IMAP Backup Software and migration tools
eSoftTools IMAP Backup Software and migration toolsosttopstonverter
 
Large Language Models for Test Case Evolution and Repair
Large Language Models for Test Case Evolution and RepairLarge Language Models for Test Case Evolution and Repair
Large Language Models for Test Case Evolution and RepairLionel Briand
 

Dernier (20)

Revolutionizing the Digital Transformation Office - Leveraging OnePlan’s AI a...
Revolutionizing the Digital Transformation Office - Leveraging OnePlan’s AI a...Revolutionizing the Digital Transformation Office - Leveraging OnePlan’s AI a...
Revolutionizing the Digital Transformation Office - Leveraging OnePlan’s AI a...
 
Data modeling 101 - Basics - Software Domain
Data modeling 101 - Basics - Software DomainData modeling 101 - Basics - Software Domain
Data modeling 101 - Basics - Software Domain
 
SAM Training Session - How to use EXCEL ?
SAM Training Session - How to use EXCEL ?SAM Training Session - How to use EXCEL ?
SAM Training Session - How to use EXCEL ?
 
Zer0con 2024 final share short version.pdf
Zer0con 2024 final share short version.pdfZer0con 2024 final share short version.pdf
Zer0con 2024 final share short version.pdf
 
UI5ers live - Custom Controls wrapping 3rd-party libs.pptx
UI5ers live - Custom Controls wrapping 3rd-party libs.pptxUI5ers live - Custom Controls wrapping 3rd-party libs.pptx
UI5ers live - Custom Controls wrapping 3rd-party libs.pptx
 
VictoriaMetrics Q1 Meet Up '24 - Community & News Update
VictoriaMetrics Q1 Meet Up '24 - Community & News UpdateVictoriaMetrics Q1 Meet Up '24 - Community & News Update
VictoriaMetrics Q1 Meet Up '24 - Community & News Update
 
2024-04-09 - From Complexity to Clarity - AWS Summit AMS.pdf
2024-04-09 - From Complexity to Clarity - AWS Summit AMS.pdf2024-04-09 - From Complexity to Clarity - AWS Summit AMS.pdf
2024-04-09 - From Complexity to Clarity - AWS Summit AMS.pdf
 
Strategies for using alternative queries to mitigate zero results
Strategies for using alternative queries to mitigate zero resultsStrategies for using alternative queries to mitigate zero results
Strategies for using alternative queries to mitigate zero results
 
OpenChain AI Study Group - Europe and Asia Recap - 2024-04-11 - Full Recording
OpenChain AI Study Group - Europe and Asia Recap - 2024-04-11 - Full RecordingOpenChain AI Study Group - Europe and Asia Recap - 2024-04-11 - Full Recording
OpenChain AI Study Group - Europe and Asia Recap - 2024-04-11 - Full Recording
 
OpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full Recording
OpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full RecordingOpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full Recording
OpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full Recording
 
Leveraging AI for Mobile App Testing on Real Devices | Applitools + Kobiton
Leveraging AI for Mobile App Testing on Real Devices | Applitools + KobitonLeveraging AI for Mobile App Testing on Real Devices | Applitools + Kobiton
Leveraging AI for Mobile App Testing on Real Devices | Applitools + Kobiton
 
Tech Tuesday Slides - Introduction to Project Management with OnePlan's Work ...
Tech Tuesday Slides - Introduction to Project Management with OnePlan's Work ...Tech Tuesday Slides - Introduction to Project Management with OnePlan's Work ...
Tech Tuesday Slides - Introduction to Project Management with OnePlan's Work ...
 
Understanding Flamingo - DeepMind's VLM Architecture
Understanding Flamingo - DeepMind's VLM ArchitectureUnderstanding Flamingo - DeepMind's VLM Architecture
Understanding Flamingo - DeepMind's VLM Architecture
 
GraphSummit Madrid - Product Vision and Roadmap - Luis Salvador Neo4j
GraphSummit Madrid - Product Vision and Roadmap - Luis Salvador Neo4jGraphSummit Madrid - Product Vision and Roadmap - Luis Salvador Neo4j
GraphSummit Madrid - Product Vision and Roadmap - Luis Salvador Neo4j
 
Amazon Bedrock in Action - presentation of the Bedrock's capabilities
Amazon Bedrock in Action - presentation of the Bedrock's capabilitiesAmazon Bedrock in Action - presentation of the Bedrock's capabilities
Amazon Bedrock in Action - presentation of the Bedrock's capabilities
 
Introduction to Firebase Workshop Slides
Introduction to Firebase Workshop SlidesIntroduction to Firebase Workshop Slides
Introduction to Firebase Workshop Slides
 
2024 DevNexus Patterns for Resiliency: Shuffle shards
2024 DevNexus Patterns for Resiliency: Shuffle shards2024 DevNexus Patterns for Resiliency: Shuffle shards
2024 DevNexus Patterns for Resiliency: Shuffle shards
 
What’s New in VictoriaMetrics: Q1 2024 Updates
What’s New in VictoriaMetrics: Q1 2024 UpdatesWhat’s New in VictoriaMetrics: Q1 2024 Updates
What’s New in VictoriaMetrics: Q1 2024 Updates
 
eSoftTools IMAP Backup Software and migration tools
eSoftTools IMAP Backup Software and migration toolseSoftTools IMAP Backup Software and migration tools
eSoftTools IMAP Backup Software and migration tools
 
Large Language Models for Test Case Evolution and Repair
Large Language Models for Test Case Evolution and RepairLarge Language Models for Test Case Evolution and Repair
Large Language Models for Test Case Evolution and Repair
 

Using Social Business Software and being compliant with EU data protection law - presented by Olaf Boerner at Social Connections VII Sockholm

  • 1. Using  Social  Business  So/ware   and  being  compliant  with  EU   data  protec9on  law   Olaf  Boerner,  BCC     14.11.2014    
  • 2.
  • 3. Agenda:     Using  Social  Business  So/ware  and  being   compliant  with  EU  data  protec9on  law   1.  Short  Introduc9on  to  EU  Data  Protec9on  Law   2.  Implica9ons  for  using  social  business   so/ware   3.  Data  protec9on  and  Cloud  based  social   systems  
  • 4. About me •  Studied  Business  Administra9on  and     Computer  Science   •  Notes  Administrator  /  Developer  since  1994   •  CEO  and  Founder  of  BCC  in  1996     •  Working  as  project  manager  senior  architect     with  large  enterprise  customers   –  Securing  IBM  Social  Business  infrastructures     –  reducing  Total  cost  of  Ownership  of  IBM  Social  Business   Infrastructures  thru  automa9ng  Administra9on     •  IBM  Champion  in  2014     •  TwiVer:  @OlafBoerner  
  • 5. Short  Disclaimer  J     I  am  not  a  lawyer  !     This  presenta9on  does  not  provide   any  legal  advices  
  • 6. Introduc9on  EU  Data  Protec9on  Law     •  Data  Protec9on  within  the  EU  is  not  op9onal   – It’s  not  an  advice    or  best  prac9ce     – It’s  not  a  silly  german  idea     – it´s  the  law  !   – In  all  EU  Member  States  and  Non-­‐EU  Member   States  that  are  part  of  the  European  Economic   Area    
  • 7. Consequences  of  privacy  breaches     •  Consequences  depend  on  the  law  of  the  member   state   •  Examples   –  Germany:  §  43  German  Federal  Protec9on  Act  up  to   300.000  EURO   –  UK:  ICO  up  to  £  500.000     •  Reputa9onal  damage  as  a  result  of  press  reports   etc   •  Many  contracts  allow  customers  and/or  supplier   to  quit  contracts    
  • 8. Sony  fined  £250,000  a/er  millions  of   UK  gamers’  personal  informa9on   compromised     •  PlaySta9on  Network  Plaeorm  was  hacked  in  April   2011     •  An  ICO  inves9ga9on  found  that  the  aVack  could   have  been  prevented  if  the  so/ware  had  been   up-­‐to-­‐date,  while  technical  developments  also   meant  passwords  were  not  secure.     hVp://ico.org.uk/news/latest_news/2013/ico-­‐ news-­‐release-­‐2013      
  • 9. ICO  fines  Bank  of  Scotland     •  “ICO  fines  Bank  of  Scotland  for  “unforgivable”   breach  of  Data  Protec9on  Act  in  August  2013,   following  repeated  instances  of  customer   details  being  sent  to  the  wrong  recipients.”   •  h"p://www.compu,ng.co.uk/ctg/news/ 2287087/ico-­‐fines-­‐bank-­‐of-­‐scotland-­‐for-­‐ unforgivable-­‐breach-­‐of-­‐data-­‐protec,on-­‐act    
  • 10. Reputa9onal  damage     hVp://brianpennington.co.uk/2012/08/16/who-­‐has-­‐breached-­‐the-­‐data-­‐protec9on-­‐act-­‐in-­‐2012-­‐find-­‐the-­‐ complete-­‐list-­‐here/  
  • 11. Pharmacist  who  worked  for  West   Essex  Primary  Care  Trust  
  • 12. OK,  OK     please  explain  the  law          
  • 13. The  difference  between  US  &  EU     •  Privacy   –  ACT  Code  of  Fair  Informa9on  Prac9ce  that  governs   the  collec9on,  maintenance,  use,  and  dissemina9on   of  personally  iden9fiable  informa9on  about   individuals  that  is  maintained  in  systems  of     •  Data  Protec,on   –  law  on  the  processing  of  data  on  iden9fiable  living   people.  It  is  the  main  piece  of  legisla9on  that  governs   the  protec9on  of  personal  data   Source:  wikepedia    
  • 14. Direc9ve  95/46  EC   •  Member  states  must  transpose  direc9ve   –  Germany:  Federal  Data  Protec9on  Act   (Bundesdatenschutzgesetz)   –  UK:  ICO  Data  Protec9on  Act  and  Privacy  and   Electronic  Communica9ons  Regula9ons  2003   •  Implementa9on  varies  from  member  state  to   another     •  EU  plans  to  unify  data  protec9on  with  a  single   law  –  General  Data  Protec9on  Regula9on  
  • 15. Legal  Scope  of  Direc9ve  95/46  EC     •  Territorial  scope:     –  EU  Member  States  and     –  Non-­‐EU  Member  States  that  are  part  of  the  European   Economic  Area     •  Iceland,     •  Norway  and     •  Liechtenstein   •  Material  scope:     –  processing  of     –  personal  data  
  • 16. Processing  Personal  Data     •  Processing  =  „any  opera9on  ...  which  is   performed  on  personal  data,  whether  or  not   by  automa9c  means,  such  as  collec9on,   recording,  organiza9on,  storage,  adap9on  or   altera9on,  retrieval,  consulta9on,  ...(art  2b)   •  So  what  is  personal  data  ?    
  • 17. Data  is  personal     if  they  relate  to  an   iden9fied  or  at  least   iden9fiable  person,  (data   subject)   if  addi9onal  informa9on   can  be  obtained  without   unreasonable  effort,   allowing  the  iden9fica9on   of  the  data  subject  
  • 18. Examples  for  personal  data   •  Name,       •  Email  adress,     •  Postal  address,     •  bank  statements,     •  credit  card  numbers  …   •  Dynamic  IP  Number  ?    
  • 19. Personal  or  not  personal  ?   •  Data  is  anonymised  if  they  no  longer  contain   any  iden9fiers   •  Anonymised  data  are  not  personal  data     •  Therefore  no  data  protec9on  law  applicable   •  Anonymise  Data  is  currently  this  only  best   prac9ce  to  convert  personal  data  instead  of   dele9ng  these  data  
  • 20. Who  is  the  responsible  for  Data   Protec9on  ?   •  Responsible  party  is  called  „Controller“     –  Natural  or  ar9ficial  person,     –  public  authority,     –  agency  ..     –  which  determines  the  purposes  and  means  of  the   processing  of  personal  data   •  Must  be  related  to  EU  !     –  controller  is  established  or  operates  within  the  EU   –  controller  uses  equipment  located  inside  the  EU  to   process  personal  data  
  • 21. Rules  for  processing  Personal  Data     Personal  Data   should  not  be   processed     except  certain   condi9ons  are   met:   Transparency   Propor9onality   Legi9mate   purpose    
  • 22. Legi9mate  purpose   Data  may   be   processed:   When  the  processing  is  necessary  for  the   performance  of  or  the  entering  into  a  contract   When  the  processing  is  necessary  for   compliance  with  a  legal  obliga9on   When  processing  is  necessary  to  protect  the   vital  interest  of  the  data  subject  or     The  data  subject  has  given  his  consent  
  • 23. Summary  –  Data  Protec9on     •  In  prac9ce  the  issue  of  data  protec9on  refers   to  all  businesses  which  electronically  process   data,   – from  wage  accoun9ng  of  their  own  employees,     – collec9ng  of  customer  data,     – storing  one  of  these  data  in  the  cloud   •  mainly  legi9ma9on  based     – on  performance  of  a  (future)  contract  or     – on  a  given  consent  by  data  subject  
  • 24. Part  II.  Implica9ons  for  using  social   business  so/ware     •  Social  Business  So/ware   – So/ware  systems  that  primarily  func9ons  to  allow   SOCIAL  user  collabora9on  and  communica9on     •  Focus  to  people‘s  business    networks   – Profiles:  TINE  ‘s  Key  applica9on  colle9ng  HR  Data   and  CVs     – Blogs     – Ac9vi9es     – Status  and  Open  Calendar’s    
  • 27. Best  prac9ces  for  social  business   •  Balancing  of  enterprise  vs  personal  interests  is   absolutely  mandatory     •  Consent  of  employees  might  be  required     –  German  legal  prac9ce:  simple  directory  of  experts   containing  name,  job  descrip9on  etc  are  considered   as  legi9mated  processing   –  For  directories  with  extended  func9onali9es  the   consent  of  each  data  subject  is  necessary   – a  consent  is  valid  for  the  dura,on  of  the   employment  only  
  • 28. Best  Prac9ce:  Recommenda9on     •  You  need  a  legal  permission  or  consent  of  the   data  subject  to  be  on  the  safe  side   –  Employee   –  External  users   •  You  need  a  procedure  to  deal  with  users  leaving   company  or  social  network   –  They  might  leave  “peacefully”  BUT     –  Employee  consent  will  end  when  leaving  the  company     –  Ex  Employee  can  withdraw  their  consent  and/or   request  for  data  dele9on    
  • 29. When  do  you  share  knowledge  ?   „In  a  social   enterprise,  your   value  will  not  be   what  you  know;  it   will  be  what  you   share.“  IBM  CEO   Ginni  RomeVy   You  need   confidence  and   trust  in  data   protec9on  to  share   knowledge    
  • 30. Part  III.  Social  Business  in  the  cloud       •  Social  Business  Systems  are  moving  cloud  first     – IBM  Connec9ons  Cloud     – Office  365     Microso/  declared  to  stop  developing  On   Premise  Collabora9on  Products  a/er  2015     IBM  is  s9ll  providing  On  Premise  but  would  love   to  move  YOU  to  the  cloud     •  1.2  Billion  $  Investment  for  Cloud  business    
  • 31. Responsibility  for  data  protec9on     in  the  cloud  ?   Data  processing  in   cloud  services  is   subject  to  European   and  na,onal  data   protec9on  law   Responsibility  for  data   protec9on  lies  with   the  customer  using   the  cloud  services  
  • 32. What  are  customers  responsibili9es  ?     WriVen  contract  for   carrying  out  data   processing  on  behalf  is   mandatory   Determina9on  where  the   data  is  technically   processed   Cloud  provider  should  be   obliged  to  use  technical   infrastructure  within  the   European  Economic  Area  
  • 33. Processing  personal  data  in  the  cloud   •  Processing  of  personal  data  needs  to  be   legi9mated  either     –  by  a  legal  permission  or     –  by  consent  of  the  data  subject   •  But     –  Legal  permission  is  limited  as  we  have  seen  already       –  Individual  Consent  of  every  cloud  user  might  be   difficult  to  obtain   •  Solu9on  ?    
  • 34. Processing  personal  data  on  behalf     A  company  may  choose  another  organisa9on  to  process   data  on  its  behalf  :    data  processor   Company  remains  responsible  for  ensuring  its  processing   complies  with  data  protec9on  law   Where  a  data  processor  is  used  the  data  controller  must   ensure  that  suitable  arrangements  are  in  place  in  order  to   comply  with  data  protec9on  law  
  • 35. TRANSPARENCY  is  No1  issue  in   the  cloud         Personal  Data   should  not  be   processed     Transparency   Propor9onality   Legi9mate   purpose    
  • 36. So  how  to  deal  with  cloud  providers  ?   •  Cloud  provider  must  disclose  where  data   processing  takes  place   •  Cloud  provider  must  implement  appropriate   technical  and  organisa9onal  measures  in  order  to   protect  personal  data   •  Cloud  user  has  to  review  such  measures   •  Agreement  whether  cloud  provider  may  assign   subcontractors   –  Where  is  the  subcontractor  located,  where  is  the   data  ?  
  • 37. Any  ques9ons  ?   •  Olaf.Boerner@bcc.biz   •  TwiVer:  @OlafBoerner       •  hVps://www.facebook.com/oboerner    
  • 38. Exkurs  Cloud  and  Data  Transfer     •  Direc9ve  95/46  EC  prohibits  transfer  of  personal   data  to  Non-­‐EU  countries  that  do  not  meet  the   EU´s  adequacy  standard  for  data  protec9on   •  Within  the  EU  -­‐  adequate  level  of  data  protec9on   •  Outside  of  Europe  it  depends   –  Safe  third  countries:   •  Switzerland,  Canada,  Israel,  Argen9na,  New  Zealand,   Australia,  Uruguay     •  USA  (Safe  Harbor)     •  Andorra,  Faeroe  Islands,  Guernsey,  Isle  of  Man,  Jersey  
  • 39. Data  Transfer  to  the  United  States     •  Safe  Harbor  Framework   – Recognised  by  the  EU  Commission  as  providing   adequate  protec9on   – Cloud  providers  in  the  US  can  sign  up  to  the  Safe   Harbor  Scheme   – A  list  of  organisa9ons  that  have  joined  Safe   Harbor  is  available  at   hVp://www.export.gov/safeharbor/   – It  may  be  advisable  to  combine  Safe  Harbor  and   EU  Standard  Contractual  Clauses  in  cases  of  doubt  
  • 40. Cloud  and  Data  Transfer  data  transfers     •  Countries  outside  EU  with  no  adequate  level   of  data  protec9on:     – use  the  EU  Standard  Contractual  Clauses     •  hVp://ec.europa.eu/jus9ce/data-­‐protec9on/ document/interna9onal-­‐transfers/transfer/ index_en.htm     – Sufficient  safeguards  for  data  protec9on  such  as   •  Binding  Corporate  Rules  (BCR)   •  EU  Standard  contractual  clauses  (for  the  transport  of   personal  data  to  processors  established  in  third   countries)  
  • 41. Any  ques9ons  ?   •  Olaf.Boerner@bcc.biz   •  TwiVer:  @OlafBoerner       •  hVps://www.facebook.com/oboerner