SlideShare une entreprise Scribd logo
1  sur  35
Télécharger pour lire hors ligne
Technical Lead, WSO2
Evolve or Die: Privacy and The Future of
Your Enterprise With CIAM
Ishara Karunarathna
97% of consumers read online
reviews, and 85% of them trust
online reviews.
“BrightLocal Local Consumer Review Survey 2017”
One-star increase on Yelp
leads to a 5-9% increase in
business revenue.
“Reviews, Reputation, and Revenue: The Case of Yelp.com :
Harvard Business School”
Impact of Consumer Reviews
Digital technology has shifted
the power of businesses from
the enterprise to customers.
Impact of Digital Transformation to Business
Knowing your
customer is key!
CIAM at the center
of digital
transformation
Personalized
experience
CIAM
Connect with
consumers
Consumer data
CIAM Checklist
Self signup & Self service dashboard
Progress profiling
Strong authentication
Omnichannel access
Scalability, Security & Fraud Detection
API and integration
Privacy
Privacy Reshapes the
Future of CIAM
Facebook faces
£500,000 fine in UK
over Cambridge
Analytica scandal
Yahoo! exposed the
personal
information of more
than 1 billion users
which has already
cost the company
$350 million
Global Privacy Outlook
D
Data
Protection
Act
PIPEDA
Privacy
Act of
1988
HIPAA,
COPPA,
CCPA,
etc.. Information
Technology
Act
Personal
Information
Protection
Act
Personal
Data
Protection Bill
POPI
Privacy is a
fundamental human
right: GDPR
GDPR is a game
changer!
GDPR : Individual Rights
5
3
Comply with requests not to
automate decision making using
personal data
Right to restrict processing6
7
8
Allow individual’s data to be stored
but not processed.
Provide transparency over how
personal data is collected, stored,
managed, protected, and
processed
Right to be informed1
Right to stop processing
Provide copies of all stored data in
a portable format
Right to data portability
Honor requests not to process an
individual’s data for specific purposes
Right to access2
Provide individual’s access to their data
and explain how they-and any
supplemental data-are used
4
Correct any personal data if
incomplete or inaccurate
Right to rectification
Remove personal data on request
when there is no compelling reason to
keep it
Right to be forgotten
Reject automated decisions
Take back control of
your personal
information: CCPA
What California Consumer Privacy Act Offers
16
Gives You
Ownership
1
Protect your right to
tell a business not to
share or sell your
personal information.
2 Gives You
Control
Gain control over the
personal information
that is collected about
you.
Hold businesses
responsible for
safeguarding your
personal information.
Gives You
Security
3
Future-proof Privacy
Guideline
Key Privacy Considerations for CIAM
Customer
Controlled
Personal Data
Transparency,
Fairness and
Lawfulness
Data Minimization
and Storage
Limitation
Accuracy,
Confidentiality and
Accountability
Key Privacy Considerations for CIAM
Customer
Controlled
Personal Data
Transparency,
Fairness and
Lawfulness
Data Minimization
and Storage
Limitation
Accuracy,
Confidentiality and
Accountability
● Personal data under customer control
○ Self-service user portal
■ Right to access
■ Right to be forgotten
■ Right to data portability
■ Right to restrict data processing
● Keep up to date
Customer Controlled Personal Data
● Review user profiles
● Alteration of user profiles
● Deletion of user profiles
● Keep user profile
up-to-date
● Support user profile
portability
Self-service User Portal
Key Privacy Considerations for CIAM
Customer
Controlled
Personal Data
Transparency,
Fairness and
Lawfulness
Data Minimization
and Storage
Limitation
Accuracy,
Confidentiality and
Accountability
● Clear privacy policy
● Get the consent for personal data processing
○ Personal data processing based on active consent
○ Ability to review given consent and revocation
○ Ability to demonstrate proof of consent
○ Consent design
● Purpose limitation
○ Consent per purpose
Transparency, Fairness and Lawfulness
Consent Lifecycle Management
Welcome
Ishara
Selfcare Portal to Manage given Consents
● Review, modify and revoke consent
Key Privacy Considerations for CIAM
Customer
Controlled
Personal Data
Transparency,
Fairness and
Lawfulness
Data Minimization
and Storage
Limitation
Accuracy,
Confidentiality and
Accountability
● Personal data shall be
○ Adequate
○ Relevant and limited to purposes
● Store data no longer than necessary
● Storage limitation should be in a data retention policy
● Pseudonymized data
● Regional data localization
Data Minimization and Storage Limitation
Application Specific Claim Management
Name : ishara
Email :
isharak@wso2.co
m
ID : 225
Org : WSO2
Name : ishara
Mobile : 0717996791
Multi-region Deployment
Key Privacy Considerations for CIAM
Customer
Controlled
Personal Data
Transparency,
Fairness and
Lawfulness
Data Minimization
and Storage
Limitation
Accuracy,
Confidentiality and
Accountability
● Prevent unauthorized or unlawful processing
● Prevent accidental loss, destruction or damage
● Adequate measures to prevent data breaches
○ Inform about the breaches without delay
● Organization culture of accountability
Accuracy, Integrity, Confidentiality and
Accountability
Multi-factor Authentication
Welcome
Ishara
STEP 1
STEP 2
Analytics, Alerts & Audit-trail
● Digital transformation is critical for business survival
● CIAM plays an integral part in digital transformation
● Privacy is a competitive differentiator in CIMA
● CIAM solution should address
○ Privacy by design
○ Privacy by default
● CIAM should follow future -proof privacy guidelines
Conclusion
THANK YOU
wso2.com

Contenu connexe

Plus de WSO2

Fueling the Digital Experience Economy with Connected Products
Fueling the Digital Experience Economy with Connected ProductsFueling the Digital Experience Economy with Connected Products
Fueling the Digital Experience Economy with Connected Products
WSO2
 
A Reference Methodology for Agile Digital Businesses
 A Reference Methodology for Agile Digital Businesses A Reference Methodology for Agile Digital Businesses
A Reference Methodology for Agile Digital Businesses
WSO2
 

Plus de WSO2 (20)

Choreo - Build unique digital experiences on WSO2's platform, secured by Etho...
Choreo - Build unique digital experiences on WSO2's platform, secured by Etho...Choreo - Build unique digital experiences on WSO2's platform, secured by Etho...
Choreo - Build unique digital experiences on WSO2's platform, secured by Etho...
 
CIO Summit Berlin 2022.pptx.pdf
CIO Summit Berlin 2022.pptx.pdfCIO Summit Berlin 2022.pptx.pdf
CIO Summit Berlin 2022.pptx.pdf
 
Delivering New Digital Experiences Fast - Introducing Choreo
Delivering New Digital Experiences Fast - Introducing ChoreoDelivering New Digital Experiences Fast - Introducing Choreo
Delivering New Digital Experiences Fast - Introducing Choreo
 
Fueling the Digital Experience Economy with Connected Products
Fueling the Digital Experience Economy with Connected ProductsFueling the Digital Experience Economy with Connected Products
Fueling the Digital Experience Economy with Connected Products
 
A Reference Methodology for Agile Digital Businesses
 A Reference Methodology for Agile Digital Businesses A Reference Methodology for Agile Digital Businesses
A Reference Methodology for Agile Digital Businesses
 
Workflows in WSO2 API Manager - WSO2 API Manager Community Call (12/15/2021)
Workflows in WSO2 API Manager - WSO2 API Manager Community Call (12/15/2021)Workflows in WSO2 API Manager - WSO2 API Manager Community Call (12/15/2021)
Workflows in WSO2 API Manager - WSO2 API Manager Community Call (12/15/2021)
 
Lessons from the pandemic - From a single use case to true transformation
 Lessons from the pandemic - From a single use case to true transformation Lessons from the pandemic - From a single use case to true transformation
Lessons from the pandemic - From a single use case to true transformation
 
Adding Liveliness to Banking Experiences
Adding Liveliness to Banking ExperiencesAdding Liveliness to Banking Experiences
Adding Liveliness to Banking Experiences
 
Building a Future-ready Bank
Building a Future-ready BankBuilding a Future-ready Bank
Building a Future-ready Bank
 
WSO2 API Manager Community Call - November 2021
WSO2 API Manager Community Call - November 2021WSO2 API Manager Community Call - November 2021
WSO2 API Manager Community Call - November 2021
 
[API World ] - Managing Asynchronous APIs
[API World ] - Managing Asynchronous APIs[API World ] - Managing Asynchronous APIs
[API World ] - Managing Asynchronous APIs
 
[API World 2021 ] - Understanding Cloud Native Deployment
[API World 2021 ] - Understanding Cloud Native Deployment[API World 2021 ] - Understanding Cloud Native Deployment
[API World 2021 ] - Understanding Cloud Native Deployment
 
[API Word 2021] - Quantum Duality of “API as a Business and a Technology”
[API Word 2021] - Quantum Duality of “API as a Business and a Technology”[API Word 2021] - Quantum Duality of “API as a Business and a Technology”
[API Word 2021] - Quantum Duality of “API as a Business and a Technology”
 
API Revisions - WSO2 API Manager Community Call (10/27/2021)
API Revisions - WSO2 API Manager Community Call (10/27/2021)API Revisions - WSO2 API Manager Community Call (10/27/2021)
API Revisions - WSO2 API Manager Community Call (10/27/2021)
 
[2021 Somos Summit] - Rethinking Identity Access Management and The Rise of t...
[2021 Somos Summit] - Rethinking Identity Access Management and The Rise of t...[2021 Somos Summit] - Rethinking Identity Access Management and The Rise of t...
[2021 Somos Summit] - Rethinking Identity Access Management and The Rise of t...
 
[ICT Spring 2021] - Managed Crowd: The Future of Business as We Know It!
[ICT Spring 2021] - Managed Crowd: The Future of Business as We Know It![ICT Spring 2021] - Managed Crowd: The Future of Business as We Know It!
[ICT Spring 2021] - Managed Crowd: The Future of Business as We Know It!
 
[EIC 2021] Securing the Digital Double - The Path to a Trusted Digital Ecosystem
[EIC 2021] Securing the Digital Double - The Path to a Trusted Digital Ecosystem[EIC 2021] Securing the Digital Double - The Path to a Trusted Digital Ecosystem
[EIC 2021] Securing the Digital Double - The Path to a Trusted Digital Ecosystem
 
[EIC 2021] The Rise of the Developer in IAM
[EIC 2021] The Rise of the Developer in IAM[EIC 2021] The Rise of the Developer in IAM
[EIC 2021] The Rise of the Developer in IAM
 
CSV and JSON Transformation in WSO2 Micro Integrator 4.0 - WSO2 APIM Communit...
CSV and JSON Transformation in WSO2 Micro Integrator 4.0 - WSO2 APIM Communit...CSV and JSON Transformation in WSO2 Micro Integrator 4.0 - WSO2 APIM Communit...
CSV and JSON Transformation in WSO2 Micro Integrator 4.0 - WSO2 APIM Communit...
 
[apidays Live Australia] How does leveraging de-centralised architecture impr...
[apidays Live Australia] How does leveraging de-centralised architecture impr...[apidays Live Australia] How does leveraging de-centralised architecture impr...
[apidays Live Australia] How does leveraging de-centralised architecture impr...
 

Dernier

Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
giselly40
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
Enterprise Knowledge
 

Dernier (20)

Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 

[WSO2Con USA 2018] Evolve or Die: Privacy and The Future of Your Enterprise With CIAM

  • 1. Technical Lead, WSO2 Evolve or Die: Privacy and The Future of Your Enterprise With CIAM Ishara Karunarathna
  • 2. 97% of consumers read online reviews, and 85% of them trust online reviews. “BrightLocal Local Consumer Review Survey 2017” One-star increase on Yelp leads to a 5-9% increase in business revenue. “Reviews, Reputation, and Revenue: The Case of Yelp.com : Harvard Business School” Impact of Consumer Reviews
  • 3. Digital technology has shifted the power of businesses from the enterprise to customers. Impact of Digital Transformation to Business
  • 5. CIAM at the center of digital transformation Personalized experience CIAM Connect with consumers Consumer data
  • 6. CIAM Checklist Self signup & Self service dashboard Progress profiling Strong authentication Omnichannel access Scalability, Security & Fraud Detection API and integration Privacy
  • 8. Facebook faces £500,000 fine in UK over Cambridge Analytica scandal
  • 9.
  • 10. Yahoo! exposed the personal information of more than 1 billion users which has already cost the company $350 million
  • 11. Global Privacy Outlook D Data Protection Act PIPEDA Privacy Act of 1988 HIPAA, COPPA, CCPA, etc.. Information Technology Act Personal Information Protection Act Personal Data Protection Bill POPI
  • 12. Privacy is a fundamental human right: GDPR
  • 13. GDPR is a game changer!
  • 14. GDPR : Individual Rights 5 3 Comply with requests not to automate decision making using personal data Right to restrict processing6 7 8 Allow individual’s data to be stored but not processed. Provide transparency over how personal data is collected, stored, managed, protected, and processed Right to be informed1 Right to stop processing Provide copies of all stored data in a portable format Right to data portability Honor requests not to process an individual’s data for specific purposes Right to access2 Provide individual’s access to their data and explain how they-and any supplemental data-are used 4 Correct any personal data if incomplete or inaccurate Right to rectification Remove personal data on request when there is no compelling reason to keep it Right to be forgotten Reject automated decisions
  • 15. Take back control of your personal information: CCPA
  • 16. What California Consumer Privacy Act Offers 16 Gives You Ownership 1 Protect your right to tell a business not to share or sell your personal information. 2 Gives You Control Gain control over the personal information that is collected about you. Hold businesses responsible for safeguarding your personal information. Gives You Security 3
  • 18. Key Privacy Considerations for CIAM Customer Controlled Personal Data Transparency, Fairness and Lawfulness Data Minimization and Storage Limitation Accuracy, Confidentiality and Accountability
  • 19. Key Privacy Considerations for CIAM Customer Controlled Personal Data Transparency, Fairness and Lawfulness Data Minimization and Storage Limitation Accuracy, Confidentiality and Accountability
  • 20. ● Personal data under customer control ○ Self-service user portal ■ Right to access ■ Right to be forgotten ■ Right to data portability ■ Right to restrict data processing ● Keep up to date Customer Controlled Personal Data
  • 21. ● Review user profiles ● Alteration of user profiles ● Deletion of user profiles ● Keep user profile up-to-date ● Support user profile portability Self-service User Portal
  • 22. Key Privacy Considerations for CIAM Customer Controlled Personal Data Transparency, Fairness and Lawfulness Data Minimization and Storage Limitation Accuracy, Confidentiality and Accountability
  • 23. ● Clear privacy policy ● Get the consent for personal data processing ○ Personal data processing based on active consent ○ Ability to review given consent and revocation ○ Ability to demonstrate proof of consent ○ Consent design ● Purpose limitation ○ Consent per purpose Transparency, Fairness and Lawfulness
  • 25. Selfcare Portal to Manage given Consents ● Review, modify and revoke consent
  • 26. Key Privacy Considerations for CIAM Customer Controlled Personal Data Transparency, Fairness and Lawfulness Data Minimization and Storage Limitation Accuracy, Confidentiality and Accountability
  • 27. ● Personal data shall be ○ Adequate ○ Relevant and limited to purposes ● Store data no longer than necessary ● Storage limitation should be in a data retention policy ● Pseudonymized data ● Regional data localization Data Minimization and Storage Limitation
  • 28. Application Specific Claim Management Name : ishara Email : isharak@wso2.co m ID : 225 Org : WSO2 Name : ishara Mobile : 0717996791
  • 30. Key Privacy Considerations for CIAM Customer Controlled Personal Data Transparency, Fairness and Lawfulness Data Minimization and Storage Limitation Accuracy, Confidentiality and Accountability
  • 31. ● Prevent unauthorized or unlawful processing ● Prevent accidental loss, destruction or damage ● Adequate measures to prevent data breaches ○ Inform about the breaches without delay ● Organization culture of accountability Accuracy, Integrity, Confidentiality and Accountability
  • 33. Analytics, Alerts & Audit-trail
  • 34. ● Digital transformation is critical for business survival ● CIAM plays an integral part in digital transformation ● Privacy is a competitive differentiator in CIMA ● CIAM solution should address ○ Privacy by design ○ Privacy by default ● CIAM should follow future -proof privacy guidelines Conclusion