Top Banner
GDPR and technology - details matter Kalle Varisvirta @kvirta
26

GDPR and technology - details matter

Jan 07, 2017

Download

Technology

Exove
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: GDPR and technology - details matter

GDPR and technology - details matterKalle Varisvirta @kvirta

Page 2: GDPR and technology - details matter

Me

Kalle Varisvirta

Technology Director

Not a lawyer

Page 3: GDPR and technology - details matter

Documentation vs.

reality

Page 4: GDPR and technology - details matter
Page 5: GDPR and technology - details matter
Page 6: GDPR and technology - details matter

Documentation vs. reality

Privacy policies (as well as PIAs) are usually written by interviewing Developers and Systems Engineers, but unfortunately by non-technical people

Technical people simplify things when asked about details by non-technical people - that’s what we’re told to do

Page 7: GDPR and technology - details matter

Cloud & SaaS services

Page 8: GDPR and technology - details matter
Page 9: GDPR and technology - details matter
Page 10: GDPR and technology - details matter
Page 11: GDPR and technology - details matter

Residual data &

removing data

Page 12: GDPR and technology - details matter

Residual data &removing data

Data leaves a trace when going through a system

Mapping your data exactly is very difficult, as is removing it

Page 13: GDPR and technology - details matter
Page 14: GDPR and technology - details matter

Varnish or CDN in the front

Web server logs

Local caches

Uploaded binary files

Backups of the servers

Page 15: GDPR and technology - details matter

MySQL logs

Binary logs on all servers

Backups of binary logs

Database dumps made by developers

Production dumps to staging environment

Page 16: GDPR and technology - details matter

Integration platform logs and local caches

Integration platform document DB oplogs

SaaS messaging platform logs and internal database

Page 17: GDPR and technology - details matter

All the SaaS services

Page 18: GDPR and technology - details matter

Finally the actual data master, its logs, backups and development environment

Page 19: GDPR and technology - details matter

Residual data

Data flows are complicated

Residual data is easily overlooked and forgotten

Removal of data becomes very problematic in the real world

Removing from backups

Page 20: GDPR and technology - details matter

Electronic format & data aggregation

Page 21: GDPR and technology - details matter

Electronic format

There are a lot of requirements for providing data in an electronic format

Most systems have the data spread out optimized for the system, not aggregation

Gathering data to a “single” electronic format would be a complicated and slow manual task for most environments

Page 22: GDPR and technology - details matter
Page 23: GDPR and technology - details matter

What to do?

Page 24: GDPR and technology - details matter

What to do?

Take the regulation seriously

Map out your systems, in full detail

Consider data flow through the system

Consider the cloud / SaaS services you might be using

Consider residual data

Page 25: GDPR and technology - details matter

What to do?

For compliance, make sure technical personnel (either internal or from your vendors) are involved

To understand the regulation, not just to provide answers

Page 26: GDPR and technology - details matter

Thanks. Questions?