Think Your Website is GDPR Compliant?
DrupalCon
NASHVILLE 2018
Mediacurrent
Think Your Website is GDPR Compliant? DrupalCon NASHVILLE 2018 - - PowerPoint PPT Presentation
Think Your Website is GDPR Compliant? DrupalCon NASHVILLE 2018 Mediacurrent Join Us for Contribution Sprints Mentored First time General Core sprint sprinter workshop sprint #drupalsprint Mediacurrent Drupal. JavaScript. Future.
DrupalCon
NASHVILLE 2018
Mediacurrent
Mediacurrent
Mentored Core sprint First time sprinter workshop General sprint
#drupalsprint
A different kind of Drupal conference.
Mark your calendar and prep your proposal! More details soon.
| 4
Dawn Aly Mark Shropshire
| 5
| 6
I. Guiding Principles of the GDPR II. Creating a Positive PX III. Security by Design IV. Advanced Marketing Strategies in a Post GDPR World V. Creating an Action Plan (not a Freak-Out Plan)
| 7
| 8
| 9
| 10
| 11
anticipated increase of data breach costs by 2020
Believe their competitive advantage will be based on the customer experience
Percentage of relationships consumers will manage without talking to a human by 2020
Sources: Gartner, Gartner, Symantec, Microsoft, Juniper Research
cost of a data breach for the average company
| 12
Legal entity or person processing the actual data on behalf of the controller GDPR required leadership position in
GDPR compliance Legal entity or person determining need and means for processing personal data
Data Subject
Individual whose personal data has been collected Public authority appointed in EU countries for monitoring compliance of GDPR
Supervisory Authority Controller Processor Data Protection Officer
| 13
| 14
| 15
| 16
○ ○
| 17
| 18
| 19
| 20
| 21
| 22
| 23
| 24
| 25 PX Do’s and Don’ts
Data Collection Transparency Data Portability
Do’s Don’ts
need
data and why
how and when data is processed and shared
understand language
data including: ○ Exporting data ○ Deleting data ○ Seeing the details of their stored data
absolutely need
access to data who doesn’t have legitimate reason for processing
and why you share it with them
should be the pattern)
policies and other documents related to data privacy
export data in a standard format that is usable for imports to other systems and services
request for deletion, export,
| 26
| 27
| 28
Document and understand security controls and regulatory requirements to include in feature planning.
Software Development Life Cycle
Identify defects through review and testing controls guided by security and privacy requirements.
Document detailed project feature implementations and processes and how they apply to security and privacy requirements.
Release software to production environments after approved through agreed upon processes.
Consider and implement changes to controls and regulations affecting the project.
Development with security and privacy controls in mind. Privacy and Security
| 29
| 30
Source: Townsend Security
| 31
| 32
Sources: Inc.com, Label Insight, Harvard Business Review
| 33
Source: Harvard Business Review
| 34
Trust Enablers
Empower the Individual Education Marketing High Quality Deliver Value
| 35
| 36
| 37
| 38
| 39
| 40
| 41
Messaging and Consent User Control
| 42
| 43
| 44
GDPR module Guardr security distribution Encrypt module GDPR Consent module Drush sql-sanitize Privacy Concerns as GDPR Compliance [#2848974] EU Cookie Compliance GDPR Export module Commerce GDPR
Mediacurrent
Come See Us at Booth #525 Join Us at our Afterparty Tuesday 7-11pm @ The George Jones