Think Your Website is GDPR Compliant? DrupalCon NASHVILLE 2018 - - PowerPoint PPT Presentation

think your website is gdpr compliant
SMART_READER_LITE
LIVE PREVIEW

Think Your Website is GDPR Compliant? DrupalCon NASHVILLE 2018 - - PowerPoint PPT Presentation

Think Your Website is GDPR Compliant? DrupalCon NASHVILLE 2018 Mediacurrent Join Us for Contribution Sprints Mentored First time General Core sprint sprinter workshop sprint #drupalsprint Mediacurrent Drupal. JavaScript. Future.


slide-1
SLIDE 1

Think Your Website is GDPR Compliant?

DrupalCon

NASHVILLE 2018

Mediacurrent

slide-2
SLIDE 2

Mediacurrent

Mentored Core sprint First time sprinter workshop General sprint

#drupalsprint

Join Us for Contribution Sprints

slide-3
SLIDE 3
  • Drupal. JavaScript. Future.
  • Keynotes. Sessions. Sprints.

A different kind of Drupal conference.

Mark your calendar and prep your proposal! More details soon.

slide-4
SLIDE 4

| 4

Today’s Team

Dawn Aly Mark Shropshire

slide-5
SLIDE 5

| 5

Disclaimers

slide-6
SLIDE 6

| 6

Today’s Agenda

I. Guiding Principles of the GDPR II. Creating a Positive PX III. Security by Design IV. Advanced Marketing Strategies in a Post GDPR World V. Creating an Action Plan (not a Freak-Out Plan)

slide-7
SLIDE 7

| 7

Guiding Principles of the GDPR

slide-8
SLIDE 8

| 8

What is GDPR?

slide-9
SLIDE 9

| 9

Who is at Risk for Compliance?

slide-10
SLIDE 10

| 10

  • Yep. Pretty much

everyone.

slide-11
SLIDE 11

| 11

The GDPR is not just an IT Discussion

43% $150 million

anticipated increase of data breach costs by 2020

89%

Believe their competitive advantage will be based on the customer experience

85%

Percentage of relationships consumers will manage without talking to a human by 2020

Sources: Gartner, Gartner, Symantec, Microsoft, Juniper Research

$3.8 million

cost of a data breach for the average company

slide-12
SLIDE 12

| 12

GDPR Roles

Legal entity or person processing the actual data on behalf of the controller GDPR required leadership position in

  • rganizations for monitoring internal

GDPR compliance Legal entity or person determining need and means for processing personal data

Data Subject

Individual whose personal data has been collected Public authority appointed in EU countries for monitoring compliance of GDPR

Supervisory Authority Controller Processor Data Protection Officer

slide-13
SLIDE 13

| 13

User Rights and Requirements Overview

slide-14
SLIDE 14

| 14

Breach Notification

slide-15
SLIDE 15

| 15

Right to Access

slide-16
SLIDE 16

| 16

Right to Erasure (Right to be Forgotten)

○ ○

slide-17
SLIDE 17

| 17

Data Portability

slide-18
SLIDE 18

| 18

Privacy by Design

slide-19
SLIDE 19

| 19

Data Protection Officers

slide-20
SLIDE 20

| 20

slide-21
SLIDE 21

| 21

Creating a Positive PX

slide-22
SLIDE 22

| 22

Data + Privacy doesn’t have to be scary.

slide-23
SLIDE 23

| 23

Universal PX Principles

slide-24
SLIDE 24

| 24

  • PII (Personally Identifiable Information)

Examples

  • Sources: https://en.wikipedia.org/wiki/Personally_identifiable_information
slide-25
SLIDE 25

| 25 PX Do’s and Don’ts

Data Collection Transparency Data Portability

Do’s Don’ts

  • Know what you collect
  • Only retain for as long as you

need

  • Protect data with encryption
  • Audit and log
  • Have clear privacy policies
  • Let users know how you use

data and why

  • Give users the right to decide

how and when data is processed and shared

  • Explain things in easy to

understand language

  • Allow users control over their

data including: ○ Exporting data ○ Deleting data ○ Seeing the details of their stored data

  • Collect any PII that you don’t

absolutely need

  • Allow anyone or system

access to data who doesn’t have legitimate reason for processing

  • Hide who you share data with

and why you share it with them

  • Force users to opt-out (opt-in

should be the pattern)

  • Create hard to read privacy

policies and other documents related to data privacy

  • Rely on blanket consents
  • Make it hard for users to

export data in a standard format that is usable for imports to other systems and services

  • Delay processing user

request for deletion, export,

  • r reporting
slide-26
SLIDE 26

| 26

Security by Design

slide-27
SLIDE 27

| 27

Secure by Design

slide-28
SLIDE 28

| 28

Privacy and Security SDLC

  • 1. PLANNING

Document and understand security controls and regulatory requirements to include in feature planning.

Software Development Life Cycle

  • 3. TESTING

Identify defects through review and testing controls guided by security and privacy requirements.

  • 4. DOCUMENTATION

Document detailed project feature implementations and processes and how they apply to security and privacy requirements.

  • 5. DEPLOYMENT

Release software to production environments after approved through agreed upon processes.

  • 6. MAINTENANCE

Consider and implement changes to controls and regulations affecting the project.

  • 2. IMPLEMENTATION

Development with security and privacy controls in mind. Privacy and Security

slide-29
SLIDE 29

| 29

Security and Privacy Principles

slide-30
SLIDE 30

| 30

One

Source: Townsend Security

slide-31
SLIDE 31

| 31

Advanced Marketing Strategies

slide-32
SLIDE 32

| 32

Trust

Sources: Inc.com, Label Insight, Harvard Business Review

94%

slide-33
SLIDE 33

| 33

Level of Trust by Industry

Source: Harvard Business Review

slide-34
SLIDE 34

| 34

Building Trust with Marketing

Trust Enablers

Empower the Individual Education Marketing High Quality Deliver Value

slide-35
SLIDE 35

| 35

Big Data May Not Be So Big

slide-36
SLIDE 36

| 36

GDPR Benefits to Data

  • Sources: Altimeter
slide-37
SLIDE 37

| 37

Marketing Automation and CRM

slide-38
SLIDE 38

| 38

Creating an Action Plan

slide-39
SLIDE 39

| 39

Enforcement begins May 25, 2018

slide-40
SLIDE 40

| 40

PX takes a team.

slide-41
SLIDE 41

| 41

  • Creating a Plan
  • Data Collection Points

Messaging and Consent User Control

slide-42
SLIDE 42

| 42

Next Steps

slide-43
SLIDE 43

| 43

PX is the new Golden Rule

slide-44
SLIDE 44

| 44

Drupal and Privacy/Security

GDPR module Guardr security distribution Encrypt module GDPR Consent module Drush sql-sanitize Privacy Concerns as GDPR Compliance [#2848974] EU Cookie Compliance GDPR Export module Commerce GDPR

slide-45
SLIDE 45

What Did You Think?

Mediacurrent

Thank you!

slide-46
SLIDE 46

Thank you!

Come See Us at Booth #525 Join Us at our Afterparty Tuesday 7-11pm @ The George Jones