“Can you recommend a GDPR expert? Yes! Great, can you give me their email address so I can contact them? No.” https://twitter.com/wardrox/status/988363811479572483
@xeraa
General Data Protection Regulation Adopted 2016/04/14 Enforceable 2018/05/25 @xeraa
Slide 9
DatenschutzGrundverordnung Fines up to 4% of global revenues or €20m
@xeraa
Slide 10
Where & Who? EU organizations Services or goods for / monitoring of EU citizens @xeraa
Slide 11
What? Personal Data Any information relating to an identified or identifiable natural person @xeraa
Slide 12
Rights? to be informed access rectification @xeraa
Slide 13
Rights? erasure (to be forgotten) restrict processing data portability @xeraa
Slide 14
Rights? object automatic decision making
@xeraa
Slide 15
PS: Personal data in a blockchain is an issue @xeraa
Slide 16
Lawful use of data? Informed consent Contractual obligation Legitimate interest @xeraa
Slide 17
Lawful use of data? Legal obligation Vital interests Public task @xeraa
Slide 18
Proof Required Right to collect and legally use
@xeraa
Slide 19
Disclosure Within 72 hours to a member state’s "supervisory body" @xeraa
Slide 20
Legacy Data Stop, Check, Delete @xeraa
Slide 21
Slide 22
What if no legal grounds?
@xeraa
Slide 23
“More GDPR bizarro world logic. Log nothing, but also make sure to have a complete understanding of all your security breaches, track them down, patch them up…. with no logs.” https://twitter.com/ianlandsman/status/997561351009599488 @xeraa
Anonymous No information that could potentially identify an individual Not considered Personal Data by GDPR @xeraa
Slide 35
Pseudonymous Re-identification possible if combined with additional information Without this information, reidentification practically impossible @xeraa
“You might think it would take a long time to run through all of the possible SSNs, but computers are very fast — there are "only" one billion possible SSNs, so your laptop can hash all of them in less time than it takes you to get a cup of coffee.” https://www.ftc.gov/news-events/blogs/techftc/2012/04/does-hashing-make-dataanonymous @xeraa
Slide 45
“Datafinder – Reverse email hashes for $0.04 per email” https://freedom-to-tinker.com/2018/04/09/fourcents-to-deanonymize-companies-reverse-hashedemail-addresses/ @xeraa
Slide 46
Slide 47
Access Control & Encryption
@xeraa
Slide 48
Slide 49
Deletion
@xeraa
Slide 50
“Interesting #GDPR solution for the "right to erasure" : Encrypt all user's data and when you have to delete it you just get rid of the private key. Will this become the norm?” https://twitter.com/Stephan007/status/985103374118014976
@xeraa
Slide 51
“[...] personal data of our users can only be persisted when it is encrypted. Each user has their own set of keys [...] it reduces the impact of leaking a dataset, since the dataset by itself is useless — attackers also need the decryption keys. [...] it allows us to control the lifecycle of data for individual users centrally.” https://labs.spotify.com/2018/09/18/scalable-user-privacy/ @xeraa
Slide 52
Conclusion @xeraa
Slide 53
Data Protection The new standard and norm of approaching personal data @xeraa