personal data processing in russia

19
Processing Personal Data in Russia: IT Technical Details

Upload: awara-group

Post on 11-Jul-2015

124 views

Category:

Documents


7 download

TRANSCRIPT

Page 1: Personal Data Processing in Russia

Processing Personal Data in Russia:IT Technical Details

Page 2: Personal Data Processing in Russia

Do you know where your data go?

Page 3: Personal Data Processing in Russia

What is a server and database?

Page 4: Personal Data Processing in Russia

Company

Page 5: Personal Data Processing in Russia

CompanySomewhere

Page 6: Personal Data Processing in Russia

What is “Russian” server and database?

Page 7: Personal Data Processing in Russia

Russia Finland

Page 8: Personal Data Processing in Russia

Russia Finland

Page 9: Personal Data Processing in Russia

Russia Finland

Page 10: Personal Data Processing in Russia

Russia Finland

Page 11: Personal Data Processing in Russia

IP Address 1

IP Address 2

Page 12: Personal Data Processing in Russia

Lab here

Page 13: Personal Data Processing in Russia

Suggested Immediate Actions

Identify the list of the data that is used in your company and is (or can be) a subject of Personal Data Processing processes,

related to recent legislation

Analyze existing IT landscape and infrastructure to locate processing sites outside Russia that mightsummon risks

Based on the results of analysis, develop strategy and action plan,

define budgets for changes if needed

Page 14: Personal Data Processing in Russia

• HR and Payroll data• IT security data (Active Directory; access

software; registration of employees)• Accounting data• Clients'/suppliers agreements and contacts• CRM data• …• Any business data is under risk

What is under risk?

Page 15: Personal Data Processing in Russia

When analyzing IT infrastructure:• Define where personal data is collected, processed and

stored in your company, who is responsible for that

• Identify how the flow of data is organized in your company;you might not even be aware how it migrates; use DLPsoftware for analysis

• Distinguish between internal IT server capacity and third-party server capacity – some part of your data can be hostedin third-party data centers

• Ensure that you understand how your backup and restorepolicy is organized and where the backups are stored

• What software do you use to collect, process and storepersonal data

Page 16: Personal Data Processing in Russia

What can you do next?

• Define that some data in reality does not relate to Personal Data Processing process

• Delete personal data from the system

• Substitute the data with just IDs and process them separately, storing the data itself inside Russian Federation

• Transfer the database without re-hosting of the application

• Transfer the whole system

• Change the system

• Terminate the process

Page 17: Personal Data Processing in Russia

Potential transfer to Russia:

• Authentication and authorization catalogues

• Catalogues synchronization systems

• Controlling systems of common access

• Portal solutions

• Mail systems• Instant messaging

Page 18: Personal Data Processing in Russia

• Remote Desktops• VPN channels• Proxy Servers• Mirror servers• …

“Hacking” tools