presentation for the lsec gdpr event - 20171130

51
Privacy (by) Design GDPR event - 30 Nov 2017 Tommy Vandepitte

Upload: tommy-vandepitte

Post on 22-Jan-2018

41 views

Category:

Education


0 download

TRANSCRIPT

Page 1: Presentation for the LSEC GDPR event - 20171130

Privacy (by) Design

GDPR event - 30 Nov 2017

Tommy Vandepitte

Page 2: Presentation for the LSEC GDPR event - 20171130

http://www.legaltechdesign.com/LegalDesignToolbox/

Page 3: Presentation for the LSEC GDPR event - 20171130

Case 1

Page 4: Presentation for the LSEC GDPR event - 20171130

Participant

Page 5: Presentation for the LSEC GDPR event - 20171130

Case 2

Page 6: Presentation for the LSEC GDPR event - 20171130

Co-organiser

Page 7: Presentation for the LSEC GDPR event - 20171130

Master of ceremony

Arthur Christmas

Page 8: Presentation for the LSEC GDPR event - 20171130

Timekeeper

Arthur Christmas

Page 9: Presentation for the LSEC GDPR event - 20171130

Experts

Arthur Christmas

Page 10: Presentation for the LSEC GDPR event - 20171130

Helpers

Arthur Christmas

Page 11: Presentation for the LSEC GDPR event - 20171130

https://sites.google.com/site/pbd20171106

Page 12: Presentation for the LSEC GDPR event - 20171130

Questions / Go onTake your pick

Page 13: Presentation for the LSEC GDPR event - 20171130

What’s in it for you? (externally)

Qualifier

Page 14: Presentation for the LSEC GDPR event - 20171130

What’s in it for you? (externally)

Differentiator

Page 15: Presentation for the LSEC GDPR event - 20171130

What’s in it for you? (externally)

Page 16: Presentation for the LSEC GDPR event - 20171130

What’s in it for you? (externally)

• Decision makers

• Future users

• CIOs

• CISOs

• DPOs

• Legal

• …

Page 17: Presentation for the LSEC GDPR event - 20171130

What’s in it for you? (externally)

Our agreeent is in line with (article 28) GPDR Our product helps you comply with

GDPR… We thought about the principles, give a

baseline, but you can tweak We thought about data subject rights, and

have implemented like this We have a dashboard for the end

customers preference, and it works like this We have audit logs, a compliance role, …

… and I have the documentation to back it up

Page 18: Presentation for the LSEC GDPR event - 20171130

What’s in it for you? (internally)

� Bring people together

� Better understanding of each others’ position

� Creates awareness

� People unknowingly learn

� Tackle big problems early, small problems later…

� Overall less rework (and thus lower cost)

Page 19: Presentation for the LSEC GDPR event - 20171130

Challenges

� It is a time investment

� First, you have to speak the same language

� DPO must stand strong in his/her shoes

� DPO must be honest

� DPO must be willing to invest in understanding the business

� DPO needs to learn to give advice in uncertainty

� Business needs to learn that first advice may need to be adjusted due to incremental insight

�…

Page 20: Presentation for the LSEC GDPR event - 20171130

The Justice League

https://www.youtube.com/watch?v=ZJVvrmLSTsg

Quis custodiet ipsos custodes?

Page 21: Presentation for the LSEC GDPR event - 20171130

Sidedeck

Page 22: Presentation for the LSEC GDPR event - 20171130

Think it through

Page 23: Presentation for the LSEC GDPR event - 20171130
Page 24: Presentation for the LSEC GDPR event - 20171130

International

Page 25: Presentation for the LSEC GDPR event - 20171130

Legal perspective

Page 26: Presentation for the LSEC GDPR event - 20171130

Legal perspective

Page 27: Presentation for the LSEC GDPR event - 20171130

In fact… it is a tale of old

Page 28: Presentation for the LSEC GDPR event - 20171130

Take different perspectives

Page 29: Presentation for the LSEC GDPR event - 20171130

Data subject centric

in mind around the table

Page 30: Presentation for the LSEC GDPR event - 20171130

Bring the bunch together

Page 31: Presentation for the LSEC GDPR event - 20171130

A challenge

Page 32: Presentation for the LSEC GDPR event - 20171130

Analysis

Page 33: Presentation for the LSEC GDPR event - 20171130

Start with why?

Page 34: Presentation for the LSEC GDPR event - 20171130

Look at the general UI

Page 35: Presentation for the LSEC GDPR event - 20171130

Overcome the human nature

Page 36: Presentation for the LSEC GDPR event - 20171130

Think like an “attacker”

…but also

Page 37: Presentation for the LSEC GDPR event - 20171130

Multiple iterations

Page 38: Presentation for the LSEC GDPR event - 20171130

Lean

Page 39: Presentation for the LSEC GDPR event - 20171130

No (full) checklist ?

“Ethics cannot be captured in checklists.”

Legislation is vague (on purpose).

Parties are not “out” on the matter yet.

No checklist can ever be “exhaustive”.

Page 40: Presentation for the LSEC GDPR event - 20171130

Academic frameworks

Page 41: Presentation for the LSEC GDPR event - 20171130

Academic frameworks

Page 42: Presentation for the LSEC GDPR event - 20171130
Page 43: Presentation for the LSEC GDPR event - 20171130

Academic frameworks

Page 44: Presentation for the LSEC GDPR event - 20171130

Where the rubber hits the road

Page 45: Presentation for the LSEC GDPR event - 20171130

Open innovation

Page 46: Presentation for the LSEC GDPR event - 20171130

Co-creation

Vodafone / Thomson Reuters

Page 47: Presentation for the LSEC GDPR event - 20171130
Page 48: Presentation for the LSEC GDPR event - 20171130
Page 49: Presentation for the LSEC GDPR event - 20171130
Page 50: Presentation for the LSEC GDPR event - 20171130

https://www.ted.com/talks/seth_godin_this_is_broken_1

Page 51: Presentation for the LSEC GDPR event - 20171130

Game design

Marlous Theunissen