SlideShare a Scribd company logo
INTELLIGENT MARKETING HUB
Privacy Engineering for Big Data
& Data Science
Brussels, October 11th 2016
European Data Innovation Hub @ AXA
@aureliepols
Data Governance & Privacy Advocate
Data is the New Oil – Privacy is the New Green – Trust is the
New Currency
AURELIE POLS,
KRUX PRIVACY ADVOCATE
• Data Governance & Privacy Advocate – Krux Digital
• Ethics Advisory Group – European Data Protection Supervisor (EDPS)
• Chief Visionary Officer – Mind Your Privacy
• Training Advisory Board – International Association of Privacy Professionals (IAPP)
• Professor of Ethics & Privacy, Big Data & Analytics Master – Instituto de Empresa (IE)
OX2 Co-founder
Webanalytics.be
@aureliepols
”My” in “my information” is not the same as “my” in “my car”
but rather the same as “my” in “my body” or “my feelings”; it
expresses a sense of constitutive belonging, not external
ownership, a sense in which my body, my feelings, and my
information are part of me but are not my (legal) possessions
- Luciano Floridi, The Ontological Interpretation of
Informational Privacy, Ethics and Information Technology,
7(4): 185-2005
@aureliepols
I’m not here to define Privacy
Analytics Privacy	(&	Data	Protection)
@aureliepols
Consider before crucifying the Rule of law
1. The specifics of data as an Economic Asset:
² Data in infinitely transferable without decay
2. Often forgotten Legislative Challenges
² Defining and recognizing Data Harms
3. Related to evolving Privacy Legislation
² Compliance is a Risk Exercise
4. Minimizing Privacy related Risks
² YOUR liability within the Data Ecosystem
@aureliepols
Privacy Engineering
VALUE / ETHICS
Corporate social
responsibility
Respect individuals
RISK
Standard operating
procedure
Do not harm
COMPLIANCE
LegislationDon’t hit people!
6
Parties Involved in Data Privacy
PEOPLE
Have People Data
GOVERNMENTS
Laws to
protect People Data
COMPANIES
Collect, use & protect
People Data
INDUSTRY
ORGANIZATIONS
Guidelines to
protect People Data
Data Quality
Ad Blocking Class Actions
ComplianceSelf-Regulation
Privacy professionals?
8
Source: IAPP-EY Annual Privacy
Governance Report 2016
https://iapp.org/media/pdf/resource_center/IAPP%202016
%20GOVERNANCE%20SURVEY-FINAL3.pdf
@aureliepols
Who owns the cookies? The jar is breaking
@aureliepols
From https://secure.edps.europa.eu/EDPSWEB/webdav/site/mySite/shared/Documents/Consultation/Opinions/2015/15-09-11_Data_Ethics_EN.pdf
@aureliepols
Erosion of human dignity through
Article 1 EU Charter of Fundamental Rights
• Discrimination => pothole app eg.
=> representativity of population?
• Loss of choices => credit scoring
=> transparency & recourse
• Loss of serendipity: tunneled vision
• Loss of life?
11
@aureliepols
Privacy Risk: it depends?
Risk Ontology
12
Experiences in the Development and Usage of a Privacy Requirements Framework by Ian Oliver,
Security Research Group, Bell Labs, Nokia
@aureliepols
Ethics of the Data Analyst
I shall remember data are not only numbers but actual people, that could be harmed by my work;
I shall treat data that might identify individuals with the utmost care, which includes respect for their dignity, avoiding
discrimination, as well as security best practices;
I will not do to personal data what I wouldn’t find acceptable for data related to my family, friends, loved ones or myself;
I understand personal data, PII &/or sensitive data is context based and often difficult to identify. In case of doubt, I
will ask for help or escalate in order to take the appropriate measures;
I understand data about individuals needs to travel with initial purpose of the data – the reason why it exists - & their
respective consent mechanisms;
a) I will never use data without knowing where it comes from, it’s purpose and consent mechanisms (see Quién es
la Última Principle);
b) I will never sell non consented data about individuals;
c) If I sell consented data, it will be accompanied by purpose. Up to the buyer to define whether subsequent data
uses are aligned.
I understand consent might be revoked and a Right to be Forgotten – i.e. deletion – could be requested, that might need
to be applied;
I shall align security protocols with how personal &/or sensitive the data is;
I will keep trace and document the data used in order to minimize risk related to data uses.
13
GOVERNANCE
V I S I T K R U X . C O M F O L L O W @ K R U X D I G I TA L
Thank you.
Aurélie Pols / apols@krux.com

More Related Content

PDF
Data Accountability & Consumer Trust
PDF
Sibos INNOTRIBE Digital Ethics
PPTX
CBC GDPR The Physics
PDF
Data & Privacy: Striking the Right Balance - Jonny Leroy
PDF
Information Privacy?! (GDPR)
PDF
Data Processing - data privacy and sensitive data
PPT
Aurélie Pols - Retargeting & Privacy: 5 Tips to stay out of (legal) trouble
PDF
2017 PlaceConf: Location & Privacy - What Marketers Must Know (Future of Priv...
Data Accountability & Consumer Trust
Sibos INNOTRIBE Digital Ethics
CBC GDPR The Physics
Data & Privacy: Striking the Right Balance - Jonny Leroy
Information Privacy?! (GDPR)
Data Processing - data privacy and sensitive data
Aurélie Pols - Retargeting & Privacy: 5 Tips to stay out of (legal) trouble
2017 PlaceConf: Location & Privacy - What Marketers Must Know (Future of Priv...

What's hot (12)

PPTX
Information Security in the Age of Wikileaks
PDF
Privacy in Bigdata Era
PPT
Lasa European NFP Technology Conference 2010 - Data protection and the cloud
PPT
Ark presentation
PDF
Why do you need an it policy it-toolkits
PPT
Privacy learning forum broadmeadows
PPTX
Developing a privacy compliance program
PPT
Training for managers and supervisors presentation
PPT
Privacy morwell june 09
PDF
Trivadis TechEvent 2016 Big Data Privacy and Security Fundamentals by Florian...
PPTX
Privacy Discusssion GM667 Saint Mary's University of MN
PPTX
Seth Earley Talks About Enterprise Information Architecture
Information Security in the Age of Wikileaks
Privacy in Bigdata Era
Lasa European NFP Technology Conference 2010 - Data protection and the cloud
Ark presentation
Why do you need an it policy it-toolkits
Privacy learning forum broadmeadows
Developing a privacy compliance program
Training for managers and supervisors presentation
Privacy morwell june 09
Trivadis TechEvent 2016 Big Data Privacy and Security Fundamentals by Florian...
Privacy Discusssion GM667 Saint Mary's University of MN
Seth Earley Talks About Enterprise Information Architecture
Ad

Viewers also liked (8)

PDF
Digitale kundeoplevelser den 29. januar - Morten Schroeder, Wilke
PDF
Mo' Metrics, Mo' Problems
PPTX
Marketing in Motion: From Unified Data to Actionable Insights
PPTX
People Data Activation: From Paradox to Paradigm
PPTX
RTB Update 2: Richard Foster, Krux
PPTX
Joe Reid, Krux: People Data Activation, from paradox to paradigm @ iMedia Dat...
PDF
"Building Trust" discussion panel at EBU Big Data conference 2017 (Pierre-Nic...
PDF
How Genentech developed its employee advocacy program | Talent Connect 2016
Digitale kundeoplevelser den 29. januar - Morten Schroeder, Wilke
Mo' Metrics, Mo' Problems
Marketing in Motion: From Unified Data to Actionable Insights
People Data Activation: From Paradox to Paradigm
RTB Update 2: Richard Foster, Krux
Joe Reid, Krux: People Data Activation, from paradox to paradigm @ iMedia Dat...
"Building Trust" discussion panel at EBU Big Data conference 2017 (Pierre-Nic...
How Genentech developed its employee advocacy program | Talent Connect 2016
Ad

Similar to Brussels data science - Privacy Engineering for Big Data & Data Science (20)

PPTX
The Meaning and Impact of the General Data Protection Regulation
PDF
The Rise of Data Ethics and Security - AIDI Webinar
PDF
Data Privacy Program – a customized solution for the new EU General Regulatio...
PDF
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
PDF
IAPP - Skills For Minimizing Privacy Risk in Data Science Product and Service...
PDF
Cyber Summit 2016: Privacy Issues in Big Data Sharing and Reuse
PDF
Hivos and Responsible Data
PDF
data-privacy-egypt-what-you-need-know-en.pdf
PPTX
Data Privacy: Protecting Information in the Digital Age
PDF
IAPP Data Protection Intensive London - Transparency in Marketing (AP part III)
PDF
data privacy handbook: A starter guide to data privacy compliance
PPTX
Challenges & Opportunities the Data Privacy Act Brings
PDF
Operationalising gdpr compliance with data management
PPT
Digital analytics & privacy: it's not the end of the world
PPT
Is Big Data killing Privacy? Nop, it's inducing a paradigm shift
PPT
Aurélie Pols en Strata Conference: Digital analytics & privacy - it’s not the...
PDF
How to Build a Privacy Program
PPTX
Helping Developers with Privacy
PPTX
e-SIDES workshop at EBDVF 2018, Vienna 14/11/2018
PDF
Privacy UX - UX Scotland 2023
The Meaning and Impact of the General Data Protection Regulation
The Rise of Data Ethics and Security - AIDI Webinar
Data Privacy Program – a customized solution for the new EU General Regulatio...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
IAPP - Skills For Minimizing Privacy Risk in Data Science Product and Service...
Cyber Summit 2016: Privacy Issues in Big Data Sharing and Reuse
Hivos and Responsible Data
data-privacy-egypt-what-you-need-know-en.pdf
Data Privacy: Protecting Information in the Digital Age
IAPP Data Protection Intensive London - Transparency in Marketing (AP part III)
data privacy handbook: A starter guide to data privacy compliance
Challenges & Opportunities the Data Privacy Act Brings
Operationalising gdpr compliance with data management
Digital analytics & privacy: it's not the end of the world
Is Big Data killing Privacy? Nop, it's inducing a paradigm shift
Aurélie Pols en Strata Conference: Digital analytics & privacy - it’s not the...
How to Build a Privacy Program
Helping Developers with Privacy
e-SIDES workshop at EBDVF 2018, Vienna 14/11/2018
Privacy UX - UX Scotland 2023

More from Aurélie Pols (20)

PDF
AI Roles and Risk for election year 2024
PDF
Preparing for the AI Act - 5 years into GDPR enforcement
PDF
Creative destruction & Privacy Whitewashing: where does risk lie?
PDF
ePrivacy Directive, a 10 steps framework to be as compliant as possible for m...
PDF
Women in STEM for IE Girl Up Club
PDF
For Superweek 2022: discussing risk using IAB's TCF
PDF
Interoperability in Digital will take a Global Village
PDF
The GDPR is here. So do you know what the courts are saying?
PDF
CPDP: Data ownership, Innovation and Privacy: looking for an approach on both...
PDF
GDPR and the aftermath: what are we building towards?
PDF
Who Goes There? Demystifying Digital Identity for All (1/2)
PDF
Data is the new infrastructure, Privacy is the new green, Trust is the new cu...
PDF
How digitization challenges our values as citizens
PDF
Technical Consequences of the Data Subject's Rights
PDF
From GDPR to ePrivacy: what does it mean to the advertising sector?
PDF
State of EU legislation: GDPR & ePrivacy for Superweek
PDF
The Great GDPR MyData Debate - Aurelie Pols - Keynote
PDF
The Data Subject First? Decoding the GDPR at StrataData
PDF
Superweek 2016 Would You Lie to Your Physician?
PDF
Multi-tasking teams within cyber security departments
AI Roles and Risk for election year 2024
Preparing for the AI Act - 5 years into GDPR enforcement
Creative destruction & Privacy Whitewashing: where does risk lie?
ePrivacy Directive, a 10 steps framework to be as compliant as possible for m...
Women in STEM for IE Girl Up Club
For Superweek 2022: discussing risk using IAB's TCF
Interoperability in Digital will take a Global Village
The GDPR is here. So do you know what the courts are saying?
CPDP: Data ownership, Innovation and Privacy: looking for an approach on both...
GDPR and the aftermath: what are we building towards?
Who Goes There? Demystifying Digital Identity for All (1/2)
Data is the new infrastructure, Privacy is the new green, Trust is the new cu...
How digitization challenges our values as citizens
Technical Consequences of the Data Subject's Rights
From GDPR to ePrivacy: what does it mean to the advertising sector?
State of EU legislation: GDPR & ePrivacy for Superweek
The Great GDPR MyData Debate - Aurelie Pols - Keynote
The Data Subject First? Decoding the GDPR at StrataData
Superweek 2016 Would You Lie to Your Physician?
Multi-tasking teams within cyber security departments

Recently uploaded (20)

PDF
Spectral efficient network and resource selection model in 5G networks
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Approach and Philosophy of On baking technology
PPTX
SOPHOS-XG Firewall Administrator PPT.pptx
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PDF
Accuracy of neural networks in brain wave diagnosis of schizophrenia
PDF
Electronic commerce courselecture one. Pdf
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PPTX
A Presentation on Artificial Intelligence
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Empathic Computing: Creating Shared Understanding
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PPTX
Spectroscopy.pptx food analysis technology
PDF
cuic standard and advanced reporting.pdf
Spectral efficient network and resource selection model in 5G networks
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Approach and Philosophy of On baking technology
SOPHOS-XG Firewall Administrator PPT.pptx
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Assigned Numbers - 2025 - Bluetooth® Document
Accuracy of neural networks in brain wave diagnosis of schizophrenia
Electronic commerce courselecture one. Pdf
Building Integrated photovoltaic BIPV_UPV.pdf
The Rise and Fall of 3GPP – Time for a Sabbatical?
20250228 LYD VKU AI Blended-Learning.pptx
A Presentation on Artificial Intelligence
“AI and Expert System Decision Support & Business Intelligence Systems”
MYSQL Presentation for SQL database connectivity
Empathic Computing: Creating Shared Understanding
Programs and apps: productivity, graphics, security and other tools
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Spectroscopy.pptx food analysis technology
cuic standard and advanced reporting.pdf

Brussels data science - Privacy Engineering for Big Data & Data Science

  • 1. INTELLIGENT MARKETING HUB Privacy Engineering for Big Data & Data Science Brussels, October 11th 2016 European Data Innovation Hub @ AXA
  • 2. @aureliepols Data Governance & Privacy Advocate Data is the New Oil – Privacy is the New Green – Trust is the New Currency AURELIE POLS, KRUX PRIVACY ADVOCATE • Data Governance & Privacy Advocate – Krux Digital • Ethics Advisory Group – European Data Protection Supervisor (EDPS) • Chief Visionary Officer – Mind Your Privacy • Training Advisory Board – International Association of Privacy Professionals (IAPP) • Professor of Ethics & Privacy, Big Data & Analytics Master – Instituto de Empresa (IE) OX2 Co-founder Webanalytics.be
  • 3. @aureliepols ”My” in “my information” is not the same as “my” in “my car” but rather the same as “my” in “my body” or “my feelings”; it expresses a sense of constitutive belonging, not external ownership, a sense in which my body, my feelings, and my information are part of me but are not my (legal) possessions - Luciano Floridi, The Ontological Interpretation of Informational Privacy, Ethics and Information Technology, 7(4): 185-2005
  • 4. @aureliepols I’m not here to define Privacy Analytics Privacy (& Data Protection)
  • 5. @aureliepols Consider before crucifying the Rule of law 1. The specifics of data as an Economic Asset: ² Data in infinitely transferable without decay 2. Often forgotten Legislative Challenges ² Defining and recognizing Data Harms 3. Related to evolving Privacy Legislation ² Compliance is a Risk Exercise 4. Minimizing Privacy related Risks ² YOUR liability within the Data Ecosystem
  • 6. @aureliepols Privacy Engineering VALUE / ETHICS Corporate social responsibility Respect individuals RISK Standard operating procedure Do not harm COMPLIANCE LegislationDon’t hit people! 6
  • 7. Parties Involved in Data Privacy PEOPLE Have People Data GOVERNMENTS Laws to protect People Data COMPANIES Collect, use & protect People Data INDUSTRY ORGANIZATIONS Guidelines to protect People Data Data Quality Ad Blocking Class Actions ComplianceSelf-Regulation
  • 8. Privacy professionals? 8 Source: IAPP-EY Annual Privacy Governance Report 2016 https://iapp.org/media/pdf/resource_center/IAPP%202016 %20GOVERNANCE%20SURVEY-FINAL3.pdf
  • 9. @aureliepols Who owns the cookies? The jar is breaking
  • 11. @aureliepols Erosion of human dignity through Article 1 EU Charter of Fundamental Rights • Discrimination => pothole app eg. => representativity of population? • Loss of choices => credit scoring => transparency & recourse • Loss of serendipity: tunneled vision • Loss of life? 11
  • 12. @aureliepols Privacy Risk: it depends? Risk Ontology 12 Experiences in the Development and Usage of a Privacy Requirements Framework by Ian Oliver, Security Research Group, Bell Labs, Nokia
  • 13. @aureliepols Ethics of the Data Analyst I shall remember data are not only numbers but actual people, that could be harmed by my work; I shall treat data that might identify individuals with the utmost care, which includes respect for their dignity, avoiding discrimination, as well as security best practices; I will not do to personal data what I wouldn’t find acceptable for data related to my family, friends, loved ones or myself; I understand personal data, PII &/or sensitive data is context based and often difficult to identify. In case of doubt, I will ask for help or escalate in order to take the appropriate measures; I understand data about individuals needs to travel with initial purpose of the data – the reason why it exists - & their respective consent mechanisms; a) I will never use data without knowing where it comes from, it’s purpose and consent mechanisms (see Quién es la Última Principle); b) I will never sell non consented data about individuals; c) If I sell consented data, it will be accompanied by purpose. Up to the buyer to define whether subsequent data uses are aligned. I understand consent might be revoked and a Right to be Forgotten – i.e. deletion – could be requested, that might need to be applied; I shall align security protocols with how personal &/or sensitive the data is; I will keep trace and document the data used in order to minimize risk related to data uses. 13 GOVERNANCE
  • 14. V I S I T K R U X . C O M F O L L O W @ K R U X D I G I TA L Thank you. Aurélie Pols / apols@krux.com