SlideShare a Scribd company logo
GDPR Readiness for Software Usage Analytics
November 7, 2017
Vic DeMarines
VP, Products & Strategy
Revulytics
Bob Siegel
President
Privacy Ref
Topics
• What is Software Usage Analytics?
• What is GDPR?
• Privacy Concepts, Personal Information Defined
• Data Controllers and Processors
• GDPR and Protecting and Improving Your Software
• How Revulytics Customers are Addressing These Issues
2
About Revulytics
Compliance Analytics
• Identify and quantify
software use and misuse
• Create actionable
intelligence
• Turn intelligence into direct
revenue
Usage Analytics
• Anonymous feature tracking
and analysis of product
usage
• Increase customer
acquisition and retention
• Generate revenue with better
products
3
• Recognized as 2017 Gartner Cool Vendor
• More than 100 customers including Fortune 500 companies
• Technology deployed to over 50M machines in more than 200 countries
• Our data has supported more than $1.8 billion in new license revenue since 2010
Software Usage Intelligence Solution Architecture
4
Cloud Service
Usage Intelligence
Reporting Dashboard
Data
Analytics
Engine
Integrated
Applications
Configured to focus
on feature adoption
ReachOut
In Application messaging
Compliance Intelligence Solution Architecture
5
Cloud Service
Compliance Dashboard
on Force.com
Integrated
Applications
Configured to
identify
organizations and
true location Gateway
Servers
Revulytics Data
Optimizer and Analysts
Revulytics Recovery
Services
What is GDPR?
• General Data Privacy Regulation
– Replaces the EU Privacy Directive (Directive 95/46/EC)
– A pan-EU law
– Becomes effective on May 25, 2018
• Five Principles
– Lawfulness, fairness, and transparency
– Purpose limitation
– Data minimization and proportionality
– Storage limitation
– Accountability
• Privacy Shield
6
Privacy Concepts, Personal Information Defined
• Data subject
• Legal basis for processing
• Data transfer
7
Personal Information…
any information related to an identified or identifiable data subject
• Privacy Policy
• Privacy Notice
Other Key Concepts
• Name
• Age/Birthdate
• Gender
• Employer
• User-id
• Email address
• User name
• Machine name
• IP Address
Revulytics
Applicable
Is IP Address Personal Information
• Court of Justice of the European Union opinion
– Breyer v Bundesrepublik Deutschland, Case C-582/14, 12 May 2016
– IP address combined with ISP records would constitute personal data in
the hands of the website provider
• Broader applicability: even if you’re not an ISP, it may be applicable
– “could keep [the IP address] indefinitely and could request at any time
from the Internet access service provider additional data to combine with
the IP address in order identify the user”
• Revulytics customer impact
– Usage Intelligence: IP address only collected for location and is then
deleted from system
– Compliance Intelligence: A key piece of information to track compliance
8
Data Controllers and Processors
9
Data Protection Authority / Supervisory Authority
Data Subject
Data
Controller
Data
Processor
End-user
Your
Company
Revulytics
GDPR and Protecting and Improving Your Software
Lawfulness, fairness, and transparency
• Lawfully processing information
– Consent (Article 7)
– Legitimate interest of the controller or a third party
(Article 6)
• Fairness and transparency
– Include legal basis in your privacy notice
– State that it will be shared with a third party
(Revulytics)
– State that processing may occur in the United States
10
GDPR and Protecting and Improving Your Software
Other principles
• Purpose limitation
• Data minimization and proportionality
• Storage limitation
• Accountability
11
GDPR and Protecting and Improving Your Software
Best practices and Revulytics products
• Revulytics Compliance Intelligence
– Use legitimate interests as a legal basis
• Consent not required
– Be transparent in your privacy notice
– Define a reasonable retention period with Compliance Intelligence
12
GDPR and Protecting and Improving Your Software
Best practices and Revulytics products
• Revulytics Usage Intelligence
– Legitimate interests as a legal basis is an option
• Consent not required: use of data to improve products
– However, sensitivity of the environment may guide you towards consent
• Example: Microsoft and Windows 10
• Consent requirements
• Separate screen (not buried in a EULA)
• Mechanism to change preference (opt-in or opt-out) at a later time
– Collecting additional information
• Avoid or limit collecting personal information
• Usage Intelligence does not retain personal information by default
– Be transparent in your privacy notice
– Define a reasonable retention period with Usage Intelligence if collecting
personal information
13
GDPR and Protecting and Improving Your Software
Best practices and Revulytics products
• ReachOut functionality
– You may send messages and surveys to the end-users
• You have an existing business relationship
• Contents must be related to the software being used
– An opt-out mechanism must be supplied and respected
• Allow end users to opt-in at a later time as well
14
GDPR and Protecting and Improving Your Software
Best practices for your privacy notice
• Privacy notice requirements will vary based on
your software
• Be transparent about the information being
collected
• Link to the privacy notice where end users will
expect to find it
15
How Revulytics Customers Address These Issues
Data Needed for Compliance
16
Consumer piracy
Lower product ASP
Piracy Response
In-Application Messaging
Direct Compliance
Audit
Specialize software
Enterprise organizations
Higher product ASP
SMB
Compliance Approach
Data Collection Meter
How Revulytics Customers Address These Issues
• Wi-Fi SSID adds to the Domain Data and provides location intelligence
17
Best Practices
• Compliance Intelligence
– Transparency and Privacy Policy key
• Include extent of data collected, include description of data being collected
• Note sharing of data with third party for your compliance program
• 100% focused on compliance
– Have a FAQ or whitepaper available that positions the deployment
• Usage Intelligence
– Implement opt-out functionality within the application, available to the user post-
installation
– Product related in-application messaging
– Consider custom data being collected
• Best practices - not a legal opinion
– Include your usage and compliance data collection in your own GDPR
assessment
– Revulytics assessing its business and platform for GDPR compliance
18
Conclusion
• To view the full webinar recording and slides, check
out the link in the comments.
• Also , read the white paper, “Privacy, Piracy, and
Product Usage GDPR Readiness for Software
Usage Analytics”
19
Vic DeMarines
VP, Products & Strategy
Revulytics
vdemarines@revulytics.com
Bob Siegel
President
Privacy Ref
bob.siegel@privacyref.com

More Related Content

PPTX
General Data Protection Regulation (GDPR)
PDF
Addressing analytics, data warehouse and Big Data challenges beyond database ...
PDF
Teleran Data Protection - Addressing 5 Critical GDPR Requirements
PPTX
Privacy and Money Laundering Prof. Hernan Huwyler CPA MBA
PPTX
CCPA Compliance for Analytics and Data Science Use Cases with Databricks and ...
PDF
Privacera Databricks CCPA Webinar Feb 2020
PPTX
How to turn GDPR into a Strategic Advantage using Connected Data
DOCX
Migration approachquestionnaire checklist
General Data Protection Regulation (GDPR)
Addressing analytics, data warehouse and Big Data challenges beyond database ...
Teleran Data Protection - Addressing 5 Critical GDPR Requirements
Privacy and Money Laundering Prof. Hernan Huwyler CPA MBA
CCPA Compliance for Analytics and Data Science Use Cases with Databricks and ...
Privacera Databricks CCPA Webinar Feb 2020
How to turn GDPR into a Strategic Advantage using Connected Data
Migration approachquestionnaire checklist

What's hot (18)

PPTX
GDPR: The Regulator's Perspective, Peter Brown, ICO
PPTX
The GDPR timeline - Stephen Bailey, NCC Group
PPTX
A Brief Overview on GDPR
PDF
Data security and privacy
PPTX
EU's General Data Protection Regulation (GDPR)
PDF
GDPR Data Subject Rights - What You Need to Know
PDF
Finding Data at Risk for CCPA Compliance
PDF
Preparing for GDPR Compliance...
PPTX
Data Protection Officer Dashboard | GDPR
PPT
Effective data protection for businesses with multiple locations
PDF
7 Key GDPR Requirements & the Role of Data Governance
PDF
Understanding gdpr compliance gdpr analytics tools
PDF
HealthCare Compliance - HIPAA & HITRUST
PDF
GDPR Jennifer Rose
PDF
How to Collect and Process Data Under GDPR?
PPTX
Data protection and privacy in the world of database DevOps
PPTX
Seeley "Necessary Protections of Privacy"
PDF
A practical guide to GDPR preparation
GDPR: The Regulator's Perspective, Peter Brown, ICO
The GDPR timeline - Stephen Bailey, NCC Group
A Brief Overview on GDPR
Data security and privacy
EU's General Data Protection Regulation (GDPR)
GDPR Data Subject Rights - What You Need to Know
Finding Data at Risk for CCPA Compliance
Preparing for GDPR Compliance...
Data Protection Officer Dashboard | GDPR
Effective data protection for businesses with multiple locations
7 Key GDPR Requirements & the Role of Data Governance
Understanding gdpr compliance gdpr analytics tools
HealthCare Compliance - HIPAA & HITRUST
GDPR Jennifer Rose
How to Collect and Process Data Under GDPR?
Data protection and privacy in the world of database DevOps
Seeley "Necessary Protections of Privacy"
A practical guide to GDPR preparation
Ad

Similar to GDPR Readiness for Software Usage Analytics (20)

PPTX
Using GDPR to Transform Customer Experience
PDF
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
PDF
Whos role is it anyway
PDF
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdpr
PDF
Toreon adding privacy by design in secure application development oss18 v20...
PDF
GDPR- The Buck Stops Here
PDF
Michael Josephs
PPTX
How Cloudera SDX can aid GDPR compliance
PPTX
Iron Mountain® Policy Center Solution Enterprise Edition
PDF
TrustArc Webinar - Cookie and Trackers: Understanding the Technology and Regu...
PPTX
General Data Protection Regulation (GDPR) Implications for Canadian Firms
PDF
Countdown to CCPA: 48 Days Until Your IBM i Data Needs to Be Secured
PPTX
Privacy Policies: Guide to Protecting User Data
PDF
GDPR Noncompliance: Avoid the Risk with Data Virtualization
PPTX
Hadoop: Making it work for the Business Unit
PPTX
General Data Protection Regulation (GDPR) Compliance
PPTX
Why We Require GDPR?
PPTX
Prepare Your Firm for GDPR
PPTX
Vuzion Love Cloud GDPR Event
PDF
Partner enablement GDPR
Using GDPR to Transform Customer Experience
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
Whos role is it anyway
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdpr
Toreon adding privacy by design in secure application development oss18 v20...
GDPR- The Buck Stops Here
Michael Josephs
How Cloudera SDX can aid GDPR compliance
Iron Mountain® Policy Center Solution Enterprise Edition
TrustArc Webinar - Cookie and Trackers: Understanding the Technology and Regu...
General Data Protection Regulation (GDPR) Implications for Canadian Firms
Countdown to CCPA: 48 Days Until Your IBM i Data Needs to Be Secured
Privacy Policies: Guide to Protecting User Data
GDPR Noncompliance: Avoid the Risk with Data Virtualization
Hadoop: Making it work for the Business Unit
General Data Protection Regulation (GDPR) Compliance
Why We Require GDPR?
Prepare Your Firm for GDPR
Vuzion Love Cloud GDPR Event
Partner enablement GDPR
Ad

Recently uploaded (20)

PDF
Navsoft: AI-Powered Business Solutions & Custom Software Development
PPTX
Introduction to Artificial Intelligence
PDF
T3DD25 TYPO3 Content Blocks - Deep Dive by André Kraus
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
PDF
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
PDF
2025 Textile ERP Trends: SAP, Odoo & Oracle
PPTX
Embracing Complexity in Serverless! GOTO Serverless Bengaluru
PPTX
L1 - Introduction to python Backend.pptx
PDF
Wondershare Filmora 15 Crack With Activation Key [2025
PDF
Design an Analysis of Algorithms II-SECS-1021-03
PDF
Why TechBuilder is the Future of Pickup and Delivery App Development (1).pdf
PDF
Odoo Companies in India – Driving Business Transformation.pdf
PDF
Adobe Premiere Pro 2025 (v24.5.0.057) Crack free
PPTX
Operating system designcfffgfgggggggvggggggggg
PDF
top salesforce developer skills in 2025.pdf
PDF
Understanding Forklifts - TECH EHS Solution
PDF
Design an Analysis of Algorithms I-SECS-1021-03
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 41
PDF
EN-Survey-Report-SAP-LeanIX-EA-Insights-2025.pdf
PDF
System and Network Administraation Chapter 3
Navsoft: AI-Powered Business Solutions & Custom Software Development
Introduction to Artificial Intelligence
T3DD25 TYPO3 Content Blocks - Deep Dive by André Kraus
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
2025 Textile ERP Trends: SAP, Odoo & Oracle
Embracing Complexity in Serverless! GOTO Serverless Bengaluru
L1 - Introduction to python Backend.pptx
Wondershare Filmora 15 Crack With Activation Key [2025
Design an Analysis of Algorithms II-SECS-1021-03
Why TechBuilder is the Future of Pickup and Delivery App Development (1).pdf
Odoo Companies in India – Driving Business Transformation.pdf
Adobe Premiere Pro 2025 (v24.5.0.057) Crack free
Operating system designcfffgfgggggggvggggggggg
top salesforce developer skills in 2025.pdf
Understanding Forklifts - TECH EHS Solution
Design an Analysis of Algorithms I-SECS-1021-03
Internet Downloader Manager (IDM) Crack 6.42 Build 41
EN-Survey-Report-SAP-LeanIX-EA-Insights-2025.pdf
System and Network Administraation Chapter 3

GDPR Readiness for Software Usage Analytics

  • 1. GDPR Readiness for Software Usage Analytics November 7, 2017 Vic DeMarines VP, Products & Strategy Revulytics Bob Siegel President Privacy Ref
  • 2. Topics • What is Software Usage Analytics? • What is GDPR? • Privacy Concepts, Personal Information Defined • Data Controllers and Processors • GDPR and Protecting and Improving Your Software • How Revulytics Customers are Addressing These Issues 2
  • 3. About Revulytics Compliance Analytics • Identify and quantify software use and misuse • Create actionable intelligence • Turn intelligence into direct revenue Usage Analytics • Anonymous feature tracking and analysis of product usage • Increase customer acquisition and retention • Generate revenue with better products 3 • Recognized as 2017 Gartner Cool Vendor • More than 100 customers including Fortune 500 companies • Technology deployed to over 50M machines in more than 200 countries • Our data has supported more than $1.8 billion in new license revenue since 2010
  • 4. Software Usage Intelligence Solution Architecture 4 Cloud Service Usage Intelligence Reporting Dashboard Data Analytics Engine Integrated Applications Configured to focus on feature adoption ReachOut In Application messaging
  • 5. Compliance Intelligence Solution Architecture 5 Cloud Service Compliance Dashboard on Force.com Integrated Applications Configured to identify organizations and true location Gateway Servers Revulytics Data Optimizer and Analysts Revulytics Recovery Services
  • 6. What is GDPR? • General Data Privacy Regulation – Replaces the EU Privacy Directive (Directive 95/46/EC) – A pan-EU law – Becomes effective on May 25, 2018 • Five Principles – Lawfulness, fairness, and transparency – Purpose limitation – Data minimization and proportionality – Storage limitation – Accountability • Privacy Shield 6
  • 7. Privacy Concepts, Personal Information Defined • Data subject • Legal basis for processing • Data transfer 7 Personal Information… any information related to an identified or identifiable data subject • Privacy Policy • Privacy Notice Other Key Concepts • Name • Age/Birthdate • Gender • Employer • User-id • Email address • User name • Machine name • IP Address Revulytics Applicable
  • 8. Is IP Address Personal Information • Court of Justice of the European Union opinion – Breyer v Bundesrepublik Deutschland, Case C-582/14, 12 May 2016 – IP address combined with ISP records would constitute personal data in the hands of the website provider • Broader applicability: even if you’re not an ISP, it may be applicable – “could keep [the IP address] indefinitely and could request at any time from the Internet access service provider additional data to combine with the IP address in order identify the user” • Revulytics customer impact – Usage Intelligence: IP address only collected for location and is then deleted from system – Compliance Intelligence: A key piece of information to track compliance 8
  • 9. Data Controllers and Processors 9 Data Protection Authority / Supervisory Authority Data Subject Data Controller Data Processor End-user Your Company Revulytics
  • 10. GDPR and Protecting and Improving Your Software Lawfulness, fairness, and transparency • Lawfully processing information – Consent (Article 7) – Legitimate interest of the controller or a third party (Article 6) • Fairness and transparency – Include legal basis in your privacy notice – State that it will be shared with a third party (Revulytics) – State that processing may occur in the United States 10
  • 11. GDPR and Protecting and Improving Your Software Other principles • Purpose limitation • Data minimization and proportionality • Storage limitation • Accountability 11
  • 12. GDPR and Protecting and Improving Your Software Best practices and Revulytics products • Revulytics Compliance Intelligence – Use legitimate interests as a legal basis • Consent not required – Be transparent in your privacy notice – Define a reasonable retention period with Compliance Intelligence 12
  • 13. GDPR and Protecting and Improving Your Software Best practices and Revulytics products • Revulytics Usage Intelligence – Legitimate interests as a legal basis is an option • Consent not required: use of data to improve products – However, sensitivity of the environment may guide you towards consent • Example: Microsoft and Windows 10 • Consent requirements • Separate screen (not buried in a EULA) • Mechanism to change preference (opt-in or opt-out) at a later time – Collecting additional information • Avoid or limit collecting personal information • Usage Intelligence does not retain personal information by default – Be transparent in your privacy notice – Define a reasonable retention period with Usage Intelligence if collecting personal information 13
  • 14. GDPR and Protecting and Improving Your Software Best practices and Revulytics products • ReachOut functionality – You may send messages and surveys to the end-users • You have an existing business relationship • Contents must be related to the software being used – An opt-out mechanism must be supplied and respected • Allow end users to opt-in at a later time as well 14
  • 15. GDPR and Protecting and Improving Your Software Best practices for your privacy notice • Privacy notice requirements will vary based on your software • Be transparent about the information being collected • Link to the privacy notice where end users will expect to find it 15
  • 16. How Revulytics Customers Address These Issues Data Needed for Compliance 16 Consumer piracy Lower product ASP Piracy Response In-Application Messaging Direct Compliance Audit Specialize software Enterprise organizations Higher product ASP SMB Compliance Approach Data Collection Meter
  • 17. How Revulytics Customers Address These Issues • Wi-Fi SSID adds to the Domain Data and provides location intelligence 17
  • 18. Best Practices • Compliance Intelligence – Transparency and Privacy Policy key • Include extent of data collected, include description of data being collected • Note sharing of data with third party for your compliance program • 100% focused on compliance – Have a FAQ or whitepaper available that positions the deployment • Usage Intelligence – Implement opt-out functionality within the application, available to the user post- installation – Product related in-application messaging – Consider custom data being collected • Best practices - not a legal opinion – Include your usage and compliance data collection in your own GDPR assessment – Revulytics assessing its business and platform for GDPR compliance 18
  • 19. Conclusion • To view the full webinar recording and slides, check out the link in the comments. • Also , read the white paper, “Privacy, Piracy, and Product Usage GDPR Readiness for Software Usage Analytics” 19 Vic DeMarines VP, Products & Strategy Revulytics vdemarines@revulytics.com Bob Siegel President Privacy Ref bob.siegel@privacyref.com