SlideShare a Scribd company logo
Dataworks Berlin
GDPR : The IBM Journey to Compliance
—
Richard Hogg, Global GDPR Evangelist
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
Richard Hogg
Global GDPR Evangelist
IBM
@banjaxx
G-
36
DaysDataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
GDPR Legal
Disclaimer
Clients are responsible for ensuring their own compliance with
various laws and regulations, including the European Union
General Data Protection Regulation. Clients are solely
responsible for obtaining advice of competent legal counsel as
to the identification and interpretation of any relevant laws and
regulations that may affect the clients’ business and any
actions the clients may need to take to comply with such laws
and regulations. The products, services, and other capabilities
described herein are not suitable for all client situations and
may have restricted availability. IBM does not provide legal,
accounting or auditing advice or represent or warrant that its
services or products will ensure that clients are in compliance
with any law or regulation.
Learn more about IBM's own GDPR readiness journey and our
GDPR capabilities and offerings to support your compliance
journey here.
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
Simply…
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
GDPR
Compliance Data
Protection
Personal
Data
The EU General Data Protection Regulation
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
GDPR
From
May 25th,
2018
Across 28 EU countries
4%
of Global Revenue or
€20M
Potential Penalty
Per-Incident
Applies
Globally
to any Organization working with
Personal Data of a Data Subject
residing in the EU
Or Profiling From the EU
5 Key General Data Protection Regulation Obligations
Rights of EU
Data Subjects
Security of
Personal Data
Compliance
& Legal Basis
Accountability of
Compliance
Data Protection by
Design and by Default
Exemplar Types
of Personal Data
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
Personal Data:
an identifier such as a name, an identification number,
location data, online identifier or to one or more factors
specific to the physical, physiological, genetic, mental,
economic, cultural or social identity of that person.
Sensitive Personal Data:
data consisting of racial or ethnic origin, political
opinions, religious or philosophical beliefs, or trade union
membership, genetic data, biometric data, data
concerning health or data concerning a natural person's
sex life or sexual orientation. The commission or alleged
commission by them of any offence; or any proceedings
for any offence committed or alleged to have been
committed by them, the disposal of such proceedings or
the sentence of any court in such proceedings.
5 Phases to Readiness
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
GDPR Framework
– Conduct GDPR risk &
privacy assessments
across governance,
people, processes, data,
security
– Develop GDPR
Readiness Roadmap
– Identify & Map personal
data
– Design governance,
training, communication,
and process standards
– Design privacy, data
management and
security management
standards
– Develop and embed
procedures, processes
and tools
– Deliver GDPR training
– Develop & embed
standards & policies
using Privacy by Design,
Security by Design
– Detailed Data Discovery
– Execute all relevant
business processes
– Monitor security and
privacy using TOMs
– Manage Consent & data
subject access rights
Identify GDPR impact and
plan Technical and
Organizational Measures
(TOM’s)
Includes Data Protection
controls, processes and
solutions to be implemented
TOMs in place: Personal
Data discovery, classification
and governance in place
Begin the new GDPR ready
way of working
– Monitor, assess, audit,
report and evaluate
adherence to GDPR
standards
Assess Design Transform ConformOperate
Monitor TOMs execution;
deliver compliance evidence
to internal and external
stakeholders
Assessments and
roadmap
Defined
implementation plan
Process enhancements
completed
Operational
framework in place
Ongoing
monitoring and
reporting
ActivityOutcomePhase
What Is IBM Doing for
GDPR Readiness?
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
Our Market Commitment
IBM has established a global project to prepare for GDPR, both for our internal
processes and for our commercial offerings. IBM recognises that our customers will
rely on IBM's offerings and technical assistance to achieve GDPR compliance within
their own organisations and IBM is well-positioned to meet this critical need.
Our GDPR Readiness Programme
GDPR Programme Management Office
IBM as a Data
Controller
Mission:
Address IBM’s
obligations for
managing
internal data.
IBM as a Data
Processor
Mission:
Ensure
compliance and
governance for
all IBM
offerings and
services that
process
personal data.
IBM GDPR
Common
Services
Mission:
Deploy
enterprise tools
and common
services to
facilitate
GDPR-related
policy, system
and business
process
changes.
IBM Vendor
Management
Mission:
Align our supply
chain to the
upstream
obligations we
make to our
clients and to
our internal
responsibilities.
IBM Client &
Contract
Management
Mission:
Help make the
client buying
process GDPR
ready.
GDPR Go-To-
Market
Mission:
Create a unified
solution to help
our clients with
their GDPR
readiness
programmes.
IBM has established a global readiness programme
tasked with identifying the key impacts of the GDPR
across IBM’s business and preparing IBM’s internal
processes and commercial offerings for compliance
with the GDPR.
The programme is organised into several work
streams, staffed with IBM’s top data privacy and
security professionals. Focal points in each Business
Unit are responsible for implementing the GDPR-
related policy, system and business process changes
mandated by the various key work streams.
www.ibm.com/gdpr
+ new Audit
Workstream
Northern Trust Accelerated
GDPR Readiness
—
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
“The journey we took to know, trust, use our data is now
accelerating our readiness to GDPR.
• Data cataloging efforts to map sensitive data elements
across key applications improved company operations and
accelerated our path to be GDPR ready
• GDPR is now helping us to advance our metadata for other purposes
such as data protection
• With good quality data with embedded governance controls,
my group is providing better service to my constituents so
Northern Trust can better serve its customers.”
Sanjay Saxena
Senior Vice President of Enterprise Data Governance at Northern Trust
Use your data
Build a single source of truth to drive a 360-degree
view of your data. Unleash insights and deepen
customer relationships.
Trust your data
Capture lineage, help ensure quality of dynamic
data and stay on top of regulations.
Know your data
Discover, find, integrate, classify and catalog all
types of data.
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
Driving Consumer Engagement,
Innovation and Competitive Advantage
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
GDPR
66%of users feel more
empowered to share
data once it has
strong governance
enablement*
Respect and treat personal data properly
Build personalized experience
Help Compliance readiness
Build brand value & loyalty
Source: Lock, Michael. “Data Governance 2.0:
Uniting People and Information to Drive Real
Business Results, Aberdeen Group, 31 August
2017, https://www-01.ibm.com/common/ssi/cgi-
bin/ssialias?htmlfid=IML14586USEN&
Driving Value Beyond GDPR
Compliance
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
The Value of Governance
Making data cleaner and more trustworthy
contributes to a technology environment that is
easier to interact with, protecting data, and guiding
users toward the data they need to support their
decisions.
Find-Share-Collaborate
− Break down data silos
− Make structured and unstructured data available
through a self-service model
− Turn complex business data into business value
− Be proacitve in the face of changing regulatory
environment
Data Governance 2.0
“Uniting people and information to drive real
business Results”
(Aberdeen group Study – August 2017)
Opportunities the GDPR
Presents to All
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
Reinforcing
accountability with
your customers
Digital
engagement and
personalisation
Improved data
management and
understanding
1 2 3
Build once. Address many needs. Accelerate innovation.
ArchivingRecords and
retention
Audit readinessSelf-service access to
data and analytics
Discovery360-degree
information driven
insights
Regulations
(such as GDPR)
Privacy and protection
EDW optimization
Trusted Analytics Foundation
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
AI & ML GDPR Accelerators
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
Compare and Comply
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
Watson Compare & Comply allows attorneys to load
contracts and other data such as regulations from any
source and have Watson analyze and consider the key
language, clauses or paragraphs driving the need for
further analysis or change
Watson considers the contractual terms, regulations or
other terms and highlights paragraphs / sentences that
contain control requirements (implicit/explicit). Users
confirm the validity.
Visualize how effectively controls have been assessed
per regulation
GDPR Outcome
Creates a range of bespoke reporting to allow a clear
view of where remediation is required, with clear
traceability back to impacting new regulations, existing
regulations or contractual terms. A clear link back to
impacting regulation or de-regulation can be seen to
support prioritization and discussions with the regulator
Accelerate Taxonomy and
Personal Data Mapping via
Industry Model
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
Business Taxonomy for Industries mapping each GDPR
Terms to business terms & objects, by Article
− Consumable for Unified Governance Catalog
execution by using IGC
Helps pre-define common classes and types of Personal
data to find and manage under GDPR
− Helps define and accelerate determining which
personal data types your business uses
− Helps define the examples and methods of finding and
managing such personal data
GDPR Outcome
An immediate re-usable taxonomy and framework of
business terms, for what personal data is used in the
business, towards a complete Mapping and inventory to a
defensible ‘Article 30 Record of Processing of Personal
data’ across the business.
Marked up GDPR Regulation Supportive Content of all GDPR
nouns in IGC
Each relevant noun
in the text points to
equivalent IGC
Term
Industry agnostic representation of GDPR regulation
Governance Value
Beyond GDPR
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
Brand Value & Loyalty
Strengthen your brand by defining and publishing ethical
standards handling personal data both internal (employees)
as external (clients)—a quality necessity for the digital age!
Grow revenue, reduce churn and acquisition costs.
Become ‘data driven’—Personalized
Establish key projects like implementing Data Governance
or creating a 360 Client View to transform your organization
to be data driven as part of your GDPR implementation.
Better customer insight and targeted marketing.
Compliance Readiness and Business Productivity
Established best practices for stewardship and efficiency of
data projects and for confidence in handling future
regulation.
Show respect & trust for Personal Data
Derive guidelines for handling personal data and raise the
awareness as part of your organization’s values
Records of
processing
activity
Consent
Building Block Journey
Governance and
lifecycle
management
Assessment
Access by the
data subject
Discovery and
mapping
Discovery and Mapping (Art. 4-5)
IS EE (IA, IGC), StoredIQ w/Cartridges, Industry Models
w/GDPR content
Records of Processing Activities (Art. 30)
GDPR Template w/IS EE, StoredIQ, Cognos 11
Manage Consent (Art. 4-7)
MDM w/ Consent Mgmt & Profiles
Governance and Lifecycle Management (Art. 5)
IS EE (IGC), Optim TDM & DP / TD Fabrication / Archive,
Atlas, StoredIQ for Legal
Data Subject Access (Art. 15)
IGC, MDM, Atlas, StoredIQ, Optim, Case Manager
Analytics GDPR Building
Blocks
Records of
processing
activity
Consent
Building Block Journey
Governance and
lifecycle
management
Assessment
Access by the
data subject
Discovery and
mapping
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
Discovery and Mapping
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
Know your relevant data: Understand where
personal data resides
Define your inventory of Personal Data
Discover where Personal Data is stored
Reveal ‘shadow’ data stores
Process structured and unstructured data and
store results in a common catalog
Leverage GDPR specific content in Industry
Models and GDPR Cartridges for StoredIQ
(RegEx & ML)
1. Articles 4-5
Information Analyzer
for Structured Data
StoredIQ
for Unstructured Data
Industry Models for Business Vocabulary Conformance
Information Governance Catalog
Extensive Personal Data
Discovery with GDPR
Cartridges
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
Plug-in discovery accelerators to find a more extensive set of
EU citizen personal data
− Maximising the use of RegEx strings
− Leveraging Machine Learning Annotators to auto-discover
personal data entities such as Names, Addresses,
Countries that can’t be defined or found by RegEx
− Tailorable & extensible by clients
Proven enterprise-scale capability to assess in-place the
common sources and types of unstructured information
− Heatmap view to prioritise Where Personal information has
been found
− Actionable outcomes and exports of specific data types
and files for remediation & mapping
GDPR Outcome
Rapidly discover the most common Personal data in all the
usual places, avoiding internal time and resources trying to
define and manage these rules; Ensuring IT can help other
stakeholders reduce Risk and Cost of Discovery.
What Is Data
Mapping?
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
GDPR ARTICLE 30
Records of Processing
Activities
Article 30 of Regulation (EU) 2016/679
controller
processor
written
sme
regulator
who
why
what
where
when
way
who
why
where
way
Records of Processing
Activities
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
It enables companies to address the
requirements of the GDPR defined in Art.
30 through appropriate tooling and a set of
artefacts provided through our GDPR
Template.
Art. 30 GDPR:
Records of processing activities
Each controller and, where applicable, the
controller’s representative, shall maintain a
record of processing activities under its
responsibility.
2. Article 30
Data Subject Access
Requests
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
Enterprise scale consistent auditable
processing for all DSAR requests, levering a
single catalog, policy and processing criteria for
each data subject
Streamline the DSAR decision and template
repeatable but personalized responses within
30 days back to the data subject
Provide auditable tracking, management and
execution of all types of DSAR’s for Art. 15
3. Article 15
Governance and Lifecycle
Management
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
Mask personal identifiable information with
realistic but fictional data, de-identify
sensitive information; mask complete
business objects across heterogeneous
databases & applications; when needed,
generate synthetic test data
Govern the lifecycle of data with archival,
records management, and defensible
disposal
Drive to Data Minimisation under GDPR
4. Article 5
JASON MICHAELS ROBERT SMITH
DBA View
Referentially-intact
subsets of data across
related tables &
applications, including
metadata.
Business View
Overall historical
“snapshot” of business
activity, representing an
application data record
– e.g. payment, invoice,
customer
Manage Consent
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
A Consent Service providing a framework for
obtaining, maintaining and applying where
specific consent is required, for some GDPR
data processing, away from the current blanket
single consent commonly imposed
Supports any categories of Consent or Sharing
preferences for data subjects, flexible and
changeable by them at any time.
Each Consent is more granular, specific for
each Purpose and clearly conveys What data is
related to that consented purpose.
Where required, explicit transparent Purposeful
Consent of any personal data processing is
available for data subjects and processors to
know and understand how it can be and is used.
5. Articles 4-7
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
Consent Management
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
What’s New for GDPR?
RegulatoryML Lab Concept
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
What’s New for GDPR?
Blockchain Whitepaper
ibm.biz/blockchain-gdpr
Using real-world examples,
this paper explores how
blockchain could address five
areas associated with GDPR
compliance
Rights of EU Data Subjects, Security of Processing,
Lawfulness and Consent, Accountability of
Compliance, and Data Protection by Design and by
Default.
In this paper, for each of the areas, we provide a
point of view on how blockchain applies, we describe
project examples, and we explore challenges and
opportunities.
Thank you
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
Richard Hogg
Global GDPR Evangelist
—
rghogg@us.ibm.com
+1-703-963-2900
ibm.com
@banjaxx
Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation

More Related Content

PPTX
Adapting to the exponential development of technology
PPTX
Risk listening: monitoring for profitable growth
PDF
Practical experiences using Atlas and Ranger to implement GDPR
PDF
Data Driven Development of Autonomous Driving at BMW
PDF
Climbing the AI Ladder
PPTX
How data modelling helps serve billions of queries in millisecond latency wit...
PPTX
Data Offload for the Chief Data Officer – how to move data onto Hadoop withou...
PDF
Postgres Vision 2018: Data as the New Oil
 
Adapting to the exponential development of technology
Risk listening: monitoring for profitable growth
Practical experiences using Atlas and Ranger to implement GDPR
Data Driven Development of Autonomous Driving at BMW
Climbing the AI Ladder
How data modelling helps serve billions of queries in millisecond latency wit...
Data Offload for the Chief Data Officer – how to move data onto Hadoop withou...
Postgres Vision 2018: Data as the New Oil
 

What's hot (20)

PDF
Postgres Vision 2018: AI Needs IA
 
PPTX
Lufthansa Reference Architecture for the OpenGroup
PDF
Postgres Vision 2018: How to Consume your Database Platform On-premises
 
PPTX
Worldwide Hybrid Cloud Computing Market – Drivers, Opportunities, Trends, and...
PDF
The Manulife Journey
PDF
Postgres Vision 2018: The Pragmatic Cloud
 
PDF
On Demand BI
PPTX
Postgres Vision 2018: Taking Postgres Everywhere
 
PPTX
Addressing Challenges with IoT Edge Management
PDF
Making Enterprise Big Data Small with Ease
PDF
Cloud Adoption, Risks and Rewards Infographic
PDF
Postgres Vision 2018: Making Modern an Old Legacy System
 
PPTX
PgConf 2018 - Postgres in a World of DevOps
 
PPTX
Harnessing the Power of Big Data at Freddie Mac
PDF
Three Dimensions of Data as a Service
PDF
Driving Digital Transformation Through Global Data Management
PPTX
Native Spark Executors on Kubernetes: Diving into the Data Lake - Chicago Clo...
PPTX
Defining a Digitalization Reference Architecture for the Pharma Industry
PDF
Postgres Vision 2018: Your Migration Path - Rabobank and a New DBaaS
 
PDF
Next generation Polyglot Architectures using Neo4j by Stefan Kolmar
Postgres Vision 2018: AI Needs IA
 
Lufthansa Reference Architecture for the OpenGroup
Postgres Vision 2018: How to Consume your Database Platform On-premises
 
Worldwide Hybrid Cloud Computing Market – Drivers, Opportunities, Trends, and...
The Manulife Journey
Postgres Vision 2018: The Pragmatic Cloud
 
On Demand BI
Postgres Vision 2018: Taking Postgres Everywhere
 
Addressing Challenges with IoT Edge Management
Making Enterprise Big Data Small with Ease
Cloud Adoption, Risks and Rewards Infographic
Postgres Vision 2018: Making Modern an Old Legacy System
 
PgConf 2018 - Postgres in a World of DevOps
 
Harnessing the Power of Big Data at Freddie Mac
Three Dimensions of Data as a Service
Driving Digital Transformation Through Global Data Management
Native Spark Executors on Kubernetes: Diving into the Data Lake - Chicago Clo...
Defining a Digitalization Reference Architecture for the Pharma Industry
Postgres Vision 2018: Your Migration Path - Rabobank and a New DBaaS
 
Next generation Polyglot Architectures using Neo4j by Stefan Kolmar
Ad

Similar to GDPR: the IBM journey to compliance (20)

PDF
1 -2-6 kista watson summit-gdpr ibm pov hogg-sm
PDF
2 -2-6 kista watson summit-gdpr how ibm preparing hogg-sm
PDF
Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...
PDF
GDPR what you should know and how to minimize impact on your business
PDF
20170323 are you ready the new gdpr is here
PDF
Explain your algorithmic decisions for gdpr
PDF
2016 11-17-gdpr-integro-webinar
PPTX
BigID GDPR Compliance Automation Webinar Slides
PPTX
GDPR: 20 Million Reasons to get ready - Part 1: Preparing for compliance
PPTX
Findability Day 2016 - What is GDPR?
PPTX
GDPR security services - Areyou ready ?
PPTX
Gdpr security services
PDF
Flash Friday: Data Quality & GDPR
PDF
GDPRIBMWhitePaper
PPTX
The EU General Protection Regulation and how Oracle can help
PPTX
GDPR How to get started?
PPTX
Data Protection and Comnpliance with the GDPR Event 22 september 2016
PPTX
Using GDPR to Transform Customer Experience
PDF
#HR and #GDPR: Preparing for 2018 Compliance
PPTX
DevOps vs GDPR: How to Comply and Stay Agile
1 -2-6 kista watson summit-gdpr ibm pov hogg-sm
2 -2-6 kista watson summit-gdpr how ibm preparing hogg-sm
Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...
GDPR what you should know and how to minimize impact on your business
20170323 are you ready the new gdpr is here
Explain your algorithmic decisions for gdpr
2016 11-17-gdpr-integro-webinar
BigID GDPR Compliance Automation Webinar Slides
GDPR: 20 Million Reasons to get ready - Part 1: Preparing for compliance
Findability Day 2016 - What is GDPR?
GDPR security services - Areyou ready ?
Gdpr security services
Flash Friday: Data Quality & GDPR
GDPRIBMWhitePaper
The EU General Protection Regulation and how Oracle can help
GDPR How to get started?
Data Protection and Comnpliance with the GDPR Event 22 september 2016
Using GDPR to Transform Customer Experience
#HR and #GDPR: Preparing for 2018 Compliance
DevOps vs GDPR: How to Comply and Stay Agile
Ad

More from DataWorks Summit (20)

PPTX
Data Science Crash Course
PPTX
Floating on a RAFT: HBase Durability with Apache Ratis
PPTX
Tracking Crime as It Occurs with Apache Phoenix, Apache HBase and Apache NiFi
PDF
HBase Tales From the Trenches - Short stories about most common HBase operati...
PPTX
Optimizing Geospatial Operations with Server-side Programming in HBase and Ac...
PPTX
Managing the Dewey Decimal System
PPTX
Practical NoSQL: Accumulo's dirlist Example
PPTX
HBase Global Indexing to support large-scale data ingestion at Uber
PPTX
Scaling Cloud-Scale Translytics Workloads with Omid and Phoenix
PPTX
Building the High Speed Cybersecurity Data Pipeline Using Apache NiFi
PPTX
Supporting Apache HBase : Troubleshooting and Supportability Improvements
PPTX
Security Framework for Multitenant Architecture
PDF
Presto: Optimizing Performance of SQL-on-Anything Engine
PPTX
Introducing MlFlow: An Open Source Platform for the Machine Learning Lifecycl...
PPTX
Extending Twitter's Data Platform to Google Cloud
PPTX
Event-Driven Messaging and Actions using Apache Flink and Apache NiFi
PPTX
Securing Data in Hybrid on-premise and Cloud Environments using Apache Ranger
PPTX
Big Data Meets NVM: Accelerating Big Data Processing with Non-Volatile Memory...
PDF
Computer Vision: Coming to a Store Near You
PPTX
Big Data Genomics: Clustering Billions of DNA Sequences with Apache Spark
Data Science Crash Course
Floating on a RAFT: HBase Durability with Apache Ratis
Tracking Crime as It Occurs with Apache Phoenix, Apache HBase and Apache NiFi
HBase Tales From the Trenches - Short stories about most common HBase operati...
Optimizing Geospatial Operations with Server-side Programming in HBase and Ac...
Managing the Dewey Decimal System
Practical NoSQL: Accumulo's dirlist Example
HBase Global Indexing to support large-scale data ingestion at Uber
Scaling Cloud-Scale Translytics Workloads with Omid and Phoenix
Building the High Speed Cybersecurity Data Pipeline Using Apache NiFi
Supporting Apache HBase : Troubleshooting and Supportability Improvements
Security Framework for Multitenant Architecture
Presto: Optimizing Performance of SQL-on-Anything Engine
Introducing MlFlow: An Open Source Platform for the Machine Learning Lifecycl...
Extending Twitter's Data Platform to Google Cloud
Event-Driven Messaging and Actions using Apache Flink and Apache NiFi
Securing Data in Hybrid on-premise and Cloud Environments using Apache Ranger
Big Data Meets NVM: Accelerating Big Data Processing with Non-Volatile Memory...
Computer Vision: Coming to a Store Near You
Big Data Genomics: Clustering Billions of DNA Sequences with Apache Spark

Recently uploaded (20)

PDF
Approach and Philosophy of On baking technology
PPT
Teaching material agriculture food technology
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Machine learning based COVID-19 study performance prediction
PPTX
Cloud computing and distributed systems.
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
KodekX | Application Modernization Development
PPTX
Big Data Technologies - Introduction.pptx
PPTX
A Presentation on Artificial Intelligence
PDF
Encapsulation theory and applications.pdf
PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
Approach and Philosophy of On baking technology
Teaching material agriculture food technology
Per capita expenditure prediction using model stacking based on satellite ima...
Machine learning based COVID-19 study performance prediction
Cloud computing and distributed systems.
Dropbox Q2 2025 Financial Results & Investor Presentation
Understanding_Digital_Forensics_Presentation.pptx
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Building Integrated photovoltaic BIPV_UPV.pdf
KodekX | Application Modernization Development
Big Data Technologies - Introduction.pptx
A Presentation on Artificial Intelligence
Encapsulation theory and applications.pdf
Unlocking AI with Model Context Protocol (MCP)
Digital-Transformation-Roadmap-for-Companies.pptx
Diabetes mellitus diagnosis method based random forest with bat algorithm
NewMind AI Weekly Chronicles - August'25 Week I
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
MYSQL Presentation for SQL database connectivity
Mobile App Security Testing_ A Comprehensive Guide.pdf

GDPR: the IBM journey to compliance

  • 1. Dataworks Berlin GDPR : The IBM Journey to Compliance — Richard Hogg, Global GDPR Evangelist Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
  • 2. Richard Hogg Global GDPR Evangelist IBM @banjaxx G- 36 DaysDataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
  • 3. GDPR Legal Disclaimer Clients are responsible for ensuring their own compliance with various laws and regulations, including the European Union General Data Protection Regulation. Clients are solely responsible for obtaining advice of competent legal counsel as to the identification and interpretation of any relevant laws and regulations that may affect the clients’ business and any actions the clients may need to take to comply with such laws and regulations. The products, services, and other capabilities described herein are not suitable for all client situations and may have restricted availability. IBM does not provide legal, accounting or auditing advice or represent or warrant that its services or products will ensure that clients are in compliance with any law or regulation. Learn more about IBM's own GDPR readiness journey and our GDPR capabilities and offerings to support your compliance journey here. Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
  • 4. Simply… Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation GDPR Compliance Data Protection Personal Data
  • 5. The EU General Data Protection Regulation Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation GDPR From May 25th, 2018 Across 28 EU countries 4% of Global Revenue or €20M Potential Penalty Per-Incident Applies Globally to any Organization working with Personal Data of a Data Subject residing in the EU Or Profiling From the EU 5 Key General Data Protection Regulation Obligations Rights of EU Data Subjects Security of Personal Data Compliance & Legal Basis Accountability of Compliance Data Protection by Design and by Default
  • 6. Exemplar Types of Personal Data Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation Personal Data: an identifier such as a name, an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person. Sensitive Personal Data: data consisting of racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data, data concerning health or data concerning a natural person's sex life or sexual orientation. The commission or alleged commission by them of any offence; or any proceedings for any offence committed or alleged to have been committed by them, the disposal of such proceedings or the sentence of any court in such proceedings.
  • 7. 5 Phases to Readiness Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation GDPR Framework – Conduct GDPR risk & privacy assessments across governance, people, processes, data, security – Develop GDPR Readiness Roadmap – Identify & Map personal data – Design governance, training, communication, and process standards – Design privacy, data management and security management standards – Develop and embed procedures, processes and tools – Deliver GDPR training – Develop & embed standards & policies using Privacy by Design, Security by Design – Detailed Data Discovery – Execute all relevant business processes – Monitor security and privacy using TOMs – Manage Consent & data subject access rights Identify GDPR impact and plan Technical and Organizational Measures (TOM’s) Includes Data Protection controls, processes and solutions to be implemented TOMs in place: Personal Data discovery, classification and governance in place Begin the new GDPR ready way of working – Monitor, assess, audit, report and evaluate adherence to GDPR standards Assess Design Transform ConformOperate Monitor TOMs execution; deliver compliance evidence to internal and external stakeholders Assessments and roadmap Defined implementation plan Process enhancements completed Operational framework in place Ongoing monitoring and reporting ActivityOutcomePhase
  • 8. What Is IBM Doing for GDPR Readiness? Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation Our Market Commitment IBM has established a global project to prepare for GDPR, both for our internal processes and for our commercial offerings. IBM recognises that our customers will rely on IBM's offerings and technical assistance to achieve GDPR compliance within their own organisations and IBM is well-positioned to meet this critical need. Our GDPR Readiness Programme GDPR Programme Management Office IBM as a Data Controller Mission: Address IBM’s obligations for managing internal data. IBM as a Data Processor Mission: Ensure compliance and governance for all IBM offerings and services that process personal data. IBM GDPR Common Services Mission: Deploy enterprise tools and common services to facilitate GDPR-related policy, system and business process changes. IBM Vendor Management Mission: Align our supply chain to the upstream obligations we make to our clients and to our internal responsibilities. IBM Client & Contract Management Mission: Help make the client buying process GDPR ready. GDPR Go-To- Market Mission: Create a unified solution to help our clients with their GDPR readiness programmes. IBM has established a global readiness programme tasked with identifying the key impacts of the GDPR across IBM’s business and preparing IBM’s internal processes and commercial offerings for compliance with the GDPR. The programme is organised into several work streams, staffed with IBM’s top data privacy and security professionals. Focal points in each Business Unit are responsible for implementing the GDPR- related policy, system and business process changes mandated by the various key work streams. www.ibm.com/gdpr + new Audit Workstream
  • 9. Northern Trust Accelerated GDPR Readiness — Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation “The journey we took to know, trust, use our data is now accelerating our readiness to GDPR. • Data cataloging efforts to map sensitive data elements across key applications improved company operations and accelerated our path to be GDPR ready • GDPR is now helping us to advance our metadata for other purposes such as data protection • With good quality data with embedded governance controls, my group is providing better service to my constituents so Northern Trust can better serve its customers.” Sanjay Saxena Senior Vice President of Enterprise Data Governance at Northern Trust
  • 10. Use your data Build a single source of truth to drive a 360-degree view of your data. Unleash insights and deepen customer relationships. Trust your data Capture lineage, help ensure quality of dynamic data and stay on top of regulations. Know your data Discover, find, integrate, classify and catalog all types of data. Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
  • 11. Driving Consumer Engagement, Innovation and Competitive Advantage Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation GDPR 66%of users feel more empowered to share data once it has strong governance enablement* Respect and treat personal data properly Build personalized experience Help Compliance readiness Build brand value & loyalty Source: Lock, Michael. “Data Governance 2.0: Uniting People and Information to Drive Real Business Results, Aberdeen Group, 31 August 2017, https://www-01.ibm.com/common/ssi/cgi- bin/ssialias?htmlfid=IML14586USEN&
  • 12. Driving Value Beyond GDPR Compliance Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation The Value of Governance Making data cleaner and more trustworthy contributes to a technology environment that is easier to interact with, protecting data, and guiding users toward the data they need to support their decisions. Find-Share-Collaborate − Break down data silos − Make structured and unstructured data available through a self-service model − Turn complex business data into business value − Be proacitve in the face of changing regulatory environment Data Governance 2.0 “Uniting people and information to drive real business Results” (Aberdeen group Study – August 2017)
  • 13. Opportunities the GDPR Presents to All Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation Reinforcing accountability with your customers Digital engagement and personalisation Improved data management and understanding 1 2 3
  • 14. Build once. Address many needs. Accelerate innovation. ArchivingRecords and retention Audit readinessSelf-service access to data and analytics Discovery360-degree information driven insights Regulations (such as GDPR) Privacy and protection EDW optimization Trusted Analytics Foundation Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
  • 15. AI & ML GDPR Accelerators Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
  • 16. Compare and Comply Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation Watson Compare & Comply allows attorneys to load contracts and other data such as regulations from any source and have Watson analyze and consider the key language, clauses or paragraphs driving the need for further analysis or change Watson considers the contractual terms, regulations or other terms and highlights paragraphs / sentences that contain control requirements (implicit/explicit). Users confirm the validity. Visualize how effectively controls have been assessed per regulation GDPR Outcome Creates a range of bespoke reporting to allow a clear view of where remediation is required, with clear traceability back to impacting new regulations, existing regulations or contractual terms. A clear link back to impacting regulation or de-regulation can be seen to support prioritization and discussions with the regulator
  • 17. Accelerate Taxonomy and Personal Data Mapping via Industry Model Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation Business Taxonomy for Industries mapping each GDPR Terms to business terms & objects, by Article − Consumable for Unified Governance Catalog execution by using IGC Helps pre-define common classes and types of Personal data to find and manage under GDPR − Helps define and accelerate determining which personal data types your business uses − Helps define the examples and methods of finding and managing such personal data GDPR Outcome An immediate re-usable taxonomy and framework of business terms, for what personal data is used in the business, towards a complete Mapping and inventory to a defensible ‘Article 30 Record of Processing of Personal data’ across the business. Marked up GDPR Regulation Supportive Content of all GDPR nouns in IGC Each relevant noun in the text points to equivalent IGC Term Industry agnostic representation of GDPR regulation
  • 18. Governance Value Beyond GDPR Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation Brand Value & Loyalty Strengthen your brand by defining and publishing ethical standards handling personal data both internal (employees) as external (clients)—a quality necessity for the digital age! Grow revenue, reduce churn and acquisition costs. Become ‘data driven’—Personalized Establish key projects like implementing Data Governance or creating a 360 Client View to transform your organization to be data driven as part of your GDPR implementation. Better customer insight and targeted marketing. Compliance Readiness and Business Productivity Established best practices for stewardship and efficiency of data projects and for confidence in handling future regulation. Show respect & trust for Personal Data Derive guidelines for handling personal data and raise the awareness as part of your organization’s values Records of processing activity Consent Building Block Journey Governance and lifecycle management Assessment Access by the data subject Discovery and mapping
  • 19. Discovery and Mapping (Art. 4-5) IS EE (IA, IGC), StoredIQ w/Cartridges, Industry Models w/GDPR content Records of Processing Activities (Art. 30) GDPR Template w/IS EE, StoredIQ, Cognos 11 Manage Consent (Art. 4-7) MDM w/ Consent Mgmt & Profiles Governance and Lifecycle Management (Art. 5) IS EE (IGC), Optim TDM & DP / TD Fabrication / Archive, Atlas, StoredIQ for Legal Data Subject Access (Art. 15) IGC, MDM, Atlas, StoredIQ, Optim, Case Manager Analytics GDPR Building Blocks Records of processing activity Consent Building Block Journey Governance and lifecycle management Assessment Access by the data subject Discovery and mapping Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation
  • 20. Discovery and Mapping Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation Know your relevant data: Understand where personal data resides Define your inventory of Personal Data Discover where Personal Data is stored Reveal ‘shadow’ data stores Process structured and unstructured data and store results in a common catalog Leverage GDPR specific content in Industry Models and GDPR Cartridges for StoredIQ (RegEx & ML) 1. Articles 4-5 Information Analyzer for Structured Data StoredIQ for Unstructured Data Industry Models for Business Vocabulary Conformance Information Governance Catalog
  • 21. Extensive Personal Data Discovery with GDPR Cartridges Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation Plug-in discovery accelerators to find a more extensive set of EU citizen personal data − Maximising the use of RegEx strings − Leveraging Machine Learning Annotators to auto-discover personal data entities such as Names, Addresses, Countries that can’t be defined or found by RegEx − Tailorable & extensible by clients Proven enterprise-scale capability to assess in-place the common sources and types of unstructured information − Heatmap view to prioritise Where Personal information has been found − Actionable outcomes and exports of specific data types and files for remediation & mapping GDPR Outcome Rapidly discover the most common Personal data in all the usual places, avoiding internal time and resources trying to define and manage these rules; Ensuring IT can help other stakeholders reduce Risk and Cost of Discovery.
  • 22. What Is Data Mapping? Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation GDPR ARTICLE 30 Records of Processing Activities Article 30 of Regulation (EU) 2016/679 controller processor written sme regulator who why what where when way who why where way
  • 23. Records of Processing Activities Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation It enables companies to address the requirements of the GDPR defined in Art. 30 through appropriate tooling and a set of artefacts provided through our GDPR Template. Art. 30 GDPR: Records of processing activities Each controller and, where applicable, the controller’s representative, shall maintain a record of processing activities under its responsibility. 2. Article 30
  • 24. Data Subject Access Requests Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation Enterprise scale consistent auditable processing for all DSAR requests, levering a single catalog, policy and processing criteria for each data subject Streamline the DSAR decision and template repeatable but personalized responses within 30 days back to the data subject Provide auditable tracking, management and execution of all types of DSAR’s for Art. 15 3. Article 15
  • 25. Governance and Lifecycle Management Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation Mask personal identifiable information with realistic but fictional data, de-identify sensitive information; mask complete business objects across heterogeneous databases & applications; when needed, generate synthetic test data Govern the lifecycle of data with archival, records management, and defensible disposal Drive to Data Minimisation under GDPR 4. Article 5 JASON MICHAELS ROBERT SMITH DBA View Referentially-intact subsets of data across related tables & applications, including metadata. Business View Overall historical “snapshot” of business activity, representing an application data record – e.g. payment, invoice, customer
  • 26. Manage Consent Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation A Consent Service providing a framework for obtaining, maintaining and applying where specific consent is required, for some GDPR data processing, away from the current blanket single consent commonly imposed Supports any categories of Consent or Sharing preferences for data subjects, flexible and changeable by them at any time. Each Consent is more granular, specific for each Purpose and clearly conveys What data is related to that consented purpose. Where required, explicit transparent Purposeful Consent of any personal data processing is available for data subjects and processors to know and understand how it can be and is used. 5. Articles 4-7
  • 27. Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation Consent Management
  • 28. Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation What’s New for GDPR? RegulatoryML Lab Concept
  • 29. Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation What’s New for GDPR? Blockchain Whitepaper ibm.biz/blockchain-gdpr Using real-world examples, this paper explores how blockchain could address five areas associated with GDPR compliance Rights of EU Data Subjects, Security of Processing, Lawfulness and Consent, Accountability of Compliance, and Data Protection by Design and by Default. In this paper, for each of the areas, we provide a point of view on how blockchain applies, we describe project examples, and we explore challenges and opportunities.
  • 30. Thank you Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation Richard Hogg Global GDPR Evangelist — rghogg@us.ibm.com +1-703-963-2900 ibm.com @banjaxx
  • 31. Dataworks Berlin / April 19, 2018 / © 2018 IBM Corporation