SlideShare a Scribd company logo
2
Most read
3
Most read
13
Most read
Global Data Privacy Regulation
Every Data Counts
Agenda
• GDPR
• Principles
• Web Developer Role
• What Is Personal Data?
• Privacy By Design
• What are cookies
• What is a privacy notice?
GDPR
• GDPR requires you to be more thoughtful about the sites and services you build, more transparent about the
ways you collect and use data, more considerate of your users, and more thorough in your development and
documentation processes.
• General Data Protection Regulation (GDPR), which becomes enforceable across Europe on 25 May 2018. This
is an overhaul, modernization, and replacement of the existing framework, the Data Protection Directive of
1995.
• GDPR adds is new definitions and requirements to reflect changes in technology which simply did not exist in
the Data Protection Directive. It also tightens up requirements for transparency, disclosure, and process.
We all have to become more diligent about:
• What data we collect,
• How we collect it, and
• What we do with it. In current turbulent times, these privacy obligations are about ethics as well as
law.
Principles
• Purpose limitation
Data can be collected and used only for those purposes that have been transmitted to the data subject and
about which the consent was received. Purpose must be “specified, explicit and legitimate”
• Data minimization
Personal data to be collected should be “adequate, relevant and limited to what is necessary in relation to
the purposes for which they are processed”.
• Accuracy
Personal data must be “accurate and where necessary kept up to date”. You must make sure that you do
not retain old and outdated contacts and ensure the erasure of inaccurate personal data without delay
• Storage limitations
Company would have to set the retention period for personal data you collect and justify that this period is
necessary for your specific objectives
• Integrity and confidentiality
The principle of integrity and confidentiality requires you to handle personal data “in a manner [ensuring]
appropriate security”, which include “protection against unlawful processing or accidental loss, destruction
or damage”.
Principles
• "Implement anonymization or pseudonymization into the systems.
• Data anonymization is a type of information sanitization whose intent is privacy protection. It is the process
of removing personally identifiable information from data sets, so that the people whom the data describe
remain anonymous.
• Pseudonymization is a data management and de-identification procedure by which personally identifiable
information fields within a data record are replaced by one or more artificial identifiers, or pseudonyms."
• Accountability
Company is responsible for compliance with the principles of the GDPR. It requires a thorough
documentation of all policies that govern the collection and procession of data.
Web Developer Role
• Web developers have a major role to play here. After all, healthy data protection practice is as much about
the development side — code, data, and security — as it is about the business side of process, information,
and strategy.
• Below, we’ll explore what you, as a developer, need to know about the new data protection regime.
What Is Personal Data?
This is defined as “any information relating to an identified or identifiable natural person.” This can be one piece of
information or multiple data points combined to create a record.
Beyond personal data there is also sensitive personal data, defined as information about a person’s:
• Racial or ethnic origin
• Political opinions
• Religious or philosophical beliefs
• Trade union membership
• Health data
• Sex life or sexual orientation
• Past or spent criminal convictions
What Is Personal Data?
GDPR expands the definition of personal data to include:
• Genetic data
• Biometric data (such as facial recognition or fingerprint logins)
• Location data
• Income
• Online identifiers
• IP addresses
• Mobile device IDs
• Browser fingerprints
• RFID tags
• MAC addresses
• Cookies
• Telemetry
• User account IDs
Privacy By Design
The Privacy by Design framework has seven foundational principles:
• Privacy must be proactive, not reactive, and must anticipate privacy issues before they reach the user. Privacy
must also be preventative, not remedial.
• Privacy must be the default setting. The user should not have to take actions to secure their privacy, and
consent for data sharing should not be assumed.
• Privacy must be embedded into design. It must be a core function of the product or service, not an add-on.
• Privacy must be positive sum and should avoid dichotomies. For example, PbD sees an achievable balance
between privacy and security, not a zero-sum game of privacy or security.
• Privacy must offer end-to-end lifecycle protection of user data. This means engaging in proper data
minimization, retention and deletion processes.
• Privacy standards must be visible, transparent, open, documented and independently verifiable. Your
processes, in other words, must stand up to external scrutiny.
• Privacy must be user-centric. This means giving users granular privacy options, maximized privacy defaults,
detailed privacy information notices, user-friendly options and clear notification of changes
What are cookies
• Cookies are small text files that websites place on your device as you are browsing. They are processed and
stored by your web browser. Cookies can also generally be easily viewed and deleted.
• Cookies can store a wealth of data, enough to potentially identify you without your consent. Cookies are the
primary tool that advertisers use to track your online activity so that they can target you with highly specific
ads.
Types of Cookies:
• Session cookies – These cookies are temporary and expire once you close your browser (or once your session
ends)
• Persistent cookies — This category encompasses all cookies that remain on your hard drive until you erase
them, or your browser does, depending on the cookie’s expiration date. All persistent cookies have an
expiration date written into their code, but their duration can vary. According to the ePrivacy Directive, they
should not last longer than 12 months
What are cookies
Cookie GDPR compliance:
• Receive users’ consent before you use any cookies except strictly necessary cookies.
• Provide accurate and specific information about the data each cookie tracks and its purpose in plain language
before consent is received.
• Document and store consent received from users.
• Allow users to access your service even if they refuse to allow the use of certain cookies
• Make it as easy for users to withdraw their consent as it was for them to give their consent in the first place
What is a privacy notice?
• A privacy notice is a public document from an organization that explains how that organization processes
personal data and how it applies data protection principles. GDPR provide detailed instructions on how to
create a privacy notice, placing an emphasis on making them easy to understand and accessible. If you are
collecting data directly from someone, you have to provide them with your privacy notice at the moment you
do so.
• The terms “privacy notice” and “privacy policy” are interchangeable
Thank You!
For any queries connect me at jatinkochhar@hotmail.com

More Related Content

PPTX
Why We Require GDPR?
PPTX
GDPR Data Life Cycle
PPTX
GDPR Data Lifecycle
PPTX
Embedding GDPR Within Your Information and Library Service
PPTX
GDPR Seminar Slides
PPTX
BigID GDPR Compliance Automation Webinar Slides
PDF
Beginning your General Data Protection Regulation (GDPR) Journey
PDF
Finding Data at Risk for CCPA Compliance
Why We Require GDPR?
GDPR Data Life Cycle
GDPR Data Lifecycle
Embedding GDPR Within Your Information and Library Service
GDPR Seminar Slides
BigID GDPR Compliance Automation Webinar Slides
Beginning your General Data Protection Regulation (GDPR) Journey
Finding Data at Risk for CCPA Compliance

What's hot (19)

PPTX
India'a Proposed Privacy & Personal Data Protection Law
PPTX
BigID & Collibra Joint Deck: Using BigID’s Privacy-centric Data Discovery to...
PPTX
Evolving international privacy regulations and cross border data transfer - g...
PPTX
Privacy Secrets Your Systems May Be Telling
PDF
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
PDF
BigID GDPR Privacy Automation Data Sheet
PPTX
An Introduction to the General Data Protection Regulation (GDPR)
PDF
BigID, OneTrust, IAPP Webinar: Bridging the Privacy Office with IT
PPTX
Data Privacy
PPTX
Collibra Data Citizen '19 - Bridging Data Privacy with Data Governance
PDF
Rent-a-DPO for IT Vendors
PDF
Privacy and Big Data Overload!
PDF
UX & GDPR - Building Customer Trust with your Digital Experiences
PDF
BigID Data sheet: Consent Governance & Orchestration
PDF
Energy Data Privacy Presentation
PDF
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
PPTX
How to Build a Privacy Program
PDF
Data Privacy
PDF
BigID Data Sheet: LGPD Compliance Automated
India'a Proposed Privacy & Personal Data Protection Law
BigID & Collibra Joint Deck: Using BigID’s Privacy-centric Data Discovery to...
Evolving international privacy regulations and cross border data transfer - g...
Privacy Secrets Your Systems May Be Telling
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
BigID GDPR Privacy Automation Data Sheet
An Introduction to the General Data Protection Regulation (GDPR)
BigID, OneTrust, IAPP Webinar: Bridging the Privacy Office with IT
Data Privacy
Collibra Data Citizen '19 - Bridging Data Privacy with Data Governance
Rent-a-DPO for IT Vendors
Privacy and Big Data Overload!
UX & GDPR - Building Customer Trust with your Digital Experiences
BigID Data sheet: Consent Governance & Orchestration
Energy Data Privacy Presentation
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
How to Build a Privacy Program
Data Privacy
BigID Data Sheet: LGPD Compliance Automated
Ad

Similar to Global Data Privacy Regulation (20)

PPTX
Gdpr presentation
PDF
Privacy by Design and by Default + General Data Protection Regulation with Si...
PDF
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
PDF
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
PDF
Magento checklist AVG / GDPR - Algemene Verordering Gegevensbescherming
PDF
GDPR webinar for business leaders
PPT
GDPR webinar presentation | LawBite
PDF
GDPR - Sink or Swim
PDF
Toreon adding privacy by design in secure application development oss18 v20...
PDF
What's Next - General Data Protection Regulation (GDPR) Changes
PDF
GDPR Changing Mindset
PDF
General Data Protection Regulation, a developer's story
PDF
Gdpr presentation
PDF
data privacy handbook: A starter guide to data privacy compliance
PDF
UX & GDPR - Building Customer Trust with your Digital Experiences
PDF
GDPR Is Around the Corner - Don't Panic
PDF
Creating a GDPR Action Plan; Not a Freakout Plan
PPTX
GDPR in the Healthcare Industry
PDF
Cookie Consent and Authorized Data Collection_Mar23.pdf
PDF
Opportunity or burden
Gdpr presentation
Privacy by Design and by Default + General Data Protection Regulation with Si...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
Magento checklist AVG / GDPR - Algemene Verordering Gegevensbescherming
GDPR webinar for business leaders
GDPR webinar presentation | LawBite
GDPR - Sink or Swim
Toreon adding privacy by design in secure application development oss18 v20...
What's Next - General Data Protection Regulation (GDPR) Changes
GDPR Changing Mindset
General Data Protection Regulation, a developer's story
Gdpr presentation
data privacy handbook: A starter guide to data privacy compliance
UX & GDPR - Building Customer Trust with your Digital Experiences
GDPR Is Around the Corner - Don't Panic
Creating a GDPR Action Plan; Not a Freakout Plan
GDPR in the Healthcare Industry
Cookie Consent and Authorized Data Collection_Mar23.pdf
Opportunity or burden
Ad

More from Jatin Kochhar (14)

DOCX
Intent Based Analytics with Google Analytics and Google Tag Manager
PPTX
Mobile Application vs Web Application
DOCX
Integration of Google Tag Manager and Google Analytics
PPTX
Search Engine Marketing
PPTX
Search Engine Optimization - Optimize Organic Search
PPTX
Analytic Tool Hotjar - Capability
PPTX
Landing Page Optimization
PPTX
Accessibility for Content Developer, Designer, Code Developer and Tester
PPTX
Accessibility Testing Approach
PPTX
What is Accessibility
PPTX
Basics of python
PPTX
Software Test Estimation
PPTX
Conformance Checklist for Product Owner
PPTX
Software Testing Metrics
Intent Based Analytics with Google Analytics and Google Tag Manager
Mobile Application vs Web Application
Integration of Google Tag Manager and Google Analytics
Search Engine Marketing
Search Engine Optimization - Optimize Organic Search
Analytic Tool Hotjar - Capability
Landing Page Optimization
Accessibility for Content Developer, Designer, Code Developer and Tester
Accessibility Testing Approach
What is Accessibility
Basics of python
Software Test Estimation
Conformance Checklist for Product Owner
Software Testing Metrics

Recently uploaded (20)

PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
GamePlan Trading System Review: Professional Trader's Honest Take
PPT
Teaching material agriculture food technology
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
KodekX | Application Modernization Development
PDF
[발표본] 너의 과제는 클라우드에 있어_KTDS_김동현_20250524.pdf
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Spectral efficient network and resource selection model in 5G networks
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Electronic commerce courselecture one. Pdf
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Modernizing your data center with Dell and AMD
PPTX
Big Data Technologies - Introduction.pptx
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
solutions_manual_-_materials___processing_in_manufacturing__demargo_.pdf
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
Dropbox Q2 2025 Financial Results & Investor Presentation
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
GamePlan Trading System Review: Professional Trader's Honest Take
Teaching material agriculture food technology
NewMind AI Weekly Chronicles - August'25 Week I
KodekX | Application Modernization Development
[발표본] 너의 과제는 클라우드에 있어_KTDS_김동현_20250524.pdf
Mobile App Security Testing_ A Comprehensive Guide.pdf
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Spectral efficient network and resource selection model in 5G networks
MYSQL Presentation for SQL database connectivity
Network Security Unit 5.pdf for BCA BBA.
Electronic commerce courselecture one. Pdf
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Modernizing your data center with Dell and AMD
Big Data Technologies - Introduction.pptx
Per capita expenditure prediction using model stacking based on satellite ima...
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
solutions_manual_-_materials___processing_in_manufacturing__demargo_.pdf
20250228 LYD VKU AI Blended-Learning.pptx

Global Data Privacy Regulation

  • 1. Global Data Privacy Regulation Every Data Counts
  • 2. Agenda • GDPR • Principles • Web Developer Role • What Is Personal Data? • Privacy By Design • What are cookies • What is a privacy notice?
  • 3. GDPR • GDPR requires you to be more thoughtful about the sites and services you build, more transparent about the ways you collect and use data, more considerate of your users, and more thorough in your development and documentation processes. • General Data Protection Regulation (GDPR), which becomes enforceable across Europe on 25 May 2018. This is an overhaul, modernization, and replacement of the existing framework, the Data Protection Directive of 1995. • GDPR adds is new definitions and requirements to reflect changes in technology which simply did not exist in the Data Protection Directive. It also tightens up requirements for transparency, disclosure, and process. We all have to become more diligent about: • What data we collect, • How we collect it, and • What we do with it. In current turbulent times, these privacy obligations are about ethics as well as law.
  • 4. Principles • Purpose limitation Data can be collected and used only for those purposes that have been transmitted to the data subject and about which the consent was received. Purpose must be “specified, explicit and legitimate” • Data minimization Personal data to be collected should be “adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed”. • Accuracy Personal data must be “accurate and where necessary kept up to date”. You must make sure that you do not retain old and outdated contacts and ensure the erasure of inaccurate personal data without delay • Storage limitations Company would have to set the retention period for personal data you collect and justify that this period is necessary for your specific objectives • Integrity and confidentiality The principle of integrity and confidentiality requires you to handle personal data “in a manner [ensuring] appropriate security”, which include “protection against unlawful processing or accidental loss, destruction or damage”.
  • 5. Principles • "Implement anonymization or pseudonymization into the systems. • Data anonymization is a type of information sanitization whose intent is privacy protection. It is the process of removing personally identifiable information from data sets, so that the people whom the data describe remain anonymous. • Pseudonymization is a data management and de-identification procedure by which personally identifiable information fields within a data record are replaced by one or more artificial identifiers, or pseudonyms." • Accountability Company is responsible for compliance with the principles of the GDPR. It requires a thorough documentation of all policies that govern the collection and procession of data.
  • 6. Web Developer Role • Web developers have a major role to play here. After all, healthy data protection practice is as much about the development side — code, data, and security — as it is about the business side of process, information, and strategy. • Below, we’ll explore what you, as a developer, need to know about the new data protection regime.
  • 7. What Is Personal Data? This is defined as “any information relating to an identified or identifiable natural person.” This can be one piece of information or multiple data points combined to create a record. Beyond personal data there is also sensitive personal data, defined as information about a person’s: • Racial or ethnic origin • Political opinions • Religious or philosophical beliefs • Trade union membership • Health data • Sex life or sexual orientation • Past or spent criminal convictions
  • 8. What Is Personal Data? GDPR expands the definition of personal data to include: • Genetic data • Biometric data (such as facial recognition or fingerprint logins) • Location data • Income • Online identifiers • IP addresses • Mobile device IDs • Browser fingerprints • RFID tags • MAC addresses • Cookies • Telemetry • User account IDs
  • 9. Privacy By Design The Privacy by Design framework has seven foundational principles: • Privacy must be proactive, not reactive, and must anticipate privacy issues before they reach the user. Privacy must also be preventative, not remedial. • Privacy must be the default setting. The user should not have to take actions to secure their privacy, and consent for data sharing should not be assumed. • Privacy must be embedded into design. It must be a core function of the product or service, not an add-on. • Privacy must be positive sum and should avoid dichotomies. For example, PbD sees an achievable balance between privacy and security, not a zero-sum game of privacy or security. • Privacy must offer end-to-end lifecycle protection of user data. This means engaging in proper data minimization, retention and deletion processes. • Privacy standards must be visible, transparent, open, documented and independently verifiable. Your processes, in other words, must stand up to external scrutiny. • Privacy must be user-centric. This means giving users granular privacy options, maximized privacy defaults, detailed privacy information notices, user-friendly options and clear notification of changes
  • 10. What are cookies • Cookies are small text files that websites place on your device as you are browsing. They are processed and stored by your web browser. Cookies can also generally be easily viewed and deleted. • Cookies can store a wealth of data, enough to potentially identify you without your consent. Cookies are the primary tool that advertisers use to track your online activity so that they can target you with highly specific ads. Types of Cookies: • Session cookies – These cookies are temporary and expire once you close your browser (or once your session ends) • Persistent cookies — This category encompasses all cookies that remain on your hard drive until you erase them, or your browser does, depending on the cookie’s expiration date. All persistent cookies have an expiration date written into their code, but their duration can vary. According to the ePrivacy Directive, they should not last longer than 12 months
  • 11. What are cookies Cookie GDPR compliance: • Receive users’ consent before you use any cookies except strictly necessary cookies. • Provide accurate and specific information about the data each cookie tracks and its purpose in plain language before consent is received. • Document and store consent received from users. • Allow users to access your service even if they refuse to allow the use of certain cookies • Make it as easy for users to withdraw their consent as it was for them to give their consent in the first place
  • 12. What is a privacy notice? • A privacy notice is a public document from an organization that explains how that organization processes personal data and how it applies data protection principles. GDPR provide detailed instructions on how to create a privacy notice, placing an emphasis on making them easy to understand and accessible. If you are collecting data directly from someone, you have to provide them with your privacy notice at the moment you do so. • The terms “privacy notice” and “privacy policy” are interchangeable
  • 13. Thank You! For any queries connect me at jatinkochhar@hotmail.com