SlideShare a Scribd company logo
© 2017 ForgeRock. All rights reserved.
GDPR
@hannsnolan
ForgeRock Identity Platform!
some of the more identity related components of the GDPR
© 2017 ForgeRock. All rights reserved.
significant penalties for GDPR infractions start on
May 25, 2018.
© 2016 ForgeRock. All rights reserved.
GDPR is different, and FR is different
• GDPR applies to every organization selling to or
monitoring anyone in the EU
• GDPR has a firm deadline (May ‘18), high penalties
(4% of global turnover), and high aspirations (human
rights)
• Privacy tools assess/ensure compliance
• GDPR tools target risk teams
• We sell to digital teams
• Who need to own and drive this challenge -- quickly -- so
that it becomes a triumph vs. a tragedy
© 2017 ForgeRock. All rights reserved.
Impact of GDPR
some of the more identity related components of the GDPR
• Consent for processing personal data
• Proof of Consent (data & processing!)
• Consent per purpose (including revocation)
• DPO (Data Protection Officer) are required (e.g. external)
• DPIAs (Data Protection Impact Assessment) under certain cir.
• Data breach notification within 72 hours
• Massive data control rights (forgotten, freeze, export rights)
• Privacy by default
• PLUS organizational/other requirements (out of scope here)
© 2017 ForgeRock. All rights reserved.
What to take care of?
• Personal Data
• where is your data? -> least privileged? encryption?
• Lawful Processing
• law and IDM? YES -> user consent driven!
• Individual's Right to Rectification, Export and Erasure
• new requirement! Big challenger: export, erasure
End user dashboards, registration journeys and consent frameworks
will need updating!
© 2017 ForgeRock. All rights reserved.
What is to do?
End user dashboards, registration journeys and consent
frameworks will need updating.
Don't see it as a compliance exercise!
The interesting aspect, is that privacy is now becoming a
competitive differentiator.
© 2016 ForgeRock. All rights reserved.
A holistic view of the
ForgeRock Identity Platform
Identity data
governance; single
view of the consumer
Giving the consumer a
single view of their
consents
Giving the consumer
control over their
consents
● Lifecycle management
of user profile and data
sharing preferences
● Secure storage of profile
data
● Anonymised syncing of
profile data and
connector-based
integration to third-party
systems
● Data residency and
fractional replication
● ToS and privacy policy
capture at registration and
authentication time
● Social/federated sign-in
● Social registration
● Social consent
management
● Interoperable,
user-driven, proactive
and reactive sharing
flows
© 2016 ForgeRock. All rights reserved.
This is not an “UMA proposal”
• UMA is one enabler of a suite of potential capabilities
that build on our core platform strengths for a general
strategic P&C capability
• But it is an important enabler that plays into:
• Cloud (loose coupling of APIs/services for building partner
ecosystems)
• Bilateral service<->user dialog required for ability to deliver
explicit consent (stronger definition of consent required by
GDPR)
• Use cases especially favored by IoT use cases
• We can call new/enhanced P&C capabilities/module(s)
anything we like
© 2017 ForgeRock. All rights reserved.
Technical Challenges
• Holistic single view of the customer
• Consent sharing (legacy backend apps!)
• New innovations and trust (Container, Micro Services,
Blockchain etc.)
• Redesigning/Creating frontends/touchpoints
• Keep customer data accurate and protected
© 2016 ForgeRock. All rights reserved.
Building a (bilateral) trusted digital
relationship -- a high-level proposal
Single view of the customer
Consent lifecycle
management
Giving the customer context,
control, choice, and
respect
• Existing platform has many
strengths
• Benefits for compliance are
under-marketed (can’t even
attempt “right to be forgotten”
if you don’t know where all
the data is…)
• We don’t have packaged
solutions targeted to P&C
challenges, just a “bag of
tools” (KC’s CIAM report)
• We don’t have direct P&C
solutions today
• GDPR has some
requirements here
• IDM, CAUD, and AM in
concert have great potential
• Consent Receipts, OAuth,
and UMA are relevant
standards
• We have hints of solutions
here (early UMA)
• GDPR has some
requirements here
• UMA is a relevant standard
© 2016 ForgeRock. All rights reserved.
Patient selectively sharing IoT health data with doctors
and other caregivers
Patient view Doctor view
© 2016 ForgeRock. All rights reserved.
Granular consented access by accountant to bank
customer’s account data and transactions
12
© 2016 ForgeRock. All rights reserved.
Consent within IDM and Sync
© 2016 ForgeRock. All rights reserved.
ForgeRock
ForgeRock
ForgeRockIdentity
ForgeRock
Forgerock.com
Forgerock.com/blog
Thank you
© 2017 ForgeRock. All rights reserved.
Further Readings
• GDPR at ForgeRock
• Webinar with Eve Maler
• Introduction ForgeRock Identity Platform
• The Role of Identity by Simon Moffatt

More Related Content

PPTX
HSBC - ForgeRock Identity Summit 2017 Dusseldorf
PPTX
Identity Live Sydney 2017 - Daniel Raskin
PPTX
Identity Live Sydney 2017 - Ian Sorbello
PDF
IoT Wonderland: Understanding the Magic of OAuth2 Device Registration Flow
PPTX
Identity Live Paris 2017 | Ian Sorbello, HSBC
PPTX
Identity Live London 2017 | Kenneth May
PPTX
Identity Live Paris 2017 | Monetising Digital Customer Relationships
PDF
Digital Identities in the Internet of Things - Securely Manage Devices at Scale
HSBC - ForgeRock Identity Summit 2017 Dusseldorf
Identity Live Sydney 2017 - Daniel Raskin
Identity Live Sydney 2017 - Ian Sorbello
IoT Wonderland: Understanding the Magic of OAuth2 Device Registration Flow
Identity Live Paris 2017 | Ian Sorbello, HSBC
Identity Live London 2017 | Kenneth May
Identity Live Paris 2017 | Monetising Digital Customer Relationships
Digital Identities in the Internet of Things - Securely Manage Devices at Scale

What's hot (20)

PPTX
Gartner - ForgeRock Identity Live 2017 - Dusseldorf
PPTX
Amer Sports - ForgeRock Identity Live - Dusseldorf
PDF
Intelligent Authentication (Identity Live Berlin 2018)
PPTX
Victor Ake and Chris Kawalek - ForgeRock Identity Live 2017 - Dusseldorf
PDF
ForgeRock and Trusona - Simplifying the Multi-factor User Experience
PDF
Steinberg - Customer identity as the cornerstone of our approach to digitaliz...
PDF
Connected Car: Putting Digital Identity Behind the Wheel
PPTX
Hermann Wimmer - ForgeRock Identity Live 2017 - Dusseldorf
PPTX
Identity Live Sydney 2017 - Tim Sheedy
PDF
Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...
PDF
The ForgeRock Identity Platform Extends CIAM, Fall 2017 Release
PPTX
Identity Objects in Mirror Are Closer Than They Appear - Identity Live 2017 -...
PPTX
Identity Live Sydney 2017 - Andrew Latham
PPTX
Identity Live Paris 2017 | Mike Ellis
PDF
Identity Live Sydney: Intelligent Authentication
PDF
Identity Live Sydney: Building Trust and Privacy in a Connected Society
PPTX
Identity Live London 2017 | Daniel Raskin
PDF
Shift from GDPR readiness to sustained compliance to improve your business an...
PDF
Winning with GDPR: How to Win Customer Loyalty and Trust
PDF
Identity Live Sydney 2018 Keynote Presentation
Gartner - ForgeRock Identity Live 2017 - Dusseldorf
Amer Sports - ForgeRock Identity Live - Dusseldorf
Intelligent Authentication (Identity Live Berlin 2018)
Victor Ake and Chris Kawalek - ForgeRock Identity Live 2017 - Dusseldorf
ForgeRock and Trusona - Simplifying the Multi-factor User Experience
Steinberg - Customer identity as the cornerstone of our approach to digitaliz...
Connected Car: Putting Digital Identity Behind the Wheel
Hermann Wimmer - ForgeRock Identity Live 2017 - Dusseldorf
Identity Live Sydney 2017 - Tim Sheedy
Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...
The ForgeRock Identity Platform Extends CIAM, Fall 2017 Release
Identity Objects in Mirror Are Closer Than They Appear - Identity Live 2017 -...
Identity Live Sydney 2017 - Andrew Latham
Identity Live Paris 2017 | Mike Ellis
Identity Live Sydney: Intelligent Authentication
Identity Live Sydney: Building Trust and Privacy in a Connected Society
Identity Live London 2017 | Daniel Raskin
Shift from GDPR readiness to sustained compliance to improve your business an...
Winning with GDPR: How to Win Customer Loyalty and Trust
Identity Live Sydney 2018 Keynote Presentation
Ad

Viewers also liked (15)

PDF
GDPR is coming in Hot. Top Burning Questions Answered to Help You Keep Your C...
PPTX
Keynote : Customer Identity Builds Digital Trust - Paris Identity Summit
PDF
DevOps Unleashed: Strategies that Speed Deployments
PPTX
Keynote: Tech, Trust, and Transformation - Paris Identity Summit 2016
PPTX
OpenAM - An Introduction
PDF
T-Systems. Automating ForgeRock Full Stack Deployments to a Magenta Cloud.
PPTX
Identity Live Sydney 2017 - Ashley Stevenson
PDF
The Business Ecosystem is a Neighborhood - ForgeRock Identity Live Austin 2017
PPTX
A Backstage Tour of Identity - Paris Identity Summit 2016
PDF
The digital pains of retail
PPTX
Identity Live London 2017 | Marko Orenius
PPTX
Identity Live London 2017 | Ashley Stevenson
PPTX
Identity Live Sydney 2017 - Michael Dowling
PDF
The Future is Now: The ForgeRock Identity Platform, Early 2017 Release
PPTX
Analyst Keynote: Putting Customers First Requires Innovation and Identity - P...
GDPR is coming in Hot. Top Burning Questions Answered to Help You Keep Your C...
Keynote : Customer Identity Builds Digital Trust - Paris Identity Summit
DevOps Unleashed: Strategies that Speed Deployments
Keynote: Tech, Trust, and Transformation - Paris Identity Summit 2016
OpenAM - An Introduction
T-Systems. Automating ForgeRock Full Stack Deployments to a Magenta Cloud.
Identity Live Sydney 2017 - Ashley Stevenson
The Business Ecosystem is a Neighborhood - ForgeRock Identity Live Austin 2017
A Backstage Tour of Identity - Paris Identity Summit 2016
The digital pains of retail
Identity Live London 2017 | Marko Orenius
Identity Live London 2017 | Ashley Stevenson
Identity Live Sydney 2017 - Michael Dowling
The Future is Now: The ForgeRock Identity Platform, Early 2017 Release
Analyst Keynote: Putting Customers First Requires Innovation and Identity - P...
Ad

Similar to Implications of GDPR in Conjunction with UMA (20)

PDF
WP-Privacy-IoT-Era - PRODUCTION
PDF
Digital Trust: How Identity Tackles the Privacy, Security and IoT Challenge
PPTX
Doing Authorisation, Consent, and Delegation Right with UMA - Paris Identity ...
PDF
Applying Innovative Tools for GDPR Success
PPTX
Doing Authorisation, Consent, and Delegation Right with UMA - London Identity...
PDF
L’identité numérique : un atout incontournable pour construire une relation c...
PDF
Data Protection and Privacy
PPTX
2015 Identity Summit - Stepping Up to New Data Protection Challenges
PPTX
Webinar: Consent 2.0: Applying User-Managed Access to the Privacy Challenge
PPT
Canberra Executive Breakfast - A Citizen-Centric Approach to Identity
PDF
Sydney Identity Summit: Doing Authorisation, Consent and Delegation Right wit...
PDF
Data Protection Scotland Summit 2019
PDF
GDPR - Applift firstscreen june 2016
PPTX
GDPR and IoT: What do you need to know?
PPTX
Webinar: "Entitlements: Taking Control of the Big Data Gold Rush"
PDF
General Data Protection Regulation - BDW Meetup, October 11th, 2017
PPTX
NYC Identity Summit Business Day: Doing Authorization, Consent, and Delegatio...
PPTX
DevOps vs GDPR: How to Comply and Stay Agile
PDF
2017: Privacy Issues on the Horizon
PPTX
CPA - Introduction to Digital Identity - rev20171102
WP-Privacy-IoT-Era - PRODUCTION
Digital Trust: How Identity Tackles the Privacy, Security and IoT Challenge
Doing Authorisation, Consent, and Delegation Right with UMA - Paris Identity ...
Applying Innovative Tools for GDPR Success
Doing Authorisation, Consent, and Delegation Right with UMA - London Identity...
L’identité numérique : un atout incontournable pour construire une relation c...
Data Protection and Privacy
2015 Identity Summit - Stepping Up to New Data Protection Challenges
Webinar: Consent 2.0: Applying User-Managed Access to the Privacy Challenge
Canberra Executive Breakfast - A Citizen-Centric Approach to Identity
Sydney Identity Summit: Doing Authorisation, Consent and Delegation Right wit...
Data Protection Scotland Summit 2019
GDPR - Applift firstscreen june 2016
GDPR and IoT: What do you need to know?
Webinar: "Entitlements: Taking Control of the Big Data Gold Rush"
General Data Protection Regulation - BDW Meetup, October 11th, 2017
NYC Identity Summit Business Day: Doing Authorization, Consent, and Delegatio...
DevOps vs GDPR: How to Comply and Stay Agile
2017: Privacy Issues on the Horizon
CPA - Introduction to Digital Identity - rev20171102

More from ForgeRock (19)

PPTX
Get the Exact Identity Solution You Need - In the Cloud - AWS and Beyond
PDF
Identity Live Sydney: Identity Management - A Strategic Opportunity
PDF
Identity Live Singapore: Transform Your Cybersecurity Capability
PDF
Identity Live Singapore 2018 Keynote Presentation
PDF
Identity Live Singapore: Just Ask 'Em
PDF
Identity Live Singapore: Building Trust & Privacy in a Connected Society
PDF
Get the Exact Identity Solution you Need in the Cloud - Deep Dive
PPTX
Get the Exact Identity Solution You Need - In the Cloud - Overview
PDF
Opening Keynote (Identity Live Berlin 2018)
PDF
BMW Group - Identity Enables the Next 100 Years.. (Identity Live Berlin 2018)
PDF
Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...
PDF
Customer Safeguarding, Fraud and GDPR: Manah Khalil
PDF
What the Internet of Things Means for Consumer Privacy: Veronica Lara
PDF
Identity Live in Austin Keynote
PDF
The Value of User and Data Centricity Beyond IoT Devices: Stein Myrseth and G...
PDF
Where Biometrics, Blockchains, and Bots are Taking Digital Identity: David Birch
PPTX
The Road to Intelligent Authentication Journeys
PDF
Go Beyond PSD2 Compliance with Digital Identity
PPT
Identity Live Paris 2017 | Jean-François Dupitier & Christophe Lemaire, Pôle ...
Get the Exact Identity Solution You Need - In the Cloud - AWS and Beyond
Identity Live Sydney: Identity Management - A Strategic Opportunity
Identity Live Singapore: Transform Your Cybersecurity Capability
Identity Live Singapore 2018 Keynote Presentation
Identity Live Singapore: Just Ask 'Em
Identity Live Singapore: Building Trust & Privacy in a Connected Society
Get the Exact Identity Solution you Need in the Cloud - Deep Dive
Get the Exact Identity Solution You Need - In the Cloud - Overview
Opening Keynote (Identity Live Berlin 2018)
BMW Group - Identity Enables the Next 100 Years.. (Identity Live Berlin 2018)
Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...
Customer Safeguarding, Fraud and GDPR: Manah Khalil
What the Internet of Things Means for Consumer Privacy: Veronica Lara
Identity Live in Austin Keynote
The Value of User and Data Centricity Beyond IoT Devices: Stein Myrseth and G...
Where Biometrics, Blockchains, and Bots are Taking Digital Identity: David Birch
The Road to Intelligent Authentication Journeys
Go Beyond PSD2 Compliance with Digital Identity
Identity Live Paris 2017 | Jean-François Dupitier & Christophe Lemaire, Pôle ...

Recently uploaded (20)

PDF
cuic standard and advanced reporting.pdf
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PPT
Teaching material agriculture food technology
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PPTX
sap open course for s4hana steps from ECC to s4
PDF
KodekX | Application Modernization Development
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
Machine learning based COVID-19 study performance prediction
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Encapsulation theory and applications.pdf
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PPTX
Big Data Technologies - Introduction.pptx
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Electronic commerce courselecture one. Pdf
PPTX
Cloud computing and distributed systems.
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
cuic standard and advanced reporting.pdf
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Teaching material agriculture food technology
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Per capita expenditure prediction using model stacking based on satellite ima...
sap open course for s4hana steps from ECC to s4
KodekX | Application Modernization Development
Mobile App Security Testing_ A Comprehensive Guide.pdf
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Dropbox Q2 2025 Financial Results & Investor Presentation
Programs and apps: productivity, graphics, security and other tools
Machine learning based COVID-19 study performance prediction
Unlocking AI with Model Context Protocol (MCP)
Encapsulation theory and applications.pdf
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
Big Data Technologies - Introduction.pptx
MYSQL Presentation for SQL database connectivity
Electronic commerce courselecture one. Pdf
Cloud computing and distributed systems.
Digital-Transformation-Roadmap-for-Companies.pptx

Implications of GDPR in Conjunction with UMA

  • 1. © 2017 ForgeRock. All rights reserved. GDPR @hannsnolan ForgeRock Identity Platform! some of the more identity related components of the GDPR
  • 2. © 2017 ForgeRock. All rights reserved. significant penalties for GDPR infractions start on May 25, 2018.
  • 3. © 2016 ForgeRock. All rights reserved. GDPR is different, and FR is different • GDPR applies to every organization selling to or monitoring anyone in the EU • GDPR has a firm deadline (May ‘18), high penalties (4% of global turnover), and high aspirations (human rights) • Privacy tools assess/ensure compliance • GDPR tools target risk teams • We sell to digital teams • Who need to own and drive this challenge -- quickly -- so that it becomes a triumph vs. a tragedy
  • 4. © 2017 ForgeRock. All rights reserved. Impact of GDPR some of the more identity related components of the GDPR • Consent for processing personal data • Proof of Consent (data & processing!) • Consent per purpose (including revocation) • DPO (Data Protection Officer) are required (e.g. external) • DPIAs (Data Protection Impact Assessment) under certain cir. • Data breach notification within 72 hours • Massive data control rights (forgotten, freeze, export rights) • Privacy by default • PLUS organizational/other requirements (out of scope here)
  • 5. © 2017 ForgeRock. All rights reserved. What to take care of? • Personal Data • where is your data? -> least privileged? encryption? • Lawful Processing • law and IDM? YES -> user consent driven! • Individual's Right to Rectification, Export and Erasure • new requirement! Big challenger: export, erasure End user dashboards, registration journeys and consent frameworks will need updating!
  • 6. © 2017 ForgeRock. All rights reserved. What is to do? End user dashboards, registration journeys and consent frameworks will need updating. Don't see it as a compliance exercise! The interesting aspect, is that privacy is now becoming a competitive differentiator.
  • 7. © 2016 ForgeRock. All rights reserved. A holistic view of the ForgeRock Identity Platform Identity data governance; single view of the consumer Giving the consumer a single view of their consents Giving the consumer control over their consents ● Lifecycle management of user profile and data sharing preferences ● Secure storage of profile data ● Anonymised syncing of profile data and connector-based integration to third-party systems ● Data residency and fractional replication ● ToS and privacy policy capture at registration and authentication time ● Social/federated sign-in ● Social registration ● Social consent management ● Interoperable, user-driven, proactive and reactive sharing flows
  • 8. © 2016 ForgeRock. All rights reserved. This is not an “UMA proposal” • UMA is one enabler of a suite of potential capabilities that build on our core platform strengths for a general strategic P&C capability • But it is an important enabler that plays into: • Cloud (loose coupling of APIs/services for building partner ecosystems) • Bilateral service<->user dialog required for ability to deliver explicit consent (stronger definition of consent required by GDPR) • Use cases especially favored by IoT use cases • We can call new/enhanced P&C capabilities/module(s) anything we like
  • 9. © 2017 ForgeRock. All rights reserved. Technical Challenges • Holistic single view of the customer • Consent sharing (legacy backend apps!) • New innovations and trust (Container, Micro Services, Blockchain etc.) • Redesigning/Creating frontends/touchpoints • Keep customer data accurate and protected
  • 10. © 2016 ForgeRock. All rights reserved. Building a (bilateral) trusted digital relationship -- a high-level proposal Single view of the customer Consent lifecycle management Giving the customer context, control, choice, and respect • Existing platform has many strengths • Benefits for compliance are under-marketed (can’t even attempt “right to be forgotten” if you don’t know where all the data is…) • We don’t have packaged solutions targeted to P&C challenges, just a “bag of tools” (KC’s CIAM report) • We don’t have direct P&C solutions today • GDPR has some requirements here • IDM, CAUD, and AM in concert have great potential • Consent Receipts, OAuth, and UMA are relevant standards • We have hints of solutions here (early UMA) • GDPR has some requirements here • UMA is a relevant standard
  • 11. © 2016 ForgeRock. All rights reserved. Patient selectively sharing IoT health data with doctors and other caregivers Patient view Doctor view
  • 12. © 2016 ForgeRock. All rights reserved. Granular consented access by accountant to bank customer’s account data and transactions 12
  • 13. © 2016 ForgeRock. All rights reserved. Consent within IDM and Sync
  • 14. © 2016 ForgeRock. All rights reserved. ForgeRock ForgeRock ForgeRockIdentity ForgeRock Forgerock.com Forgerock.com/blog Thank you
  • 15. © 2017 ForgeRock. All rights reserved. Further Readings • GDPR at ForgeRock • Webinar with Eve Maler • Introduction ForgeRock Identity Platform • The Role of Identity by Simon Moffatt