GDPR
PRIVACY BY DESIGN
A reflection of 6 months GDPR in EU
MICHELANGELO VAN DAM
I'm a senior #php architect, co-founder
and #ceo of @in2itvof, #community leader
at @phpbenelux, coach
at @CoderDojoBelgium, #MVP, #digitalnomad,
likes #coffee.
GDPR
WHAT WAS GDPR AGAIN?
GDPR
WHAT WAS GDPR AGAIN?
Regulate the privacy of EU data subjects
GDPR
WHAT WAS GDPR AGAIN?
Regulate the privacy of EU data subjects
Sanction corporations in violation of GDPR
GDPR
WHAT WAS GDPR AGAIN?
Regulate the privacy of EU data subjects
Sanction corporations in violation of GDPR
Offer a privacy framework for businesses
GDPR
6 MONTHS LATER…
GDPR
6 MONTHS LATER…
Lots of consent e-mailsX
GDPR
6 MONTHS LATER…
Lots of consent e-mailsX
Insufficient staff at DPA’sX
GDPR
6 MONTHS LATER…
Lots of consent e-mailsX
Insufficient staff at DPA’sX
Businesses still neglect regulationX
IS GDPR A FUD?
IS GDPR A FUD?
Promise to increase staff?
IS GDPR A FUD?
Promise to increase staff?
More compliance control?
IS GDPR A FUD?
Promise to increase staff?
More compliance control?
Other GDPR-like regulations outside of EU?
DATA BREACH PROTECTION?
DATA BREACH PROTECTION?
Cases against Facebook, Google & Microsoft
DATA BREACH PROTECTION?
Cases against Facebook, Google & Microsoft
Warnings given for EU violations
DATA BREACH PROTECTION?
Cases against Facebook, Google & Microsoft
International violations not consideredX
Warnings given for EU violations
STATISTICS
Breaches reported between May 25 2018 and January 28 2019
0
4000
8000
12000
16000
Austria
Belgium
Bulgaria
Croatia
Cyprus
Czechia
Denmark
Estonia
Finland
France
Germany
Greece
Hungary
Ireland
Italy
Latvia
Lithuania
Luxembourg
Malta
Netherlands
Poland
Portugal
Romania
Slovakia
Slovenia
Spain
Sweden
UK
Source: BleepingComputer
PERSONAL BREACHES
๏ Sales Intelligence business
๏ Breached on July 23, 2018
๏ 200+ Million records
๏ Data aggregator
PERSONAL BREACHES
NO PERSONAL NOTIFICATION
“Action from Europe not possible”
“Action from Europe not possible”
“Change your password”
THIS GDPR ISSUE WAS FEATURED ON
TROYHUNT.COM
๏ Global hotel chain
๏ November 19, 2018
๏ 500+ Million records breached
๏ Data includes passport numbers
PERSONAL BREACHES
“GBA does not have any information”
“GBA does not have any information”
“Contact Starwood on their data
breach website”
WHY CARE?
It seems nothing changed and things
are what they were before GDPR
PROTECTION CORE
Individual
PROTECTION CORE
Individual
Finance
Health
Religion
Politics
Education
Sex
Identity
Relationship
THE LATEST BREACH
#ProTip:
Register with
haveibeenpwned.com to
be notified when your
data was found in a
breach
WE NEED PROTECTION!
Our identity is at stake!
PRIVACY BY DESIGN
Require minimal personal information
PRIVACY BY DESIGN
Require minimal personal information
PRIVACY BY DESIGN
Encryption on data, storage and networks
Require minimal personal information
PRIVACY BY DESIGN
Encryption on data, storage and networks
Remove data when no longer needed
INTERNATIONAL ADOPTION
INTERNATIONAL ADOPTION
Australia
India
US (California)
Canada
Argentina
Uruguay
New Zealand
South Africa
INTERNATIONAL ADOPTION
INTERNATIONAL ADOPTION
More countries are taking actions
IT’S UP TO THE DEVELOPERS!
IT’S UP TO THE DEVELOPERS!
Learn about (web application) security
IT’S UP TO THE DEVELOPERS!
Learn about (web application) security
Learn about encryption types & techniques
IT’S UP TO THE DEVELOPERS!
Learn about (web application) security
Learn about encryption types & techniques
Add more telemetry in your applications
GREENFIELD PROJECT
GREENFIELD PROJECT
User information
GREENFIELD PROJECT
User information
Location data
GREENFIELD PROJECT
User information
Location data
Advertisements
BROWNFIELD PROJECT
BROWNFIELD PROJECT
Customer data
BROWNFIELD PROJECT
Customer data
Financial records
BROWNFIELD PROJECT
Customer data
Financial records
Employee info
SUMMARY
SUMMARY
GDPR is here to stay
SUMMARY
GDPR is here to stay
Personal information protection goes global
SUMMARY
GDPR is here to stay
Personal information protection goes global
We all have a responsibility to protect data
REFERENCES
Article 25 GDPR ENISA Privacy By Design ICO Data protection
QUESTIONS?
QUESTIONS?
Slides online
slideshare.net/DragonBe
QUESTIONS?
Slides online
slideshare.net/DragonBe
Contact me
twitter.com/DragonBe

Privacy by design