SlideShare a Scribd company logo
1 of 7
1
Enter2020
Panel: Privacy & Cybersecurity
2
About Carnival
9 cruise lines
104 ships
237,000 lower berths
12.5M passengers carried
700 ports visited around the world
21 new ships scheduled to be delivered through 2025
3
Threeof my largerPrivSec headaches
1. Rapidly changing regulatory environments
How to remain compliant
The effect of multiple applicable national laws
2. Data proliferation
Purpose of collection
Nature of data (operational, marketing, medical, criminal etc.)
Processing across international borders
Minimisation and risk-reduction
3. Human error?
Privacy-led culture
Root causes
Proactive vs reactive approaches
4
Theregulatoryand legal environment
On a typical day, we have to take into account:
EU General Data Protection Regulation
Data
Protection
Code
BDSG
UK
Data
Protection
Act 2018
India
Data
Protection
Act 2019
USA
CA CCPA
ME LD946
NV Chap. 603
India
Cyber
Security Act
And all other EU Member States
Canada
7 Provincial
Privacy Laws
Plus many,
many others
Canada
Privacy Act
PIPEDA
5
Dataproliferation
Often unhealthy tension between operational
and analytics needs
Our Insights teams say more data gives better
insight… so all data is collected “just in case”
Q: At what point does “for improving our
services” cease to be credible as a purpose
for retaining data?
Replicated across multiple systems, including
foreign-hosted cloud services
Risk reduction is our primary goal
Q: When do I go on holiday?
Mosaic Group Name Country Living
Mosaic Type Name Rural Vogue
Booking Propensity Model Class High
Fare Type Model Class Select Fare
Lead Time Model Class 0 to 3 Months
Lead Time Second Model Class Over 12 Months
Ship Model Class Ventura
Ship Second Model Class Britannia
Cabin Inside Model Class Low
Cabin Outside Model Class Low
Cabin Balcony Model Class Medium
Cabin Suite Model Class High
Trade Atlantic Islands Or Coast Model ClassHigh
Trade Baltic Model Class Low
Trade Norway Fjords Model Class Medium
“Number 5 need more input!”
Customer propensity model
(partial) of a VIP customer
6
Humanerror?
Privacy-supporting culture is vital – no blame!
We investigate and classify root cause in three
high-level categories:
Human error
“I misheard their email address on the phone”
Human error controls could have prevented
“I wrote the wrong address on the envelope”
“We linked incorrect holidays” (back-to-back)
System error
“Accented characters are ignored”
Both proactive and reactive approaches
essential – light-touch Problem Management
0
5
10
15
20
25
30
35
Incidentvolume
Incident, near miss and identified opportunity by month
New Inc Closed Inc Open at EOM
Nature of incidents reported 2018-2019
Human error System error
7
Thankyou!
Any questions?


More Related Content

Similar to Panel 8-Carnival uk

The State of International Mailing and Shipping
The State of International Mailing and ShippingThe State of International Mailing and Shipping
The State of International Mailing and Shipping
Krish Iyer
 
Review DNI WTAs for 2015 and 2016 (see attached). Compare and con.docx
Review DNI WTAs for 2015 and 2016 (see attached). Compare and con.docxReview DNI WTAs for 2015 and 2016 (see attached). Compare and con.docx
Review DNI WTAs for 2015 and 2016 (see attached). Compare and con.docx
ronak56
 

Similar to Panel 8-Carnival uk (20)

The State of International Mailing and Shipping
The State of International Mailing and ShippingThe State of International Mailing and Shipping
The State of International Mailing and Shipping
 
Bo e v1.0
Bo e v1.0Bo e v1.0
Bo e v1.0
 
Presentation to Legislative Committee on Economic Development & International...
Presentation to Legislative Committee on Economic Development & International...Presentation to Legislative Committee on Economic Development & International...
Presentation to Legislative Committee on Economic Development & International...
 
Change is the New Norm. Adapt or Die. Disruptive Technology (and Technology t...
Change is the New Norm. Adapt or Die. Disruptive Technology (and Technology t...Change is the New Norm. Adapt or Die. Disruptive Technology (and Technology t...
Change is the New Norm. Adapt or Die. Disruptive Technology (and Technology t...
 
Review DNI WTAs for 2015 and 2016 (see attached). Compare and con.docx
Review DNI WTAs for 2015 and 2016 (see attached). Compare and con.docxReview DNI WTAs for 2015 and 2016 (see attached). Compare and con.docx
Review DNI WTAs for 2015 and 2016 (see attached). Compare and con.docx
 
Corporate Treasurers Focus on Cyber Security
Corporate Treasurers Focus on Cyber SecurityCorporate Treasurers Focus on Cyber Security
Corporate Treasurers Focus on Cyber Security
 
Pmac Cfo Procurement 2006
Pmac Cfo Procurement 2006Pmac Cfo Procurement 2006
Pmac Cfo Procurement 2006
 
SFScon 22 - Paolo Pinto - Real Life Data Anonymization.pdf
SFScon 22 - Paolo Pinto - Real Life Data Anonymization.pdfSFScon 22 - Paolo Pinto - Real Life Data Anonymization.pdf
SFScon 22 - Paolo Pinto - Real Life Data Anonymization.pdf
 
Challenges in the Business and Law of Cybersecurity, CLEAR Cyber Conference, ...
Challenges in the Business and Law of Cybersecurity, CLEAR Cyber Conference, ...Challenges in the Business and Law of Cybersecurity, CLEAR Cyber Conference, ...
Challenges in the Business and Law of Cybersecurity, CLEAR Cyber Conference, ...
 
Upsc carrier research liability whitepaper
Upsc carrier research liability whitepaperUpsc carrier research liability whitepaper
Upsc carrier research liability whitepaper
 
Drawing And Writing Paper. Online assignment writing service.
Drawing And Writing Paper. Online assignment writing service.Drawing And Writing Paper. Online assignment writing service.
Drawing And Writing Paper. Online assignment writing service.
 
Cyber attack response from the CEO perspective - Tallinn Estonia - Short Simu...
Cyber attack response from the CEO perspective - Tallinn Estonia - Short Simu...Cyber attack response from the CEO perspective - Tallinn Estonia - Short Simu...
Cyber attack response from the CEO perspective - Tallinn Estonia - Short Simu...
 
Essay About Background
Essay About BackgroundEssay About Background
Essay About Background
 
Fraud management optimisation
Fraud management optimisation Fraud management optimisation
Fraud management optimisation
 
The Changing Landscape of Cyber Liability
The Changing Landscape of Cyber LiabilityThe Changing Landscape of Cyber Liability
The Changing Landscape of Cyber Liability
 
WCIT 2014 Matt Stamper - Information Assurance in a Global Context
WCIT 2014 Matt Stamper - Information Assurance in a Global ContextWCIT 2014 Matt Stamper - Information Assurance in a Global Context
WCIT 2014 Matt Stamper - Information Assurance in a Global Context
 
NSTIC and IDESG Update
NSTIC and IDESG UpdateNSTIC and IDESG Update
NSTIC and IDESG Update
 
Australia: Taking Bigger Steps | A.T. Kearney
Australia: Taking Bigger Steps | A.T. KearneyAustralia: Taking Bigger Steps | A.T. Kearney
Australia: Taking Bigger Steps | A.T. Kearney
 
Crossing the streams: How security professionals can leverage the NZ Privacy ...
Crossing the streams: How security professionals can leverage the NZ Privacy ...Crossing the streams: How security professionals can leverage the NZ Privacy ...
Crossing the streams: How security professionals can leverage the NZ Privacy ...
 
Wolfgang Essentials 2016 - Constantin Gurdgiev - The Online Economy
Wolfgang Essentials 2016 - Constantin Gurdgiev - The Online EconomyWolfgang Essentials 2016 - Constantin Gurdgiev - The Online Economy
Wolfgang Essentials 2016 - Constantin Gurdgiev - The Online Economy
 

Recently uploaded

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

Recently uploaded (20)

MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024
 
Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 

Panel 8-Carnival uk

  • 2. 2 About Carnival 9 cruise lines 104 ships 237,000 lower berths 12.5M passengers carried 700 ports visited around the world 21 new ships scheduled to be delivered through 2025
  • 3. 3 Threeof my largerPrivSec headaches 1. Rapidly changing regulatory environments How to remain compliant The effect of multiple applicable national laws 2. Data proliferation Purpose of collection Nature of data (operational, marketing, medical, criminal etc.) Processing across international borders Minimisation and risk-reduction 3. Human error? Privacy-led culture Root causes Proactive vs reactive approaches
  • 4. 4 Theregulatoryand legal environment On a typical day, we have to take into account: EU General Data Protection Regulation Data Protection Code BDSG UK Data Protection Act 2018 India Data Protection Act 2019 USA CA CCPA ME LD946 NV Chap. 603 India Cyber Security Act And all other EU Member States Canada 7 Provincial Privacy Laws Plus many, many others Canada Privacy Act PIPEDA
  • 5. 5 Dataproliferation Often unhealthy tension between operational and analytics needs Our Insights teams say more data gives better insight… so all data is collected “just in case” Q: At what point does “for improving our services” cease to be credible as a purpose for retaining data? Replicated across multiple systems, including foreign-hosted cloud services Risk reduction is our primary goal Q: When do I go on holiday? Mosaic Group Name Country Living Mosaic Type Name Rural Vogue Booking Propensity Model Class High Fare Type Model Class Select Fare Lead Time Model Class 0 to 3 Months Lead Time Second Model Class Over 12 Months Ship Model Class Ventura Ship Second Model Class Britannia Cabin Inside Model Class Low Cabin Outside Model Class Low Cabin Balcony Model Class Medium Cabin Suite Model Class High Trade Atlantic Islands Or Coast Model ClassHigh Trade Baltic Model Class Low Trade Norway Fjords Model Class Medium “Number 5 need more input!” Customer propensity model (partial) of a VIP customer
  • 6. 6 Humanerror? Privacy-supporting culture is vital – no blame! We investigate and classify root cause in three high-level categories: Human error “I misheard their email address on the phone” Human error controls could have prevented “I wrote the wrong address on the envelope” “We linked incorrect holidays” (back-to-back) System error “Accented characters are ignored” Both proactive and reactive approaches essential – light-touch Problem Management 0 5 10 15 20 25 30 35 Incidentvolume Incident, near miss and identified opportunity by month New Inc Closed Inc Open at EOM Nature of incidents reported 2018-2019 Human error System error

Editor's Notes

  1. From the latest published annual report (FY18) UK brands alone are going to see over 12,000 lower berths added in the next 3 years with our Excel and Pinnacle-class ships.
  2. Mention marketing laws (PECR in full) UK headquartered company … but also American Ships are registered in a number of flag states – international waters Within 12NM of land that country’s law applies Our guests are global - they might form contract in another country though Our crew are global, but employment contract may be via a manning company in another country. Consider most difficult issues on an ad-hoc basis
  3. Lifetime value etc
  4. What is an incident? A breach or other misprocessing of personal data 97 incidents reported to the Privacy team in 2018, 10 of which came to the attention of the ICO. We can only report on the ones we’re told about.
  5. Team to wave hello