Successfully reported this slideshow.
We use your LinkedIn profile and activity data to personalize ads and to show you more relevant ads. You can change your ad preferences anytime.

2019 | An Interoperable Personal Data Receipt Ecosystem in Practice | Identiverse | Day 4, June 28

144 views

Published on

This LIVE DEMO shows six Kantara Initiative Working Group participants’ products interoperating to generate, store, present, and act on Personal Data Receipts. We have assembled a non-commercial Privacy Control Panel system and want to show it off to you!
Today, online service providers get information from or about you so that they can provide services. New privacy and data protection regulations have been coming into effect, which increase the requirement for notice, transparency and accountability when your data is collected and processed. Service providers are required to keep records about their terms of service and your agreement.
At their core, these regulations embody variations of the OECD basic principles of privacy protection which suggest the obligations of providers and the rights of the individual.
There are very few tools available to the individual internet user to help them understand, manage and control their online information.
This creates a power imbalance if one wants to go back later and exercise rights with respect to data – because you probably don’t remember who, what, where, when and how the service provider got your information.
There’s a solution!
Imagine if the service provider offered you a “Personal Data Receipt”. This receipt would include timestamps, the contents of the privacy notice you saw, what data was collected for what purposes, conditions like ‘delete-by-date’ instructions, and other useful facts. Just like a store checkout receipt, if there’s an issue later on or if you want to look back to see what you did last year, you can open up the receipt and take action.
In 2018, Kantara Initiative published the “Consent Receipt Specification v1.1” which is an interoperable Personal Data Receipt specification tailored to a specific legal basis for processing. This demo shows real products in action working with these receipts.

Published in: Technology
  • Be the first to comment

  • Be the first to like this

2019 | An Interoperable Personal Data Receipt Ecosystem in Practice | Identiverse | Day 4, June 28

  1. 1. Privacy Control Panel A live demonstration for Identiverse June 2019 Andrew Hughes AndrewHughes3000@gmail.com Leadership CouncilChair, Kantara Initiative 1Copyright © 2019 Kantara Initiative Inc.
  2. 2. 2 » PersonalData(Consent) Receipt » TheKantaraInitiative PrivacyControlPanelDemo » Demosof ProductsShowing Receipts » KantaraInitiativeConsent& InformationSharingWork Group Copyright © 2019 Kantara Initiative Inc.
  3. 3. 3 A simpleapproach A standardizeddata format A basis for invention& innovation Copyright © 2019 Kantara Initiative Inc.
  4. 4. WHAT IS A RECEIPT? 4Copyright © 2019 Kantara Initiative Inc.
  5. 5. 5 Asalesreceipt is: » A personalrecord » Independent of the receipt issuer » Evidence of the event » Containsinteraction‘metadata’ » Timestamps, Contact information, Verification codes » Transaction details, Cryptographic elements & signatures » Points to or containsissuer’s policy statements Copyright © 2019 Kantara Initiative Inc.
  6. 6. RECEIPTS AND THE ‘AGREEMENT FLOW’ 6Copyright © 2019 Kantara Initiative Inc.
  7. 7. 7Copyright © 2019 Kantara Initiative Inc.
  8. 8. 8Copyright © 2019 Kantara Initiative Inc.
  9. 9. 9Copyright © 2019 Kantara Initiative Inc.
  10. 10. 10Copyright © 2019 Kantara Initiative Inc.
  11. 11. 11Copyright © 2019 Kantara Initiative Inc.
  12. 12. 12Copyright © 2019 Kantara Initiative Inc.
  13. 13. 13Copyright © 2019 Kantara Initiative Inc. The ‘agreementflow’ illustratesimportant interactions » Offer—acceptterms » ‘Meeting of the minds’ » Intent to enter intoagreement » Record keeping » Exchange of ‘valuableconsideration’
  14. 14. 14Copyright © 2019 Kantara Initiative Inc. Salesreceiptsare requiredby law (AUS,NZ, others) or bycustom Why not Personal Data Receipts?
  15. 15. 15 Whenpersonal data is involved: » PrivacyNotice » Privacy Statement » Purpose of processing » Data controller contact information » PLUS Additional detailsthatare very familiarto Data ProtectionOfficers (but not to regular people) Copyright © 2019 Kantara Initiative Inc.
  16. 16. 16Copyright © 2019 Kantara Initiative Inc. The Kantara Initiative Consent Receipt * Privacy Statement & Notice Personal Data Receipt* Data Subject Rights
  17. 17. 17Copyright © 2019 Kantara Initiative Inc. The ‘agreementflow’ illustrates that theindependentpersonal record-keepingfunction is not supported fordata-related interactions!
  18. 18. 18 Apersonal data receiptis: » A personalrecord » Independent of the receipt issuer » Evidence of the event » Containsinteraction‘metadata’ » Timestamps, Contact information, Verification codes » Transaction details, Cryptographic elements & signatures » Points to or containsissuer’s policy statements Copyright © 2019 Kantara Initiative Inc.
  19. 19. 19 Standardized Personal Data Receipts offered to you whenever you agree to personal dataprocessing willhelp enable a product ecosystem that assists you to exercise your data rights… Copyright © 2019 Kantara Initiative Inc.
  20. 20. THE KANTARA INITIATIVE CONSENT RECEIPT SPECIFICATION V1.1 20Copyright © 2019 Kantara Initiative Inc.
  21. 21. Copyright © 2019 Kantara Initiative Inc. 21
  22. 22. A Consent Receipt ;-) {"version":"KI-CR-v1.1.0","jurisdiction":"GB","consentTimestamp":1513086888,"collection Method":"Consentua","consentReceiptID":"132553a7-5599-46c7-8af1-7975a50f6a5c", "piiPrincipalId":"Coops","piiControllers":[{"piiController":"KamesCapital","contact":"IainHenderson","address":{"streetAddress":"Kames Capitalplc PO Box3733 RoyalWoottonBassett SN44BG United Kingdom","addressLocality":null,"postOfficeBoxNumber": null,"postalCode":null,"addressCountry":null},"email":"iain.henderson@kamescapital.com","phone":"0800358 3009 "}],"services":[{"service":"KamesCapital", "purposes":[{"purpose":"Usedbythe financialregulator","consentType":"EXPLICIT", "purposeCategory":["SalesTracking"],"piiCategory":["SalesTracking"],"termination": "www.consentua.com/terminaton","thirdPartyDisclosure":false,"thirdPartyName":""},{"purpose":"UsedbyAegon Asset Management to encourageyoutosee if theirproductscan help youmeet yourfinancialgoals andobjectives.","consentType” :"EXPLICIT","purposeCategory":["Marketing"],"piiCategory":["Marketing"],"termination": "www.consentua.com/terminaton","thirdPartyDisclosure":false,"thirdPartyName":"AegonAsset Management"}]}], "policyUrl":"https://www.kamescapital.com/privacy.aspx","sensitive":false,"spiCat":null} Copyright © 2019 Kantara Initiative Inc. 22
  23. 23. Copyright © 2019 Kantara Initiative Inc. 23
  24. 24. 24Copyright © 2019 Kantara Initiative Inc.
  25. 25. Demonstrations of Receipt Implementations KantaraConsent Receipts in Action Copyright © 2019 Kantara Initiative Inc. 25
  26. 26. FeaturingKantaraMembers Copyright © 2019 Kantara Initiative Inc. 26
  27. 27. Kantara Privacy Control Panel: Consentua PaperCup Shop+ UbisecureAPI & Control Panel KantaraConsent Receipts in Action Copyright © 2019 Kantara Initiative Inc. 28
  28. 28. THE ‘PRIVACY CONTROL PANEL’ DEMONARRATIVE 29Copyright © 2019 Kantara Initiative Inc.
  29. 29. Imaginein a few months: you have‘agreed’at 500 services Copyright © 2019 Kantara Initiative Inc. 30
  30. 30. Now What? Copyright © 2019 Kantara Initiative Inc. 31
  31. 31. Use Your KantaraInitiative PrivacyControlPanel! (ofcourse) Copyright © 2019 Kantara Initiative Inc. 32
  32. 32. 33Copyright © 2019 Kantara Initiative Inc.
  33. 33. The Simple Demo GET STORE VIEW Copyright © 2019 Kantara Initiative Inc. 34
  34. 34. Transmute Industries Driver-Shipper Proof KantaraConsent Receipts in Action Copyright © 2019 Kantara Initiative Inc. 35
  35. 35. 36Copyright © 2019 Kantara Initiative Inc.
  36. 36. IDENTOS Federated Privacy Exchange KantaraConsent Receipts in Action Copyright © 2019 Kantara Initiative Inc. 37
  37. 37. About IDENTOS Products In  Mobile authentication  Data encryption  Compliance management Segments ◇ Healthcare ◇ Government ◇ Finance ◇ Education ◇ IoT ◇ B2C Community of Practice Copyright © 2019 Kantara Initiative Inc. 38
  38. 38. We. Put people first to protect & authorize access to (Private) data beyond the enterprise. Authenticate Digital Identities across a zero- knowledge Privacy respecting UMA 2.0 Server Enable Trusted Digital Ecosystems & Marketplaces Anywhere. Anytime. Provide Explicit Compliance with Authorization & Consent management On-demand Distribute Security with decentralized access in a Mobile Wallet Copyright © 2019 Kantara Initiative Inc. 39
  39. 39. FPX Architecture Service Providers Banting App Electronic Health Records Personal Health Record Consent Receipt Shoebox FPX Resource Servers Hospitals Digital Services Copyright © 2019 Kantara Initiative Inc. 40
  40. 40. WhyWe Use ConsentReceipts Our use cases Notice, Consent & policy management Legal & regulatory compliance History & revocation User Choice Standard data model (+ API) Presentation UI/UX challenges during notice Consistency between platforms Actionable history User choice of ‘shoebox’ providers Copyright © 2019 Kantara Initiative Inc. 41
  41. 41. FPX Demo-Usea ServiceProvider 1 3 4 Electronic Health Record Authorized Data CR Shoebox Banting App 2 Copyright © 2019 Kantara Initiative Inc. 42
  42. 42. Demo-1 Year Later 1 FPX Banting App Copyright © 2019 Kantara Initiative Inc. 43
  43. 43. Demo Copyright © 2019 Kantara Initiative Inc. 44
  44. 44. Functionalityon Web Copyright © 2019 Kantara Initiative Inc. 45
  45. 45. Contact Info& Links https://identos.com Twitter: @identos_inc Email:alec@identos.ca Twitter: @aleclaws Copyright © 2019 Kantara Initiative Inc. 46
  46. 46. Sphere Identity Customer Onboarding KantaraConsent Receipts in Action Copyright © 2019 Kantara Initiative Inc. 47
  47. 47. 48Copyright © 2019 Kantara Initiative Inc.
  48. 48. OpenConsent Open Notice Network KantaraConsent Receipts in Action Copyright © 2019 Kantara Initiative Inc. 49
  49. 49. digi.me Consent Mobility Dashboard KantaraConsent Receipts in Action Copyright © 2019 Kantara Initiative Inc. 50
  50. 50. 51Copyright © 2019 Kantara Initiative Inc. Automatic Receipt Generation& Offer  Definethe‘Shoebox’ API  Sites should offer receipts by default  Develop browser add-ons to convert existinginformation to Kantara standard receipt  Once people have many receipts, apps can be inventedfor management,control and action
  51. 51. Datafund.io ReceiptGenerator API KantaraConsent Receipts in Action Copyright © 2019 Kantara Initiative Inc. 52
  52. 52. Datafund.io Receipt Generator https://youtu.be/vZJuaQoLilI 53Copyright © 2019 Kantara Initiative Inc.
  53. 53. 54Copyright © 2019 Kantara Initiative Inc.
  54. 54. WHAT HAPPENS NEXT? 55Copyright © 2019 Kantara Initiative Inc.
  55. 55. 56Copyright © 2019 Kantara Initiative Inc. Next work items  Discover more implementations  Next version of the specification  Functional & structural updates  Additional use case requirements  Specification update project has started  Introduce personal data receipt concept to Privacy Engineeringcommunity  Adapt/adopt controlled vocabularies (e.g. W3C DPV)
  56. 56. 57Copyright © 2019 Kantara Initiative Inc. Known Implementations Tell us about your project! kantarainitiative.org/confluence/display/infosharing
  57. 57. Kantara Initiative Groups Contact Kantara Initiative: - the global consortium improving trustworthy use of identity and personal data kantarainitiative.org kantarainitiative.org/membership/ colin@kantarainitiative.org Consent & Information Sharing WG: - Consent Receipt specification - Interop demo development - Data sharing specifications kantarainitiative.org/confluence/display/infosharing andrewhughes3000@gmail.com JOIN: https://kantarainitiative.org/gpa-signup/?selectedGroup=3 Consent Practices WG: - Common practices for consent management kantarainitiative.org/confluence/display/consentmanagement andrewhughes3000@gmail.com JOIN: https://kantarainitiative.org/gpa-signup/?selectedGroup=40 Copyright © 2019 Kantara Initiative Inc. 58
  58. 58. Nurture. Develop. Operate. – that’s what we do Colin Wallis,Executive Director colin@kantarainitiative.org Twitter: @KantaraColin, @KantaraNews Join us at https://kantarainitiative.org/membership/ Ethics & Conformance Trust Marked 59Copyright © 2019 Kantara Initiative Inc.

×