SlideShare a Scribd company logo
1 of 11
Download to read offline
© Qentinel Group 2017 PUBLIC 1
GDPR and Test Data Challenge
Antti Heimola (Kalle Huttunen) 4.5.2017, Test Automation Clinic
© Qentinel Group 2017 PUBLIC 2
Purpose
of the presentation is to highlight some things to be done, before May-
25, 2018, because General Data Protection Regulation (GDPR) will
replace Data Protection Directive (1995). Test data management is
one of the topic to be taken care of.
“The primary objectives of the GDPR are to give citizens and residents
back control of their personal data and to simplify the regulatory
environment for international business by unifying the regulation within
the EU.”
https://en.wikipedia.org/wiki/General_Data_Protection_Regulation
© Qentinel Group 2017 PUBLIC 3
Main Differences 1995  2018
1. Personal Data Redefined
• Broader definition: mobile device identifiers, social identity, economic status, etc.
2. Individual Rights
• Right to access
• Right to be forgotten
• Terms of agreements (may) need to updated
3. Data Controllers vs. Data Processors
• DPD - only data controllers were held accountable
• Data Protection Officer (DPO) may need to be appointed
• Data protection policy and data processing activity record (>250)
• Impact assessments in case of high risk of data breach
https://britishlegalitforum.com/wp-content/uploads/2017/02/GDPR-Whitepaper-British-Legal-Technology-Forum-2017-Sponsor.pdf
© Qentinel Group 2017 PUBLIC 4
Main Differences 1995  2018
4. Information Governance and Security - Privacy by design
• Privacy of data collected is taken into account at all steps of business processes
• Impact assessments for automated data processing activities
5. Data Breach Notification and Penalties
• Notification of a personal data breach within 72 hours
• Penalties 4% of the global turnover, or 20M€
• lacking consent to process data or violating privacy by design
• Penalties 2% of the global turnover
• records not in order or not notifying the supervisory authority
6. Global Impact
• Company that markets goods/services to EU residents can be subject to GDPR
https://britishlegalitforum.com/wp-content/uploads/2017/02/GDPR-Whitepaper-British-Legal-Technology-Forum-2017-Sponsor.pdf
© Qentinel Group 2017 PUBLIC 5
Common Test Data Management Problems
• Production data is too big to copy, slow, and expensive
• Test data is not available at the speed needed in agile
development and DevOps
• Data in test environments are shared and that makes test results
unreliable
• Production data is sensitive and cannot be used
© Qentinel Group 2017 PUBLIC 6
Used solution
Production data is too big to copy, slow, and expensive
• Use subsets of production data
 Finding and selecting subsets is time consuming
 Test coverage is not as good as with full data
© Qentinel Group 2017 PUBLIC 7
Used solution
Data in test environments are shared and that makes test results
unreliable
• Follow process where certain data is reserved for certain people/project
 If process is not followed, it is easy to mess up test results
 Refresh not possible when wanted
• Follow process where whole environment is reserved people/project
 If process not followed it is easy to mess up test results
 Limits people/projects that can test in parallel
 Refresh not possible when wanted
© Qentinel Group 2017 PUBLIC 8
Used solution
Production data contains sensitive information
• Limit access to certain persons that have hard NDAs
 Only these persons can perform testing
• Use synthetic test data (subset of anonymized data)
 Synthetic test data is not as good as real data
• Masking production data
Data integrity can suffer if design not done properly
© Qentinel Group 2017 PUBLIC 9
Solutions used today are not optimal
• Expensive
• Limiting speed of testing
• Limiting volume of testing
• Limiting test coverage
• Limiting use of effective use of test automation and CI/CD
• Affecting reliability of test results
• Generating additional manual work
• GDPR non-compliance
© Qentinel Group 2017 PUBLIC 10
Penalties
Data
portability
Right to be
forgotten
Items for the Discussion Session
Privacy
by design
Plan for data
security
breaches
Obligations
as a Data
Processor
How to manage test data
Readable and
understandable
user agreements
Right to
access
Data
Controller
obligations
Impact
assessment
Need for
DPO
Rights of data
subjects – how to
deal with difficult
individuals
© Qentinel Group 2017 PUBLIC 11
ContactQentinel Group
www.qentinel.com kalle.huttunen@qentinel.com

More Related Content

What's hot

Building a Foundation for Proactive and Predictive Pharmacovigilance
Building a Foundation for Proactive and Predictive PharmacovigilanceBuilding a Foundation for Proactive and Predictive Pharmacovigilance
Building a Foundation for Proactive and Predictive PharmacovigilanceVeeva Systems
 
Jameel marketing presentation
Jameel marketing presentationJameel marketing presentation
Jameel marketing presentationAhamed Jameel
 
What to Expect When Migrating: A Walk Through a Clinical Data Migration (2017)
What to Expect When Migrating: A Walk Through a Clinical Data Migration (2017)What to Expect When Migrating: A Walk Through a Clinical Data Migration (2017)
What to Expect When Migrating: A Walk Through a Clinical Data Migration (2017)Julie Champagne
 
Accelerometer data processing with GGIR - a success story in Research Software
Accelerometer data processing with GGIR - a success story in Research SoftwareAccelerometer data processing with GGIR - a success story in Research Software
Accelerometer data processing with GGIR - a success story in Research SoftwareVincent van Hees
 
Applied data analytics_v1_6.23
Applied data analytics_v1_6.23Applied data analytics_v1_6.23
Applied data analytics_v1_6.23John C. Havens
 
Tell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KC
Tell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KCTell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KC
Tell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KCKevin Perry
 
Pistoia Alliance USA Conference 2016
Pistoia Alliance USA Conference 2016Pistoia Alliance USA Conference 2016
Pistoia Alliance USA Conference 2016Pistoia Alliance
 
Growth Opportunities for Entrepreneurs in Clinical Research Services
Growth Opportunities for Entrepreneurs in Clinical Research ServicesGrowth Opportunities for Entrepreneurs in Clinical Research Services
Growth Opportunities for Entrepreneurs in Clinical Research ServicesCraig Lipset
 
Pistoia Alliance USA Conference 2016
Pistoia Alliance USA Conference 2016Pistoia Alliance USA Conference 2016
Pistoia Alliance USA Conference 2016Pistoia Alliance
 
The Industry’s Move Toward Digitally Connected Clinical Trials
The Industry’s Move Toward Digitally Connected Clinical TrialsThe Industry’s Move Toward Digitally Connected Clinical Trials
The Industry’s Move Toward Digitally Connected Clinical TrialsVeeva Systems
 
NIHCollaboratoryGrandRounds_26Jul2019 [Lipset]
NIHCollaboratoryGrandRounds_26Jul2019 [Lipset]NIHCollaboratoryGrandRounds_26Jul2019 [Lipset]
NIHCollaboratoryGrandRounds_26Jul2019 [Lipset]Craig Lipset
 
Delivering Healthcare Solutions to Combat the Spread of COVID-19
Delivering Healthcare Solutions to Combat the Spread of COVID-19Delivering Healthcare Solutions to Combat the Spread of COVID-19
Delivering Healthcare Solutions to Combat the Spread of COVID-19Cassia Networks
 
Pistoia Alliance USA Conference 2016
Pistoia Alliance USA Conference 2016Pistoia Alliance USA Conference 2016
Pistoia Alliance USA Conference 2016Pistoia Alliance
 
Gp p4c risk management of home intelligence system
Gp p4c risk management of home intelligence systemGp p4c risk management of home intelligence system
Gp p4c risk management of home intelligence systemAmitkumar Singalwar
 
Toby Basey-Fisher , CEO, Co Founder, Eva Diagnostics
Toby Basey-Fisher , CEO, Co Founder, Eva DiagnosticsToby Basey-Fisher , CEO, Co Founder, Eva Diagnostics
Toby Basey-Fisher , CEO, Co Founder, Eva DiagnosticsInvestnet
 
We are Alert but Should We Be Alarmed
We are Alert but Should We Be AlarmedWe are Alert but Should We Be Alarmed
We are Alert but Should We Be AlarmedARDC
 
Improving Clinical Trial Performance: Part 2 - A Unified Approach for Improvi...
Improving Clinical Trial Performance: Part 2 - A Unified Approach for Improvi...Improving Clinical Trial Performance: Part 2 - A Unified Approach for Improvi...
Improving Clinical Trial Performance: Part 2 - A Unified Approach for Improvi...Veeva Systems
 
Covenant Health Care
Covenant Health CareCovenant Health Care
Covenant Health CareMitchel Nolan
 

What's hot (20)

Building a Foundation for Proactive and Predictive Pharmacovigilance
Building a Foundation for Proactive and Predictive PharmacovigilanceBuilding a Foundation for Proactive and Predictive Pharmacovigilance
Building a Foundation for Proactive and Predictive Pharmacovigilance
 
Jameel marketing presentation
Jameel marketing presentationJameel marketing presentation
Jameel marketing presentation
 
What to Expect When Migrating: A Walk Through a Clinical Data Migration (2017)
What to Expect When Migrating: A Walk Through a Clinical Data Migration (2017)What to Expect When Migrating: A Walk Through a Clinical Data Migration (2017)
What to Expect When Migrating: A Walk Through a Clinical Data Migration (2017)
 
Accelerometer data processing with GGIR - a success story in Research Software
Accelerometer data processing with GGIR - a success story in Research SoftwareAccelerometer data processing with GGIR - a success story in Research Software
Accelerometer data processing with GGIR - a success story in Research Software
 
Applied data analytics_v1_6.23
Applied data analytics_v1_6.23Applied data analytics_v1_6.23
Applied data analytics_v1_6.23
 
Tell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KC
Tell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KCTell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KC
Tell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KC
 
Pistoia Alliance USA Conference 2016
Pistoia Alliance USA Conference 2016Pistoia Alliance USA Conference 2016
Pistoia Alliance USA Conference 2016
 
Growth Opportunities for Entrepreneurs in Clinical Research Services
Growth Opportunities for Entrepreneurs in Clinical Research ServicesGrowth Opportunities for Entrepreneurs in Clinical Research Services
Growth Opportunities for Entrepreneurs in Clinical Research Services
 
2010 One Page Ad
2010 One Page Ad2010 One Page Ad
2010 One Page Ad
 
Pistoia Alliance USA Conference 2016
Pistoia Alliance USA Conference 2016Pistoia Alliance USA Conference 2016
Pistoia Alliance USA Conference 2016
 
The Industry’s Move Toward Digitally Connected Clinical Trials
The Industry’s Move Toward Digitally Connected Clinical TrialsThe Industry’s Move Toward Digitally Connected Clinical Trials
The Industry’s Move Toward Digitally Connected Clinical Trials
 
NIHCollaboratoryGrandRounds_26Jul2019 [Lipset]
NIHCollaboratoryGrandRounds_26Jul2019 [Lipset]NIHCollaboratoryGrandRounds_26Jul2019 [Lipset]
NIHCollaboratoryGrandRounds_26Jul2019 [Lipset]
 
Delivering Healthcare Solutions to Combat the Spread of COVID-19
Delivering Healthcare Solutions to Combat the Spread of COVID-19Delivering Healthcare Solutions to Combat the Spread of COVID-19
Delivering Healthcare Solutions to Combat the Spread of COVID-19
 
Pistoia Alliance USA Conference 2016
Pistoia Alliance USA Conference 2016Pistoia Alliance USA Conference 2016
Pistoia Alliance USA Conference 2016
 
Gp p4c risk management of home intelligence system
Gp p4c risk management of home intelligence systemGp p4c risk management of home intelligence system
Gp p4c risk management of home intelligence system
 
Toby Basey-Fisher , CEO, Co Founder, Eva Diagnostics
Toby Basey-Fisher , CEO, Co Founder, Eva DiagnosticsToby Basey-Fisher , CEO, Co Founder, Eva Diagnostics
Toby Basey-Fisher , CEO, Co Founder, Eva Diagnostics
 
We are Alert but Should We Be Alarmed
We are Alert but Should We Be AlarmedWe are Alert but Should We Be Alarmed
We are Alert but Should We Be Alarmed
 
Identifying critical security controls
Identifying critical security controlsIdentifying critical security controls
Identifying critical security controls
 
Improving Clinical Trial Performance: Part 2 - A Unified Approach for Improvi...
Improving Clinical Trial Performance: Part 2 - A Unified Approach for Improvi...Improving Clinical Trial Performance: Part 2 - A Unified Approach for Improvi...
Improving Clinical Trial Performance: Part 2 - A Unified Approach for Improvi...
 
Covenant Health Care
Covenant Health CareCovenant Health Care
Covenant Health Care
 

Similar to GDPR and test data challenge Antti Heimola 20170504

Partner enablement GDPR
Partner enablement GDPRPartner enablement GDPR
Partner enablement GDPRJuan Niekerk
 
Partner enablement GDPR
Partner enablement GDPRPartner enablement GDPR
Partner enablement GDPRJuan Niekerk
 
De groote de man Ingrid de Poorter
De groote de man Ingrid de PoorterDe groote de man Ingrid de Poorter
De groote de man Ingrid de PoorterBigDataExpo
 
How to turn GDPR into a Strategic Advantage using Connected Data
How to turn GDPR into a Strategic Advantage using Connected DataHow to turn GDPR into a Strategic Advantage using Connected Data
How to turn GDPR into a Strategic Advantage using Connected DataNeo4j
 
Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...
Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...
Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...Denodo
 
Data- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerData- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerCapgemini
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firmsaccenture
 
Solving the Data Management Challenge for Healthcare
Solving the Data Management Challenge for HealthcareSolving the Data Management Challenge for Healthcare
Solving the Data Management Challenge for HealthcareDelphix
 
GDPR Noncompliance: Avoid the Risk with Data Virtualization
GDPR Noncompliance: Avoid the Risk with Data VirtualizationGDPR Noncompliance: Avoid the Risk with Data Virtualization
GDPR Noncompliance: Avoid the Risk with Data VirtualizationDenodo
 
¿En qué se parece el Gobierno del Dato a un parque de atracciones?
¿En qué se parece el Gobierno del Dato a un parque de atracciones?¿En qué se parece el Gobierno del Dato a un parque de atracciones?
¿En qué se parece el Gobierno del Dato a un parque de atracciones?Denodo
 
GDPR Readiness for Software Usage Analytics
GDPR Readiness for Software Usage AnalyticsGDPR Readiness for Software Usage Analytics
GDPR Readiness for Software Usage AnalyticsRevulytics Inc.
 
Building the Business Case for TPRM - DVV Solutions Breakfast Briefing March ...
Building the Business Case for TPRM - DVV Solutions Breakfast Briefing March ...Building the Business Case for TPRM - DVV Solutions Breakfast Briefing March ...
Building the Business Case for TPRM - DVV Solutions Breakfast Briefing March ...DVV Solutions Third Party Risk Management
 
Delivering Analytics at Scale with a Governed Data Lake
Delivering Analytics at Scale with a Governed Data LakeDelivering Analytics at Scale with a Governed Data Lake
Delivering Analytics at Scale with a Governed Data LakeJean-Michel Franco
 
CIO WaterCooler Focus: GDPR - James Duthie
CIO WaterCooler Focus: GDPR - James DuthieCIO WaterCooler Focus: GDPR - James Duthie
CIO WaterCooler Focus: GDPR - James DuthieAndrew Pryor
 
General Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) ComplianceGeneral Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) Complianceaccenture
 
Getting to Approval Faster Through Technology Innovation
Getting to Approval Faster Through Technology InnovationGetting to Approval Faster Through Technology Innovation
Getting to Approval Faster Through Technology InnovationPAREXEL International
 
QA Fest 2017. Per Thorsheim.GDPR - An overview and its relevance for QA
QA Fest 2017. Per Thorsheim.GDPR - An overview and its relevance for QAQA Fest 2017. Per Thorsheim.GDPR - An overview and its relevance for QA
QA Fest 2017. Per Thorsheim.GDPR - An overview and its relevance for QAQAFest
 

Similar to GDPR and test data challenge Antti Heimola 20170504 (20)

Partner enablement GDPR
Partner enablement GDPRPartner enablement GDPR
Partner enablement GDPR
 
Partner enablement GDPR
Partner enablement GDPRPartner enablement GDPR
Partner enablement GDPR
 
De groote de man Ingrid de Poorter
De groote de man Ingrid de PoorterDe groote de man Ingrid de Poorter
De groote de man Ingrid de Poorter
 
How to turn GDPR into a Strategic Advantage using Connected Data
How to turn GDPR into a Strategic Advantage using Connected DataHow to turn GDPR into a Strategic Advantage using Connected Data
How to turn GDPR into a Strategic Advantage using Connected Data
 
Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...
Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...
Implementar una estrategia eficiente de gobierno y seguridad del dato con la ...
 
Data- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerData- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offer
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firms
 
BDVe Webinar Series - Making GDPR for SMEs
BDVe Webinar Series - Making GDPR for SMEsBDVe Webinar Series - Making GDPR for SMEs
BDVe Webinar Series - Making GDPR for SMEs
 
Solving the Data Management Challenge for Healthcare
Solving the Data Management Challenge for HealthcareSolving the Data Management Challenge for Healthcare
Solving the Data Management Challenge for Healthcare
 
GDPR Noncompliance: Avoid the Risk with Data Virtualization
GDPR Noncompliance: Avoid the Risk with Data VirtualizationGDPR Noncompliance: Avoid the Risk with Data Virtualization
GDPR Noncompliance: Avoid the Risk with Data Virtualization
 
¿En qué se parece el Gobierno del Dato a un parque de atracciones?
¿En qué se parece el Gobierno del Dato a un parque de atracciones?¿En qué se parece el Gobierno del Dato a un parque de atracciones?
¿En qué se parece el Gobierno del Dato a un parque de atracciones?
 
GDPR- The Buck Stops Here
GDPR-  The Buck Stops HereGDPR-  The Buck Stops Here
GDPR- The Buck Stops Here
 
GDPR Readiness for Software Usage Analytics
GDPR Readiness for Software Usage AnalyticsGDPR Readiness for Software Usage Analytics
GDPR Readiness for Software Usage Analytics
 
Where's My Data? Managing the Data Residency Challenge
Where's My Data? Managing the Data Residency ChallengeWhere's My Data? Managing the Data Residency Challenge
Where's My Data? Managing the Data Residency Challenge
 
Building the Business Case for TPRM - DVV Solutions Breakfast Briefing March ...
Building the Business Case for TPRM - DVV Solutions Breakfast Briefing March ...Building the Business Case for TPRM - DVV Solutions Breakfast Briefing March ...
Building the Business Case for TPRM - DVV Solutions Breakfast Briefing March ...
 
Delivering Analytics at Scale with a Governed Data Lake
Delivering Analytics at Scale with a Governed Data LakeDelivering Analytics at Scale with a Governed Data Lake
Delivering Analytics at Scale with a Governed Data Lake
 
CIO WaterCooler Focus: GDPR - James Duthie
CIO WaterCooler Focus: GDPR - James DuthieCIO WaterCooler Focus: GDPR - James Duthie
CIO WaterCooler Focus: GDPR - James Duthie
 
General Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) ComplianceGeneral Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) Compliance
 
Getting to Approval Faster Through Technology Innovation
Getting to Approval Faster Through Technology InnovationGetting to Approval Faster Through Technology Innovation
Getting to Approval Faster Through Technology Innovation
 
QA Fest 2017. Per Thorsheim.GDPR - An overview and its relevance for QA
QA Fest 2017. Per Thorsheim.GDPR - An overview and its relevance for QAQA Fest 2017. Per Thorsheim.GDPR - An overview and its relevance for QA
QA Fest 2017. Per Thorsheim.GDPR - An overview and its relevance for QA
 

More from Qentinel

Sap Finug hosted by Qentinel 12.3.2019, esitykset
Sap Finug hosted by Qentinel 12.3.2019, esityksetSap Finug hosted by Qentinel 12.3.2019, esitykset
Sap Finug hosted by Qentinel 12.3.2019, esityksetQentinel
 
Qentinel's garage story in Slush 2018
Qentinel's garage story in Slush 2018Qentinel's garage story in Slush 2018
Qentinel's garage story in Slush 2018Qentinel
 
What is computer vision?
What is computer vision?What is computer vision?
What is computer vision?Qentinel
 
SAP End-to-end liiketoimintaprosessin testaus
SAP End-to-end liiketoimintaprosessin testausSAP End-to-end liiketoimintaprosessin testaus
SAP End-to-end liiketoimintaprosessin testausQentinel
 
End-to-end huoltoprosessin testaus, IFS Asiakaspäivä
End-to-end huoltoprosessin testaus, IFS AsiakaspäiväEnd-to-end huoltoprosessin testaus, IFS Asiakaspäivä
End-to-end huoltoprosessin testaus, IFS AsiakaspäiväQentinel
 
Women in Tech - tukiäly asiakaskokemuksen kumppanina
Women in Tech - tukiäly asiakaskokemuksen kumppaninaWomen in Tech - tukiäly asiakaskokemuksen kumppanina
Women in Tech - tukiäly asiakaskokemuksen kumppaninaQentinel
 
Writing Readable Test Automation - Qentinel Automation Clinic 1.3.2018
Writing Readable Test Automation - Qentinel Automation Clinic 1.3.2018Writing Readable Test Automation - Qentinel Automation Clinic 1.3.2018
Writing Readable Test Automation - Qentinel Automation Clinic 1.3.2018Qentinel
 
Ecosystem Automation as a Service - Qentinel Automation Clinic 1.3.2018
Ecosystem Automation as a Service - Qentinel Automation Clinic 1.3.2018Ecosystem Automation as a Service - Qentinel Automation Clinic 1.3.2018
Ecosystem Automation as a Service - Qentinel Automation Clinic 1.3.2018Qentinel
 
Menesty ekosysteemissä -webinaari 14.11.2017
Menesty ekosysteemissä -webinaari 14.11.2017Menesty ekosysteemissä -webinaari 14.11.2017
Menesty ekosysteemissä -webinaari 14.11.2017Qentinel
 
Asiakaskokemus ekosysteemissä-qentinel-2017-04-27
Asiakaskokemus ekosysteemissä-qentinel-2017-04-27Asiakaskokemus ekosysteemissä-qentinel-2017-04-27
Asiakaskokemus ekosysteemissä-qentinel-2017-04-27Qentinel
 
Kilpailuetua muutoksessa –webinaari. Miten johdan epävarmuuksilla?
Kilpailuetua muutoksessa –webinaari. Miten johdan epävarmuuksilla?Kilpailuetua muutoksessa –webinaari. Miten johdan epävarmuuksilla?
Kilpailuetua muutoksessa –webinaari. Miten johdan epävarmuuksilla?Qentinel
 
Etumatkan kolme-taitoa-esko-hannula-20170216
Etumatkan kolme-taitoa-esko-hannula-20170216Etumatkan kolme-taitoa-esko-hannula-20170216
Etumatkan kolme-taitoa-esko-hannula-20170216Qentinel
 
Asiakaskokemus tulevaisuudessa -webinaari Qentinel 10.1.2017
Asiakaskokemus tulevaisuudessa -webinaari Qentinel 10.1.2017Asiakaskokemus tulevaisuudessa -webinaari Qentinel 10.1.2017
Asiakaskokemus tulevaisuudessa -webinaari Qentinel 10.1.2017Qentinel
 
Test Automation Nightmares - Antti Heimola, Qentinel
Test Automation Nightmares - Antti Heimola, QentinelTest Automation Nightmares - Antti Heimola, Qentinel
Test Automation Nightmares - Antti Heimola, QentinelQentinel
 
End-to-end testaus eri päätelaitteilla - Antti Heimola
End-to-end testaus eri päätelaitteilla - Antti HeimolaEnd-to-end testaus eri päätelaitteilla - Antti Heimola
End-to-end testaus eri päätelaitteilla - Antti HeimolaQentinel
 
Testiautomaatio ei ole tekninen ongelma - Kalle Huttunen
Testiautomaatio ei ole tekninen ongelma - Kalle HuttunenTestiautomaatio ei ole tekninen ongelma - Kalle Huttunen
Testiautomaatio ei ole tekninen ongelma - Kalle HuttunenQentinel
 
Safety nets with fast feedback loops | Jani haapala 2016-10
Safety nets with fast feedback loops | Jani haapala 2016-10Safety nets with fast feedback loops | Jani haapala 2016-10
Safety nets with fast feedback loops | Jani haapala 2016-10Qentinel
 
Jos sinulla olisi kaikki tieto - tietäisitkö kaiken? Esko Hannulan esitys 8.9...
Jos sinulla olisi kaikki tieto - tietäisitkö kaiken? Esko Hannulan esitys 8.9...Jos sinulla olisi kaikki tieto - tietäisitkö kaiken? Esko Hannulan esitys 8.9...
Jos sinulla olisi kaikki tieto - tietäisitkö kaiken? Esko Hannulan esitys 8.9...Qentinel
 
CI Security Scan - Teemu Vesalan esitys 7.6. Testiautomaatioklinkassa
CI Security Scan - Teemu Vesalan esitys 7.6. TestiautomaatioklinkassaCI Security Scan - Teemu Vesalan esitys 7.6. Testiautomaatioklinkassa
CI Security Scan - Teemu Vesalan esitys 7.6. TestiautomaatioklinkassaQentinel
 
Testiautomaatio ja Key word driven -ajattelutapa - Kalle Huttusen esitys 7.6.
Testiautomaatio ja Key word driven -ajattelutapa - Kalle Huttusen esitys 7.6.Testiautomaatio ja Key word driven -ajattelutapa - Kalle Huttusen esitys 7.6.
Testiautomaatio ja Key word driven -ajattelutapa - Kalle Huttusen esitys 7.6.Qentinel
 

More from Qentinel (20)

Sap Finug hosted by Qentinel 12.3.2019, esitykset
Sap Finug hosted by Qentinel 12.3.2019, esityksetSap Finug hosted by Qentinel 12.3.2019, esitykset
Sap Finug hosted by Qentinel 12.3.2019, esitykset
 
Qentinel's garage story in Slush 2018
Qentinel's garage story in Slush 2018Qentinel's garage story in Slush 2018
Qentinel's garage story in Slush 2018
 
What is computer vision?
What is computer vision?What is computer vision?
What is computer vision?
 
SAP End-to-end liiketoimintaprosessin testaus
SAP End-to-end liiketoimintaprosessin testausSAP End-to-end liiketoimintaprosessin testaus
SAP End-to-end liiketoimintaprosessin testaus
 
End-to-end huoltoprosessin testaus, IFS Asiakaspäivä
End-to-end huoltoprosessin testaus, IFS AsiakaspäiväEnd-to-end huoltoprosessin testaus, IFS Asiakaspäivä
End-to-end huoltoprosessin testaus, IFS Asiakaspäivä
 
Women in Tech - tukiäly asiakaskokemuksen kumppanina
Women in Tech - tukiäly asiakaskokemuksen kumppaninaWomen in Tech - tukiäly asiakaskokemuksen kumppanina
Women in Tech - tukiäly asiakaskokemuksen kumppanina
 
Writing Readable Test Automation - Qentinel Automation Clinic 1.3.2018
Writing Readable Test Automation - Qentinel Automation Clinic 1.3.2018Writing Readable Test Automation - Qentinel Automation Clinic 1.3.2018
Writing Readable Test Automation - Qentinel Automation Clinic 1.3.2018
 
Ecosystem Automation as a Service - Qentinel Automation Clinic 1.3.2018
Ecosystem Automation as a Service - Qentinel Automation Clinic 1.3.2018Ecosystem Automation as a Service - Qentinel Automation Clinic 1.3.2018
Ecosystem Automation as a Service - Qentinel Automation Clinic 1.3.2018
 
Menesty ekosysteemissä -webinaari 14.11.2017
Menesty ekosysteemissä -webinaari 14.11.2017Menesty ekosysteemissä -webinaari 14.11.2017
Menesty ekosysteemissä -webinaari 14.11.2017
 
Asiakaskokemus ekosysteemissä-qentinel-2017-04-27
Asiakaskokemus ekosysteemissä-qentinel-2017-04-27Asiakaskokemus ekosysteemissä-qentinel-2017-04-27
Asiakaskokemus ekosysteemissä-qentinel-2017-04-27
 
Kilpailuetua muutoksessa –webinaari. Miten johdan epävarmuuksilla?
Kilpailuetua muutoksessa –webinaari. Miten johdan epävarmuuksilla?Kilpailuetua muutoksessa –webinaari. Miten johdan epävarmuuksilla?
Kilpailuetua muutoksessa –webinaari. Miten johdan epävarmuuksilla?
 
Etumatkan kolme-taitoa-esko-hannula-20170216
Etumatkan kolme-taitoa-esko-hannula-20170216Etumatkan kolme-taitoa-esko-hannula-20170216
Etumatkan kolme-taitoa-esko-hannula-20170216
 
Asiakaskokemus tulevaisuudessa -webinaari Qentinel 10.1.2017
Asiakaskokemus tulevaisuudessa -webinaari Qentinel 10.1.2017Asiakaskokemus tulevaisuudessa -webinaari Qentinel 10.1.2017
Asiakaskokemus tulevaisuudessa -webinaari Qentinel 10.1.2017
 
Test Automation Nightmares - Antti Heimola, Qentinel
Test Automation Nightmares - Antti Heimola, QentinelTest Automation Nightmares - Antti Heimola, Qentinel
Test Automation Nightmares - Antti Heimola, Qentinel
 
End-to-end testaus eri päätelaitteilla - Antti Heimola
End-to-end testaus eri päätelaitteilla - Antti HeimolaEnd-to-end testaus eri päätelaitteilla - Antti Heimola
End-to-end testaus eri päätelaitteilla - Antti Heimola
 
Testiautomaatio ei ole tekninen ongelma - Kalle Huttunen
Testiautomaatio ei ole tekninen ongelma - Kalle HuttunenTestiautomaatio ei ole tekninen ongelma - Kalle Huttunen
Testiautomaatio ei ole tekninen ongelma - Kalle Huttunen
 
Safety nets with fast feedback loops | Jani haapala 2016-10
Safety nets with fast feedback loops | Jani haapala 2016-10Safety nets with fast feedback loops | Jani haapala 2016-10
Safety nets with fast feedback loops | Jani haapala 2016-10
 
Jos sinulla olisi kaikki tieto - tietäisitkö kaiken? Esko Hannulan esitys 8.9...
Jos sinulla olisi kaikki tieto - tietäisitkö kaiken? Esko Hannulan esitys 8.9...Jos sinulla olisi kaikki tieto - tietäisitkö kaiken? Esko Hannulan esitys 8.9...
Jos sinulla olisi kaikki tieto - tietäisitkö kaiken? Esko Hannulan esitys 8.9...
 
CI Security Scan - Teemu Vesalan esitys 7.6. Testiautomaatioklinkassa
CI Security Scan - Teemu Vesalan esitys 7.6. TestiautomaatioklinkassaCI Security Scan - Teemu Vesalan esitys 7.6. Testiautomaatioklinkassa
CI Security Scan - Teemu Vesalan esitys 7.6. Testiautomaatioklinkassa
 
Testiautomaatio ja Key word driven -ajattelutapa - Kalle Huttusen esitys 7.6.
Testiautomaatio ja Key word driven -ajattelutapa - Kalle Huttusen esitys 7.6.Testiautomaatio ja Key word driven -ajattelutapa - Kalle Huttusen esitys 7.6.
Testiautomaatio ja Key word driven -ajattelutapa - Kalle Huttusen esitys 7.6.
 

Recently uploaded

WSO2 Micro Integrator for Enterprise Integration in a Decentralized, Microser...
WSO2 Micro Integrator for Enterprise Integration in a Decentralized, Microser...WSO2 Micro Integrator for Enterprise Integration in a Decentralized, Microser...
WSO2 Micro Integrator for Enterprise Integration in a Decentralized, Microser...WSO2
 
ChatGPT and Beyond - Elevating DevOps Productivity
ChatGPT and Beyond - Elevating DevOps ProductivityChatGPT and Beyond - Elevating DevOps Productivity
ChatGPT and Beyond - Elevating DevOps ProductivityVictorSzoltysek
 
Modernizing Legacy Systems Using Ballerina
Modernizing Legacy Systems Using BallerinaModernizing Legacy Systems Using Ballerina
Modernizing Legacy Systems Using BallerinaWSO2
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 
JohnPollard-hybrid-app-RailsConf2024.pptx
JohnPollard-hybrid-app-RailsConf2024.pptxJohnPollard-hybrid-app-RailsConf2024.pptx
JohnPollard-hybrid-app-RailsConf2024.pptxJohnPollard37
 
The Zero-ETL Approach: Enhancing Data Agility and Insight
The Zero-ETL Approach: Enhancing Data Agility and InsightThe Zero-ETL Approach: Enhancing Data Agility and Insight
The Zero-ETL Approach: Enhancing Data Agility and InsightSafe Software
 
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...TrustArc
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingEdi Saputra
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native ApplicationsWSO2
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 
Choreo: Empowering the Future of Enterprise Software Engineering
Choreo: Empowering the Future of Enterprise Software EngineeringChoreo: Empowering the Future of Enterprise Software Engineering
Choreo: Empowering the Future of Enterprise Software EngineeringWSO2
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Jeffrey Haguewood
 
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)Samir Dash
 
JavaScript Usage Statistics 2024 - The Ultimate Guide
JavaScript Usage Statistics 2024 - The Ultimate GuideJavaScript Usage Statistics 2024 - The Ultimate Guide
JavaScript Usage Statistics 2024 - The Ultimate GuidePixlogix Infotech
 
How to Check CNIC Information Online with Pakdata cf
How to Check CNIC Information Online with Pakdata cfHow to Check CNIC Information Online with Pakdata cf
How to Check CNIC Information Online with Pakdata cfdanishmna97
 
Design and Development of a Provenance Capture Platform for Data Science
Design and Development of a Provenance Capture Platform for Data ScienceDesign and Development of a Provenance Capture Platform for Data Science
Design and Development of a Provenance Capture Platform for Data SciencePaolo Missier
 
WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdfSandro Moreira
 

Recently uploaded (20)

WSO2 Micro Integrator for Enterprise Integration in a Decentralized, Microser...
WSO2 Micro Integrator for Enterprise Integration in a Decentralized, Microser...WSO2 Micro Integrator for Enterprise Integration in a Decentralized, Microser...
WSO2 Micro Integrator for Enterprise Integration in a Decentralized, Microser...
 
ChatGPT and Beyond - Elevating DevOps Productivity
ChatGPT and Beyond - Elevating DevOps ProductivityChatGPT and Beyond - Elevating DevOps Productivity
ChatGPT and Beyond - Elevating DevOps Productivity
 
Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..
 
Modernizing Legacy Systems Using Ballerina
Modernizing Legacy Systems Using BallerinaModernizing Legacy Systems Using Ballerina
Modernizing Legacy Systems Using Ballerina
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
JohnPollard-hybrid-app-RailsConf2024.pptx
JohnPollard-hybrid-app-RailsConf2024.pptxJohnPollard-hybrid-app-RailsConf2024.pptx
JohnPollard-hybrid-app-RailsConf2024.pptx
 
The Zero-ETL Approach: Enhancing Data Agility and Insight
The Zero-ETL Approach: Enhancing Data Agility and InsightThe Zero-ETL Approach: Enhancing Data Agility and Insight
The Zero-ETL Approach: Enhancing Data Agility and Insight
 
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Choreo: Empowering the Future of Enterprise Software Engineering
Choreo: Empowering the Future of Enterprise Software EngineeringChoreo: Empowering the Future of Enterprise Software Engineering
Choreo: Empowering the Future of Enterprise Software Engineering
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
 
JavaScript Usage Statistics 2024 - The Ultimate Guide
JavaScript Usage Statistics 2024 - The Ultimate GuideJavaScript Usage Statistics 2024 - The Ultimate Guide
JavaScript Usage Statistics 2024 - The Ultimate Guide
 
How to Check CNIC Information Online with Pakdata cf
How to Check CNIC Information Online with Pakdata cfHow to Check CNIC Information Online with Pakdata cf
How to Check CNIC Information Online with Pakdata cf
 
Design and Development of a Provenance Capture Platform for Data Science
Design and Development of a Provenance Capture Platform for Data ScienceDesign and Development of a Provenance Capture Platform for Data Science
Design and Development of a Provenance Capture Platform for Data Science
 
WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering Developers
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 

GDPR and test data challenge Antti Heimola 20170504

  • 1. © Qentinel Group 2017 PUBLIC 1 GDPR and Test Data Challenge Antti Heimola (Kalle Huttunen) 4.5.2017, Test Automation Clinic
  • 2. © Qentinel Group 2017 PUBLIC 2 Purpose of the presentation is to highlight some things to be done, before May- 25, 2018, because General Data Protection Regulation (GDPR) will replace Data Protection Directive (1995). Test data management is one of the topic to be taken care of. “The primary objectives of the GDPR are to give citizens and residents back control of their personal data and to simplify the regulatory environment for international business by unifying the regulation within the EU.” https://en.wikipedia.org/wiki/General_Data_Protection_Regulation
  • 3. © Qentinel Group 2017 PUBLIC 3 Main Differences 1995  2018 1. Personal Data Redefined • Broader definition: mobile device identifiers, social identity, economic status, etc. 2. Individual Rights • Right to access • Right to be forgotten • Terms of agreements (may) need to updated 3. Data Controllers vs. Data Processors • DPD - only data controllers were held accountable • Data Protection Officer (DPO) may need to be appointed • Data protection policy and data processing activity record (>250) • Impact assessments in case of high risk of data breach https://britishlegalitforum.com/wp-content/uploads/2017/02/GDPR-Whitepaper-British-Legal-Technology-Forum-2017-Sponsor.pdf
  • 4. © Qentinel Group 2017 PUBLIC 4 Main Differences 1995  2018 4. Information Governance and Security - Privacy by design • Privacy of data collected is taken into account at all steps of business processes • Impact assessments for automated data processing activities 5. Data Breach Notification and Penalties • Notification of a personal data breach within 72 hours • Penalties 4% of the global turnover, or 20M€ • lacking consent to process data or violating privacy by design • Penalties 2% of the global turnover • records not in order or not notifying the supervisory authority 6. Global Impact • Company that markets goods/services to EU residents can be subject to GDPR https://britishlegalitforum.com/wp-content/uploads/2017/02/GDPR-Whitepaper-British-Legal-Technology-Forum-2017-Sponsor.pdf
  • 5. © Qentinel Group 2017 PUBLIC 5 Common Test Data Management Problems • Production data is too big to copy, slow, and expensive • Test data is not available at the speed needed in agile development and DevOps • Data in test environments are shared and that makes test results unreliable • Production data is sensitive and cannot be used
  • 6. © Qentinel Group 2017 PUBLIC 6 Used solution Production data is too big to copy, slow, and expensive • Use subsets of production data  Finding and selecting subsets is time consuming  Test coverage is not as good as with full data
  • 7. © Qentinel Group 2017 PUBLIC 7 Used solution Data in test environments are shared and that makes test results unreliable • Follow process where certain data is reserved for certain people/project  If process is not followed, it is easy to mess up test results  Refresh not possible when wanted • Follow process where whole environment is reserved people/project  If process not followed it is easy to mess up test results  Limits people/projects that can test in parallel  Refresh not possible when wanted
  • 8. © Qentinel Group 2017 PUBLIC 8 Used solution Production data contains sensitive information • Limit access to certain persons that have hard NDAs  Only these persons can perform testing • Use synthetic test data (subset of anonymized data)  Synthetic test data is not as good as real data • Masking production data Data integrity can suffer if design not done properly
  • 9. © Qentinel Group 2017 PUBLIC 9 Solutions used today are not optimal • Expensive • Limiting speed of testing • Limiting volume of testing • Limiting test coverage • Limiting use of effective use of test automation and CI/CD • Affecting reliability of test results • Generating additional manual work • GDPR non-compliance
  • 10. © Qentinel Group 2017 PUBLIC 10 Penalties Data portability Right to be forgotten Items for the Discussion Session Privacy by design Plan for data security breaches Obligations as a Data Processor How to manage test data Readable and understandable user agreements Right to access Data Controller obligations Impact assessment Need for DPO Rights of data subjects – how to deal with difficult individuals
  • 11. © Qentinel Group 2017 PUBLIC 11 ContactQentinel Group www.qentinel.com kalle.huttunen@qentinel.com