SlideShare a Scribd company logo
1 of 21
Download to read offline
EUROPEAN
DATA
PROTECTION
SUPERVISOR
The EU’s independent data
protection authority
Data-protection in the
Western Balkans and Eastern
Partnership Region
EDPS Technology &
Privacy unit
Massimo ATTORESI
Deputy Head of T&P unit
19 September 2023
2
A bit about the TP unit: our story
2012 2019 2023
Technology Sector
created
2 people
Our Composition and Expertise –Multidisciplinarystaff with focus on technologicaland
scientific research
Expertise in Telecommunications, Computer engineering, Computer science, Physics, Auditing,
Information security etc.
Technology sector
becomes Technology
and Privacy unit
8 people
Technology
unit grows
to 15 people
Technology & Privacy Unit
3
The Supervisor
Secretary/General
Cabinet
Supervision &
Enforcement
Policy &
Consultation
Technology
& Privacy
Governance
& Internal
Compliance
Information &
Communication
HR, Budget &
Administration
EDPB
Secretariat
4
What T&P Unit does?
Support functions
SupportPolicy and Consultation Unit
in technologicial matters (informal-formal Consultations, Opinions). Participation
in EDPB subgroups, international fora (GPA, Spring Conference, int. organisations)
Direct Attributions
SupportSupervision and EnforcementUnit
in technological matters (prior consultations, mainly in AFSJ, joint
Audits/Investigations, Complaints). In a few cases, with high technological focus,
TP is on the lead.
Supportour Director in Security Functions
LSO and LISO Functions.
Technology monitoring & foresight
Techsonar, TechDispatch, IPEN organisation, preparation guidelines specific topics, training
in PETS, collaboration with other organisations in technology matters ( in the EU, such as
ENISA, international, such as IWGDPT/Berlin Group), support Supervisor & Sec Gen
Technology and
Privacy Unit
IT function
EDPS own IT needs as an institution: IT Strategy, IT Governance, Local IT support. Own
systems, NextCloud, EuVideo-Voice, PKI infrastructure. Auditing tolos such as WEC,
mobile apps lab.
IT Audits
Mainly in the context of Large Scale IT Systems and Coordinated Supervision.
Data Breach Notification Handling
6
How are we organised?
Management
Luis Velasco (HoU)
Massimo Attoresi (DHoU)
Technology Monitoring and Foresight Sector
System Oversight and Technology Audits
Digital Transformation
• IRM – IT Governance
• ICDT
• IT Strategy, IT Feasibility Study
• SLA EP
• Local IT function
• Innovation Projects
• IT audits on Large Scale IT systems
• Other IT audits outside ASFJ area
• Data breach notifications, DBN
Guidelines and DBN system
• Expertise in AFSJ including support
the other two sectors and to P&C,
S&E and EDPB
• DPO meetings
• Technological expertise including support
the other two sectors and to PC and SE in
the rest of topics, Digital Euro, Cloud, AI,
Blockchain, Surveillance, Finance, Health,
eGovernment, Data Spaces....
• Guidelines on technology topics
• Foresight activities. TechSonar &
TechDispatch
• Contributions to EDPB in topics above
• IPEN Organisation
• Berlin Group, GPA....
7
Personal Data Breaches
• “a breach of security leading to the accidental unlawful
destruction, loss, alteration, unauthorised disclosure of, or access to,
personal data transmitted, stored or otherwise processed”
EUDPR Art. 3(16)
8
Personal Data Breaches
Root causes of
personal data breaches
2019-2022
9
Our topics of interest
10
Technology Monitoring & Foresight
11
Technology Monitoring: TechSonar
(Foresight dimension)
TechSonar aims to anticipate emerging
technology trends: the main aim of this
initiative is to better understand future
developments in the technology sector from a
data protection perspective.
12
Technology Monitoring: TechDispatch
Smart speakers Connected Cars Contact Tracing
with Apps
Quantum
Computing
Facial Emotion
Recognition
Card Based
Systems
Federated Social
Media Platforms
TechDispatch provides factual descriptions
of a new technology, preliminarily assesses
possible impacts on privacy and the
protection of personal data, as we
understand them now, and provides links to
further recommended reading.
13
Technology Monitoring: IPEN network
The purpose of exchange with Academia and
Engineers in the IPEN Network is to bring
together developers and data protection experts
with a technical background from different
areas in order to launch and support projects
that build privacy into everyday tools and
develop new tools that can effectively protect
and enhance our privacy.
IPEN2023 – Explainable AI
IPEN2022 - CBDC
IPEN2022 - DigitalIdentity
IPEN2021 - Pseudonymisation
IPEN2021 SyntheticData Webinar
IPEN2020 - Contact Tracing Apps webinar
IPEN2020 - Encryption webinar
IPEN2020 - Online Workshop
IPEN2020 - Panel on Web Tracking
IPENWorkshop 2019 - Rome
IPENData Protection Day Workshop 2019
IPENWorkshop 2018 - Barcelona
IPENWorkshop 2017 - Vienna
IPENWorkshop 2016 - Frankfurt
IPENWorkshop 2015 - Leuven
IPENWorkshop 2014 – Berlin
• Guidelineson personal data and electronic communicationsin the EU institutions
(eCommunicationsguidelines)
• Guidelineson Personal Data BreachNotification
• IT governanceand IT management
• Guidelineson the use of cloud computing services by the Europeaninstitutions and
bodies
• Mobile Devices
• Mobile Applications
• Web Services
• Security Measures for Personal Data Processing
14
Technology & Privacy – EDPS Guidelines
15
The Web is watching you:
Watch back with the “WEC”
16
Various Compliance Tools for Website
Controllers
Cloud Solutions
• Qualys SSL Labs (HTTPS check)
• Cookiebot (Cookiecheck)
• PrivacyScore, Webbkoll
(Cookies, HTTPS, etc.)
• OneTrust (Cookiecheck)
Problems
• no scans in intranets
• confidentiality or compliance issues
• transparency, reproducibility of the cloud solution
On-Premise Solutions
• OpenWPM by Mozilla
• WebXray
• Developer Toolbar
(Firefox and Chrome)
• Website Evidence Collector
bytheEDPS
• Website Evidence Collector
by the EDPS
17
Website Evidence Collector (WEC)
from the EDPS
Features
• automated, reproducible evidence collection
• records screenshots, cookies, traffic,
potential web beacons, HTTPS security
• no legal judgements: data protectionlaw agnostic
Output
• machine- and human-readable output
• with many details to identify tracking issues
18
Digital Sovereignty – EDPS Fediverse
pilots
• EDPS launched on 28 April 2022 Fediverse pilot
and invites other EU institutions to participate.
• EU Voice powered by Mastodon with
35 accounts of EU institutions, bodies, agencies
https://social.network.europa.eu
• EU Video powered by Peertube with
about 6 accounts
https://tube.network.europa.eu(originally EU Tube)
...and an ongoing Pilot on a sovereign Cloud - NextCloud collaborationtools
T&P unit follows closely EU legislative developments with a significant technology
dimension. Files include:
• The ArtificialIntelligence Act (AIA)
• Digital Services Act (DSA), the Digital Markets Act (DMA), the Data
Governance Act (DGA) and the Data Act
• Regulation as regards establishing a framework for a European Digital Identity
• Digital Euro joint Opinion with the EDPB
• Regulation laying down rules to prevent and combat child sexual abuse
• Regulation on the digitalisationof the visa procedure
• Directiveon informationexchange between law enforcement authorities of
Member States
19
Legislative proposals followed by T&P
20
Collaboration with EDPB and EDPB
secretariat
• Interface with the European Parliament for the provisionof general basic services
to all the EDPS units including the EDPB Secretariat
• Collaborationwith EDPB Secretariat in the organisation of the Website Audit
BootCamp
• Participationin the EDPB “ChatGPT taskforce”
• Management of projects using EDPB Expert pool of experts in the field of
ArtificialIntelligence.
• Collaborationin TECH subgroup within the EDPB. Co-rapporteurs in multiple
documents such pseudo-anonymisation, blockchain, ....
• Supervision of Large Scale IT Systems and contributionto the Coordianted
Supervision Committee
21
Artificial Intelligence & AI Act
• EDPS has been identifying and assessing AI risks under
GDPR/EUDPR
• AI Act identifies the EDPS as the AI competent authority for
the EU institutions
• Preparations will start to understand our tasks, interaction
with MSs national competent and market authorities,
interaction with applicable data protectionlaw, the role of
« regulatory sandboxes »
@EU_EDPS
European Data
Protection Supervison
EDPS
The EU’s independent data
protection authority
EUROPEAN
DATA
PROTECTION
SUPERVISOR
Some icons from https://www.flaticon.com/
Word cloud created in https://wordart.com

More Related Content

Similar to Day 02 - EDPS Technology & Privacy unit.pdf

SFScon19 - Eugenio Bettella Marco Reguzzoni - Internet of Things & cybersecur...
SFScon19 - Eugenio Bettella Marco Reguzzoni - Internet of Things & cybersecur...SFScon19 - Eugenio Bettella Marco Reguzzoni - Internet of Things & cybersecur...
SFScon19 - Eugenio Bettella Marco Reguzzoni - Internet of Things & cybersecur...South Tyrol Free Software Conference
 
Legal certainty as a tool for the spread of the internet of things
Legal certainty as a tool for the spread of the internet of thingsLegal certainty as a tool for the spread of the internet of things
Legal certainty as a tool for the spread of the internet of thingsGuido Noto La Diega
 
Cloud Services As An Enabler: the Strategic, Legal & Pragmatic Approach
Cloud Services As An Enabler: the Strategic, Legal & Pragmatic ApproachCloud Services As An Enabler: the Strategic, Legal & Pragmatic Approach
Cloud Services As An Enabler: the Strategic, Legal & Pragmatic ApproachSLA-Ready Network
 
Webinar: Why risk managers should look at Artificial Intelligence now?
Webinar: Why risk managers should look at Artificial Intelligence now?Webinar: Why risk managers should look at Artificial Intelligence now?
Webinar: Why risk managers should look at Artificial Intelligence now?FERMA
 
201704624- e-privacy 2017 - summer edition - 24000 dati
201704624- e-privacy 2017 - summer edition  - 24000 dati201704624- e-privacy 2017 - summer edition  - 24000 dati
201704624- e-privacy 2017 - summer edition - 24000 datiyasoiler
 
EU Investment Programs in AI and Blockchain
EU Investment Programs in AI and Blockchain EU Investment Programs in AI and Blockchain
EU Investment Programs in AI and Blockchain Soren Gigler
 
Trends and Prospects in the Information Society: Hungary and the New Member S...
Trends and Prospects in the Information Society:Hungary and the New Member S...Trends and Prospects in the Information Society:Hungary and the New Member S...
Trends and Prospects in the Information Society: Hungary and the New Member S...Filipe Mello
 
eGovernment for Citizen: Leveraging Open SOA Standards and Interoperability ...
eGovernment for Citizen:  Leveraging Open SOA Standards and Interoperability ...eGovernment for Citizen:  Leveraging Open SOA Standards and Interoperability ...
eGovernment for Citizen: Leveraging Open SOA Standards and Interoperability ...Adomas Svirskas
 
GDPR and Data Ethics considerations in personal data sharing
GDPR and Data Ethics considerations in personal data sharingGDPR and Data Ethics considerations in personal data sharing
GDPR and Data Ethics considerations in personal data sharingBig Data Value Association
 
L'economia europea dei dati. Politiche europee e opportunità di finanziamento...
L'economia europea dei dati. Politiche europee e opportunità di finanziamento...L'economia europea dei dati. Politiche europee e opportunità di finanziamento...
L'economia europea dei dati. Politiche europee e opportunità di finanziamento...Data Driven Innovation
 
e-SIDES workshop at EBDVF 2018, Vienna 14/11/2018
e-SIDES workshop at EBDVF 2018, Vienna 14/11/2018 e-SIDES workshop at EBDVF 2018, Vienna 14/11/2018
e-SIDES workshop at EBDVF 2018, Vienna 14/11/2018 e-SIDES.eu
 
PECB Webinar: The Internet of Things
PECB Webinar: The Internet of ThingsPECB Webinar: The Internet of Things
PECB Webinar: The Internet of ThingsPECB
 
North European Cybersecurity Cluster - an example of the regional trust platf...
North European Cybersecurity Cluster - an example of the regional trust platf...North European Cybersecurity Cluster - an example of the regional trust platf...
North European Cybersecurity Cluster - an example of the regional trust platf...DATA SECURITY SOLUTIONS
 
Jan Langedijk, Siemens
Jan Langedijk, SiemensJan Langedijk, Siemens
Jan Langedijk, SiemensDutch Power
 
From E-Government to Open Government
From E-Government to Open GovernmentFrom E-Government to Open Government
From E-Government to Open GovernmentJohann Höchtl
 
Privacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital SetupPrivacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital SetupPiwik PRO
 
28032012 Jacques Bus Privacy en Identiteit in Europese richtlijnen en program...
28032012 Jacques Bus Privacy en Identiteit in Europese richtlijnen en program...28032012 Jacques Bus Privacy en Identiteit in Europese richtlijnen en program...
28032012 Jacques Bus Privacy en Identiteit in Europese richtlijnen en program...Stichting ePortfolio Support
 
IT to IOT Evolution
IT to IOT EvolutionIT to IOT Evolution
IT to IOT EvolutionJayakumar PP
 

Similar to Day 02 - EDPS Technology & Privacy unit.pdf (20)

SFScon19 - Eugenio Bettella Marco Reguzzoni - Internet of Things & cybersecur...
SFScon19 - Eugenio Bettella Marco Reguzzoni - Internet of Things & cybersecur...SFScon19 - Eugenio Bettella Marco Reguzzoni - Internet of Things & cybersecur...
SFScon19 - Eugenio Bettella Marco Reguzzoni - Internet of Things & cybersecur...
 
Legal certainty as a tool for the spread of the internet of things
Legal certainty as a tool for the spread of the internet of thingsLegal certainty as a tool for the spread of the internet of things
Legal certainty as a tool for the spread of the internet of things
 
Cloud Services As An Enabler: the Strategic, Legal & Pragmatic Approach
Cloud Services As An Enabler: the Strategic, Legal & Pragmatic ApproachCloud Services As An Enabler: the Strategic, Legal & Pragmatic Approach
Cloud Services As An Enabler: the Strategic, Legal & Pragmatic Approach
 
Beawre pitch
Beawre pitchBeawre pitch
Beawre pitch
 
Webinar: Why risk managers should look at Artificial Intelligence now?
Webinar: Why risk managers should look at Artificial Intelligence now?Webinar: Why risk managers should look at Artificial Intelligence now?
Webinar: Why risk managers should look at Artificial Intelligence now?
 
201704624- e-privacy 2017 - summer edition - 24000 dati
201704624- e-privacy 2017 - summer edition  - 24000 dati201704624- e-privacy 2017 - summer edition  - 24000 dati
201704624- e-privacy 2017 - summer edition - 24000 dati
 
EU Investment Programs in AI and Blockchain
EU Investment Programs in AI and Blockchain EU Investment Programs in AI and Blockchain
EU Investment Programs in AI and Blockchain
 
Trends and Prospects in the Information Society: Hungary and the New Member S...
Trends and Prospects in the Information Society:Hungary and the New Member S...Trends and Prospects in the Information Society:Hungary and the New Member S...
Trends and Prospects in the Information Society: Hungary and the New Member S...
 
eGovernment for Citizen: Leveraging Open SOA Standards and Interoperability ...
eGovernment for Citizen:  Leveraging Open SOA Standards and Interoperability ...eGovernment for Citizen:  Leveraging Open SOA Standards and Interoperability ...
eGovernment for Citizen: Leveraging Open SOA Standards and Interoperability ...
 
GDPR and Data Ethics considerations in personal data sharing
GDPR and Data Ethics considerations in personal data sharingGDPR and Data Ethics considerations in personal data sharing
GDPR and Data Ethics considerations in personal data sharing
 
L'economia europea dei dati. Politiche europee e opportunità di finanziamento...
L'economia europea dei dati. Politiche europee e opportunità di finanziamento...L'economia europea dei dati. Politiche europee e opportunità di finanziamento...
L'economia europea dei dati. Politiche europee e opportunità di finanziamento...
 
2019 04-08 oasc-martin_brynskov
2019 04-08 oasc-martin_brynskov2019 04-08 oasc-martin_brynskov
2019 04-08 oasc-martin_brynskov
 
e-SIDES workshop at EBDVF 2018, Vienna 14/11/2018
e-SIDES workshop at EBDVF 2018, Vienna 14/11/2018 e-SIDES workshop at EBDVF 2018, Vienna 14/11/2018
e-SIDES workshop at EBDVF 2018, Vienna 14/11/2018
 
PECB Webinar: The Internet of Things
PECB Webinar: The Internet of ThingsPECB Webinar: The Internet of Things
PECB Webinar: The Internet of Things
 
North European Cybersecurity Cluster - an example of the regional trust platf...
North European Cybersecurity Cluster - an example of the regional trust platf...North European Cybersecurity Cluster - an example of the regional trust platf...
North European Cybersecurity Cluster - an example of the regional trust platf...
 
Jan Langedijk, Siemens
Jan Langedijk, SiemensJan Langedijk, Siemens
Jan Langedijk, Siemens
 
From E-Government to Open Government
From E-Government to Open GovernmentFrom E-Government to Open Government
From E-Government to Open Government
 
Privacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital SetupPrivacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital Setup
 
28032012 Jacques Bus Privacy en Identiteit in Europese richtlijnen en program...
28032012 Jacques Bus Privacy en Identiteit in Europese richtlijnen en program...28032012 Jacques Bus Privacy en Identiteit in Europese richtlijnen en program...
28032012 Jacques Bus Privacy en Identiteit in Europese richtlijnen en program...
 
IT to IOT Evolution
IT to IOT EvolutionIT to IOT Evolution
IT to IOT Evolution
 

More from Support for Improvement in Governance and Management SIGMA

More from Support for Improvement in Governance and Management SIGMA (20)

PPT - SIGMA-GIZ Academies - Stage 1 - CAF Ukraine roadmap.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - CAF Ukraine roadmap.pdfPPT - SIGMA-GIZ Academies - Stage 1 - CAF Ukraine roadmap.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - CAF Ukraine roadmap.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 - CAF Moldova roadmap.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - CAF Moldova roadmap.pdfPPT - SIGMA-GIZ Academies - Stage 1 - CAF Moldova roadmap.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - CAF Moldova roadmap.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 -CAF Armenia roadmap.pdf
PPT - SIGMA-GIZ Academies - Stage 1 -CAF Armenia roadmap.pdfPPT - SIGMA-GIZ Academies - Stage 1 -CAF Armenia roadmap.pdf
PPT - SIGMA-GIZ Academies - Stage 1 -CAF Armenia roadmap.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 - Financial support tu PAR in Montenegro....
PPT - SIGMA-GIZ Academies - Stage 1 - Financial support tu PAR in Montenegro....PPT - SIGMA-GIZ Academies - Stage 1 - Financial support tu PAR in Montenegro....
PPT - SIGMA-GIZ Academies - Stage 1 - Financial support tu PAR in Montenegro....
 
PPT - SIGMA-GIZ Academies - Stage 1 - SIGMA opening.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - SIGMA opening.pdfPPT - SIGMA-GIZ Academies - Stage 1 - SIGMA opening.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - SIGMA opening.pdf
 
Photo gallery - SIGMA-GIZ Academies on QM - Stage 1.pdf
Photo gallery - SIGMA-GIZ Academies on QM - Stage 1.pdfPhoto gallery - SIGMA-GIZ Academies on QM - Stage 1.pdf
Photo gallery - SIGMA-GIZ Academies on QM - Stage 1.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 - prezentacija gsb podgorica.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - prezentacija gsb podgorica.pdfPPT - SIGMA-GIZ Academies - Stage 1 - prezentacija gsb podgorica.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - prezentacija gsb podgorica.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 - CAF-MONTENEGRO-29-FEB.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - CAF-MONTENEGRO-29-FEB.pdfPPT - SIGMA-GIZ Academies - Stage 1 - CAF-MONTENEGRO-29-FEB.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - CAF-MONTENEGRO-29-FEB.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 - CAF Georgia.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - CAF Georgia.pdfPPT - SIGMA-GIZ Academies - Stage 1 - CAF Georgia.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - CAF Georgia.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 - QM Roadmapping Day 2 and 3.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - QM Roadmapping Day 2  and 3.pdfPPT - SIGMA-GIZ Academies - Stage 1 - QM Roadmapping Day 2  and 3.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - QM Roadmapping Day 2 and 3.pdf
 
Academies-QM_Stage1_Ministry of Higher Education CAF.pdf
Academies-QM_Stage1_Ministry of Higher Education CAF.pdfAcademies-QM_Stage1_Ministry of Higher Education CAF.pdf
Academies-QM_Stage1_Ministry of Higher Education CAF.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 - ReSPA and CAF.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - ReSPA and CAF.pdfPPT - SIGMA-GIZ Academies - Stage 1 - ReSPA and CAF.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - ReSPA and CAF.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 -Bosnia Herzegovina CAF.pdf
PPT - SIGMA-GIZ Academies - Stage 1 -Bosnia Herzegovina CAF.pdfPPT - SIGMA-GIZ Academies - Stage 1 -Bosnia Herzegovina CAF.pdf
PPT - SIGMA-GIZ Academies - Stage 1 -Bosnia Herzegovina CAF.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 -Montenegro CAF.pdf
PPT - SIGMA-GIZ Academies - Stage 1 -Montenegro CAF.pdfPPT - SIGMA-GIZ Academies - Stage 1 -Montenegro CAF.pdf
PPT - SIGMA-GIZ Academies - Stage 1 -Montenegro CAF.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 - North Macedonia CAF.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - North Macedonia CAF.pdfPPT - SIGMA-GIZ Academies - Stage 1 - North Macedonia CAF.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - North Macedonia CAF.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 - CAF in Ukraine.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - CAF in Ukraine.pdfPPT - SIGMA-GIZ Academies - Stage 1 - CAF in Ukraine.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - CAF in Ukraine.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 -Serbia CAF.pdf
PPT - SIGMA-GIZ Academies - Stage 1 -Serbia CAF.pdfPPT - SIGMA-GIZ Academies - Stage 1 -Serbia CAF.pdf
PPT - SIGMA-GIZ Academies - Stage 1 -Serbia CAF.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 - SIGMA opening.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - SIGMA opening.pdfPPT - SIGMA-GIZ Academies - Stage 1 - SIGMA opening.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - SIGMA opening.pdf
 
Omnichannel management, by Willem Pieterson - SIGMA Webinars on service desig...
Omnichannel management, by Willem Pieterson - SIGMA Webinars on service desig...Omnichannel management, by Willem Pieterson - SIGMA Webinars on service desig...
Omnichannel management, by Willem Pieterson - SIGMA Webinars on service desig...
 
eZdravlje, by Vladimir Raickovic - SIGMA Webinars on service design and deliv...
eZdravlje, by Vladimir Raickovic - SIGMA Webinars on service design and deliv...eZdravlje, by Vladimir Raickovic - SIGMA Webinars on service design and deliv...
eZdravlje, by Vladimir Raickovic - SIGMA Webinars on service design and deliv...
 

Recently uploaded

Powering Britain: Can we decarbonise electricity without disadvantaging poore...
Powering Britain: Can we decarbonise electricity without disadvantaging poore...Powering Britain: Can we decarbonise electricity without disadvantaging poore...
Powering Britain: Can we decarbonise electricity without disadvantaging poore...ResolutionFoundation
 
(TARA) Call Girls Chakan ( 7001035870 ) HI-Fi Pune Escorts Service
(TARA) Call Girls Chakan ( 7001035870 ) HI-Fi Pune Escorts Service(TARA) Call Girls Chakan ( 7001035870 ) HI-Fi Pune Escorts Service
(TARA) Call Girls Chakan ( 7001035870 ) HI-Fi Pune Escorts Serviceranjana rawat
 
Climate change and safety and health at work
Climate change and safety and health at workClimate change and safety and health at work
Climate change and safety and health at workChristina Parmionova
 
VIP High Class Call Girls Amravati Anushka 8250192130 Independent Escort Serv...
VIP High Class Call Girls Amravati Anushka 8250192130 Independent Escort Serv...VIP High Class Call Girls Amravati Anushka 8250192130 Independent Escort Serv...
VIP High Class Call Girls Amravati Anushka 8250192130 Independent Escort Serv...Suhani Kapoor
 
Cunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile Service
Cunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile ServiceCunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile Service
Cunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile ServiceHigh Profile Call Girls
 
Artificial Intelligence in Philippine Local Governance: Challenges and Opport...
Artificial Intelligence in Philippine Local Governance: Challenges and Opport...Artificial Intelligence in Philippine Local Governance: Challenges and Opport...
Artificial Intelligence in Philippine Local Governance: Challenges and Opport...CedZabala
 
How the Congressional Budget Office Assists Lawmakers
How the Congressional Budget Office Assists LawmakersHow the Congressional Budget Office Assists Lawmakers
How the Congressional Budget Office Assists LawmakersCongressional Budget Office
 
2024: The FAR, Federal Acquisition Regulations - Part 28
2024: The FAR, Federal Acquisition Regulations - Part 282024: The FAR, Federal Acquisition Regulations - Part 28
2024: The FAR, Federal Acquisition Regulations - Part 28JSchaus & Associates
 
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escortsranjana rawat
 
##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas Whats Up Number
##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas  Whats Up Number##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas  Whats Up Number
##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas Whats Up NumberMs Riya
 
Zechariah Boodey Farmstead Collaborative presentation - Humble Beginnings
Zechariah Boodey Farmstead Collaborative presentation -  Humble BeginningsZechariah Boodey Farmstead Collaborative presentation -  Humble Beginnings
Zechariah Boodey Farmstead Collaborative presentation - Humble Beginningsinfo695895
 
Club of Rome: Eco-nomics for an Ecological Civilization
Club of Rome: Eco-nomics for an Ecological CivilizationClub of Rome: Eco-nomics for an Ecological Civilization
Club of Rome: Eco-nomics for an Ecological CivilizationEnergy for One World
 
Climate change and occupational safety and health.
Climate change and occupational safety and health.Climate change and occupational safety and health.
Climate change and occupational safety and health.Christina Parmionova
 
Goa Escorts WhatsApp Number South Goa Call Girl … 8588052666…
Goa Escorts WhatsApp Number South Goa Call Girl … 8588052666…Goa Escorts WhatsApp Number South Goa Call Girl … 8588052666…
Goa Escorts WhatsApp Number South Goa Call Girl … 8588052666…nishakur201
 
(VASUDHA) Call Girls Balaji Nagar ( 7001035870 ) HI-Fi Pune Escorts Service
(VASUDHA) Call Girls Balaji Nagar ( 7001035870 ) HI-Fi Pune Escorts Service(VASUDHA) Call Girls Balaji Nagar ( 7001035870 ) HI-Fi Pune Escorts Service
(VASUDHA) Call Girls Balaji Nagar ( 7001035870 ) HI-Fi Pune Escorts Serviceranjana rawat
 
VIP Kolkata Call Girl Jatin Das Park 👉 8250192130 Available With Room
VIP Kolkata Call Girl Jatin Das Park 👉 8250192130  Available With RoomVIP Kolkata Call Girl Jatin Das Park 👉 8250192130  Available With Room
VIP Kolkata Call Girl Jatin Das Park 👉 8250192130 Available With Roomishabajaj13
 
Call Girls Service AECS Layout Just Call 7001305949 Enjoy College Girls Service
Call Girls Service AECS Layout Just Call 7001305949 Enjoy College Girls ServiceCall Girls Service AECS Layout Just Call 7001305949 Enjoy College Girls Service
Call Girls Service AECS Layout Just Call 7001305949 Enjoy College Girls Servicenarwatsonia7
 

Recently uploaded (20)

Powering Britain: Can we decarbonise electricity without disadvantaging poore...
Powering Britain: Can we decarbonise electricity without disadvantaging poore...Powering Britain: Can we decarbonise electricity without disadvantaging poore...
Powering Britain: Can we decarbonise electricity without disadvantaging poore...
 
(TARA) Call Girls Chakan ( 7001035870 ) HI-Fi Pune Escorts Service
(TARA) Call Girls Chakan ( 7001035870 ) HI-Fi Pune Escorts Service(TARA) Call Girls Chakan ( 7001035870 ) HI-Fi Pune Escorts Service
(TARA) Call Girls Chakan ( 7001035870 ) HI-Fi Pune Escorts Service
 
Call Girls Service Connaught Place @9999965857 Delhi 🫦 No Advance VVIP 🍎 SER...
Call Girls Service Connaught Place @9999965857 Delhi 🫦 No Advance  VVIP 🍎 SER...Call Girls Service Connaught Place @9999965857 Delhi 🫦 No Advance  VVIP 🍎 SER...
Call Girls Service Connaught Place @9999965857 Delhi 🫦 No Advance VVIP 🍎 SER...
 
Climate change and safety and health at work
Climate change and safety and health at workClimate change and safety and health at work
Climate change and safety and health at work
 
VIP High Class Call Girls Amravati Anushka 8250192130 Independent Escort Serv...
VIP High Class Call Girls Amravati Anushka 8250192130 Independent Escort Serv...VIP High Class Call Girls Amravati Anushka 8250192130 Independent Escort Serv...
VIP High Class Call Girls Amravati Anushka 8250192130 Independent Escort Serv...
 
Cunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile Service
Cunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile ServiceCunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile Service
Cunningham Road Call Girls Bangalore WhatsApp 8250192130 High Profile Service
 
Artificial Intelligence in Philippine Local Governance: Challenges and Opport...
Artificial Intelligence in Philippine Local Governance: Challenges and Opport...Artificial Intelligence in Philippine Local Governance: Challenges and Opport...
Artificial Intelligence in Philippine Local Governance: Challenges and Opport...
 
How the Congressional Budget Office Assists Lawmakers
How the Congressional Budget Office Assists LawmakersHow the Congressional Budget Office Assists Lawmakers
How the Congressional Budget Office Assists Lawmakers
 
2024: The FAR, Federal Acquisition Regulations - Part 28
2024: The FAR, Federal Acquisition Regulations - Part 282024: The FAR, Federal Acquisition Regulations - Part 28
2024: The FAR, Federal Acquisition Regulations - Part 28
 
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
 
##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas Whats Up Number
##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas  Whats Up Number##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas  Whats Up Number
##9711199012 Call Girls Delhi Rs-5000 UpTo 10 K Hauz Khas Whats Up Number
 
Call Girls In Rohini ꧁❤ 🔝 9953056974🔝❤꧂ Escort ServiCe
Call Girls In  Rohini ꧁❤ 🔝 9953056974🔝❤꧂ Escort ServiCeCall Girls In  Rohini ꧁❤ 🔝 9953056974🔝❤꧂ Escort ServiCe
Call Girls In Rohini ꧁❤ 🔝 9953056974🔝❤꧂ Escort ServiCe
 
Zechariah Boodey Farmstead Collaborative presentation - Humble Beginnings
Zechariah Boodey Farmstead Collaborative presentation -  Humble BeginningsZechariah Boodey Farmstead Collaborative presentation -  Humble Beginnings
Zechariah Boodey Farmstead Collaborative presentation - Humble Beginnings
 
Club of Rome: Eco-nomics for an Ecological Civilization
Club of Rome: Eco-nomics for an Ecological CivilizationClub of Rome: Eco-nomics for an Ecological Civilization
Club of Rome: Eco-nomics for an Ecological Civilization
 
Climate change and occupational safety and health.
Climate change and occupational safety and health.Climate change and occupational safety and health.
Climate change and occupational safety and health.
 
Goa Escorts WhatsApp Number South Goa Call Girl … 8588052666…
Goa Escorts WhatsApp Number South Goa Call Girl … 8588052666…Goa Escorts WhatsApp Number South Goa Call Girl … 8588052666…
Goa Escorts WhatsApp Number South Goa Call Girl … 8588052666…
 
(VASUDHA) Call Girls Balaji Nagar ( 7001035870 ) HI-Fi Pune Escorts Service
(VASUDHA) Call Girls Balaji Nagar ( 7001035870 ) HI-Fi Pune Escorts Service(VASUDHA) Call Girls Balaji Nagar ( 7001035870 ) HI-Fi Pune Escorts Service
(VASUDHA) Call Girls Balaji Nagar ( 7001035870 ) HI-Fi Pune Escorts Service
 
VIP Kolkata Call Girl Jatin Das Park 👉 8250192130 Available With Room
VIP Kolkata Call Girl Jatin Das Park 👉 8250192130  Available With RoomVIP Kolkata Call Girl Jatin Das Park 👉 8250192130  Available With Room
VIP Kolkata Call Girl Jatin Das Park 👉 8250192130 Available With Room
 
Call Girls Service AECS Layout Just Call 7001305949 Enjoy College Girls Service
Call Girls Service AECS Layout Just Call 7001305949 Enjoy College Girls ServiceCall Girls Service AECS Layout Just Call 7001305949 Enjoy College Girls Service
Call Girls Service AECS Layout Just Call 7001305949 Enjoy College Girls Service
 
Delhi Russian Call Girls In Connaught Place ➡️9999965857 India's Finest Model...
Delhi Russian Call Girls In Connaught Place ➡️9999965857 India's Finest Model...Delhi Russian Call Girls In Connaught Place ➡️9999965857 India's Finest Model...
Delhi Russian Call Girls In Connaught Place ➡️9999965857 India's Finest Model...
 

Day 02 - EDPS Technology & Privacy unit.pdf

  • 1. EUROPEAN DATA PROTECTION SUPERVISOR The EU’s independent data protection authority Data-protection in the Western Balkans and Eastern Partnership Region EDPS Technology & Privacy unit Massimo ATTORESI Deputy Head of T&P unit 19 September 2023
  • 2. 2 A bit about the TP unit: our story 2012 2019 2023 Technology Sector created 2 people Our Composition and Expertise –Multidisciplinarystaff with focus on technologicaland scientific research Expertise in Telecommunications, Computer engineering, Computer science, Physics, Auditing, Information security etc. Technology sector becomes Technology and Privacy unit 8 people Technology unit grows to 15 people
  • 3. Technology & Privacy Unit 3 The Supervisor Secretary/General Cabinet Supervision & Enforcement Policy & Consultation Technology & Privacy Governance & Internal Compliance Information & Communication HR, Budget & Administration EDPB Secretariat
  • 4. 4 What T&P Unit does? Support functions SupportPolicy and Consultation Unit in technologicial matters (informal-formal Consultations, Opinions). Participation in EDPB subgroups, international fora (GPA, Spring Conference, int. organisations) Direct Attributions SupportSupervision and EnforcementUnit in technological matters (prior consultations, mainly in AFSJ, joint Audits/Investigations, Complaints). In a few cases, with high technological focus, TP is on the lead. Supportour Director in Security Functions LSO and LISO Functions. Technology monitoring & foresight Techsonar, TechDispatch, IPEN organisation, preparation guidelines specific topics, training in PETS, collaboration with other organisations in technology matters ( in the EU, such as ENISA, international, such as IWGDPT/Berlin Group), support Supervisor & Sec Gen Technology and Privacy Unit IT function EDPS own IT needs as an institution: IT Strategy, IT Governance, Local IT support. Own systems, NextCloud, EuVideo-Voice, PKI infrastructure. Auditing tolos such as WEC, mobile apps lab. IT Audits Mainly in the context of Large Scale IT Systems and Coordinated Supervision. Data Breach Notification Handling
  • 5. 6 How are we organised? Management Luis Velasco (HoU) Massimo Attoresi (DHoU) Technology Monitoring and Foresight Sector System Oversight and Technology Audits Digital Transformation • IRM – IT Governance • ICDT • IT Strategy, IT Feasibility Study • SLA EP • Local IT function • Innovation Projects • IT audits on Large Scale IT systems • Other IT audits outside ASFJ area • Data breach notifications, DBN Guidelines and DBN system • Expertise in AFSJ including support the other two sectors and to P&C, S&E and EDPB • DPO meetings • Technological expertise including support the other two sectors and to PC and SE in the rest of topics, Digital Euro, Cloud, AI, Blockchain, Surveillance, Finance, Health, eGovernment, Data Spaces.... • Guidelines on technology topics • Foresight activities. TechSonar & TechDispatch • Contributions to EDPB in topics above • IPEN Organisation • Berlin Group, GPA....
  • 6. 7 Personal Data Breaches • “a breach of security leading to the accidental unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed” EUDPR Art. 3(16)
  • 7. 8 Personal Data Breaches Root causes of personal data breaches 2019-2022
  • 8. 9 Our topics of interest
  • 10. 11 Technology Monitoring: TechSonar (Foresight dimension) TechSonar aims to anticipate emerging technology trends: the main aim of this initiative is to better understand future developments in the technology sector from a data protection perspective.
  • 11. 12 Technology Monitoring: TechDispatch Smart speakers Connected Cars Contact Tracing with Apps Quantum Computing Facial Emotion Recognition Card Based Systems Federated Social Media Platforms TechDispatch provides factual descriptions of a new technology, preliminarily assesses possible impacts on privacy and the protection of personal data, as we understand them now, and provides links to further recommended reading.
  • 12. 13 Technology Monitoring: IPEN network The purpose of exchange with Academia and Engineers in the IPEN Network is to bring together developers and data protection experts with a technical background from different areas in order to launch and support projects that build privacy into everyday tools and develop new tools that can effectively protect and enhance our privacy. IPEN2023 – Explainable AI IPEN2022 - CBDC IPEN2022 - DigitalIdentity IPEN2021 - Pseudonymisation IPEN2021 SyntheticData Webinar IPEN2020 - Contact Tracing Apps webinar IPEN2020 - Encryption webinar IPEN2020 - Online Workshop IPEN2020 - Panel on Web Tracking IPENWorkshop 2019 - Rome IPENData Protection Day Workshop 2019 IPENWorkshop 2018 - Barcelona IPENWorkshop 2017 - Vienna IPENWorkshop 2016 - Frankfurt IPENWorkshop 2015 - Leuven IPENWorkshop 2014 – Berlin
  • 13. • Guidelineson personal data and electronic communicationsin the EU institutions (eCommunicationsguidelines) • Guidelineson Personal Data BreachNotification • IT governanceand IT management • Guidelineson the use of cloud computing services by the Europeaninstitutions and bodies • Mobile Devices • Mobile Applications • Web Services • Security Measures for Personal Data Processing 14 Technology & Privacy – EDPS Guidelines
  • 14. 15 The Web is watching you: Watch back with the “WEC”
  • 15. 16 Various Compliance Tools for Website Controllers Cloud Solutions • Qualys SSL Labs (HTTPS check) • Cookiebot (Cookiecheck) • PrivacyScore, Webbkoll (Cookies, HTTPS, etc.) • OneTrust (Cookiecheck) Problems • no scans in intranets • confidentiality or compliance issues • transparency, reproducibility of the cloud solution On-Premise Solutions • OpenWPM by Mozilla • WebXray • Developer Toolbar (Firefox and Chrome) • Website Evidence Collector bytheEDPS • Website Evidence Collector by the EDPS
  • 16. 17 Website Evidence Collector (WEC) from the EDPS Features • automated, reproducible evidence collection • records screenshots, cookies, traffic, potential web beacons, HTTPS security • no legal judgements: data protectionlaw agnostic Output • machine- and human-readable output • with many details to identify tracking issues
  • 17. 18 Digital Sovereignty – EDPS Fediverse pilots • EDPS launched on 28 April 2022 Fediverse pilot and invites other EU institutions to participate. • EU Voice powered by Mastodon with 35 accounts of EU institutions, bodies, agencies https://social.network.europa.eu • EU Video powered by Peertube with about 6 accounts https://tube.network.europa.eu(originally EU Tube) ...and an ongoing Pilot on a sovereign Cloud - NextCloud collaborationtools
  • 18. T&P unit follows closely EU legislative developments with a significant technology dimension. Files include: • The ArtificialIntelligence Act (AIA) • Digital Services Act (DSA), the Digital Markets Act (DMA), the Data Governance Act (DGA) and the Data Act • Regulation as regards establishing a framework for a European Digital Identity • Digital Euro joint Opinion with the EDPB • Regulation laying down rules to prevent and combat child sexual abuse • Regulation on the digitalisationof the visa procedure • Directiveon informationexchange between law enforcement authorities of Member States 19 Legislative proposals followed by T&P
  • 19. 20 Collaboration with EDPB and EDPB secretariat • Interface with the European Parliament for the provisionof general basic services to all the EDPS units including the EDPB Secretariat • Collaborationwith EDPB Secretariat in the organisation of the Website Audit BootCamp • Participationin the EDPB “ChatGPT taskforce” • Management of projects using EDPB Expert pool of experts in the field of ArtificialIntelligence. • Collaborationin TECH subgroup within the EDPB. Co-rapporteurs in multiple documents such pseudo-anonymisation, blockchain, .... • Supervision of Large Scale IT Systems and contributionto the Coordianted Supervision Committee
  • 20. 21 Artificial Intelligence & AI Act • EDPS has been identifying and assessing AI risks under GDPR/EUDPR • AI Act identifies the EDPS as the AI competent authority for the EU institutions • Preparations will start to understand our tasks, interaction with MSs national competent and market authorities, interaction with applicable data protectionlaw, the role of « regulatory sandboxes »
  • 21. @EU_EDPS European Data Protection Supervison EDPS The EU’s independent data protection authority EUROPEAN DATA PROTECTION SUPERVISOR Some icons from https://www.flaticon.com/ Word cloud created in https://wordart.com