SlideShare a Scribd company logo
1 of 13
Download to read offline
5/3/2018
1
GDPR and Dynamics 365 – the
Waldorf and Statler
perspective
Joris Poelmans, Realdolmen, @jopxtwits
Stephane Dorrekens, Business Elements, @stephanedujour
Interactive session:
• GDPR introduction & basics
• Impact on Dynamics 365
• Real life examples
Remarks:
• Share your feedback
• No simple answers
• Inspired by sessions from @MimCRM (Mohamed Mostafa CRM MVP)
• Not an exclusive list of considerations or solution design approaches
• Disclaimer: no warranty!
J
5/3/2018
2
EU launched Data
Protection Directive
back in 1995
When <1% of EU
citizens accessed
the internet
J
Things are about to change …
• Extension of existing privacy practices
• Enforcement of regulation vs recommendations &
guidelines
J
5/3/2018
3
New Framework: GDPR
 Into effect on May 25th 2018
 Modernize the obsolete 95 directive
 Create a unified EU law to replace the
current haywire of inconsistent
framework
 Applies both to processors and
controllers
 Administrative sanctions – up to 20
mio EUR or 4% of yearly turnover
J
Data processing must comply with 6 GDPR
principles
1. Lawfulness, fairness and transparency
2. Purpose limitation
3. Retention
4. Integrity and confidentiality
5. Data minimization
6. Accuracy
J
“the controller shall be responsible
for, and be able to demonstrate,
compliance with the principles”
5/3/2018
4
What is processing?
S
Key changes in GDPR
• Single set of rules across EU – territorial scope
• One stop shop
• New right for individuals:
• Subject consent expands
• Insight into data
• Right to be forgotten
• Extra accountability and responsibility for data controllers
• Data portability
• Data breach notification
• Data Protection Impact Assessments
• Appointing a Data Protection Officer
• Higher sanctions (€€€)
S
5/3/2018
5
Impacted areas in Dynamics 365
Data classification
(PII and sensitive
data)
Consent and data
access controls
Auditing,
monitoring,
security and
reporting
Governance
S
Impacted areas in Dynamics 365
Data classification
(PII and sensitive
data)
Consent and data
access controls
Auditing,
monitoring,
security and
reporting
Governance
J
5/3/2018
6
Data classification – PII and sensitive data
Factors specific to the physical, physiological, genetic, mental,
economic, cultural or social identity (hobbies and leisure, …)
Name, address,email, date of birth
Identification number (e.g. RRN)
Location data (address, GPS/geolocation)
Online identifiers (IP addresses, cookies, …)
J
Sensitive: racial or ethnic origin, political opinions, religious or
philosophical beliefs, genetic or biometric data, health data, union
membership, sexual orientation, etc …
Data classification – challenge of
duplicate/incomplete customer records
J
Mia Smith
m.smith@hotmail.com
Ms. Smith
mia.smith@gmail.com
Ms. Mia Smith
mia.smith@gmail.com
25/5/1992
003277979794
5/3/2018
7
Data classification – deduplication using
machine learning
• Video- https://www.tamr.com/video/tamr-helping-toyota-motor-europe-create-connected-
seamless-customer-experience/
J
Data classification –
Dynamics 365 design options/considerations
• The 5 Ws of personal data
• Use multiple forms: minimum & full, separate non-sensitive and
sensitive data, apply field level security
• Limit/remove data export privileges
• Security roles, access teams, field level security, business units
• Consider storing sensitive data in data warehouse for
aggregate reporting only
• Run regular “Bulk delete” jobs to satisfy your data retention
policies (taking into account interactions/transactions)
• What about file and email attachments?
J
5/3/2018
8
Impacted areas in Dynamics 365
Data classification
(PII and sensitive
data)
Consent and data
access controls
Auditing,
monitoring,
security and
reporting
Governance
S
Consent and data access controls
S
5/3/2018
9
Consent and data access controls–
Dynamics 365 design options/considerations
• Capture consent information in CRM
• Web Site (CRM Portal, Customer Web Sites,..)
• Landing Pages (Dynamics Marketing, Click Dimensions, Adobe,..)
• Self Service Portals (ie: Myxxxx)
• Internal Systems (ie: DWH, Mainframe, etc..)
• NB: For GDPR - consent is not per person but by contact point per usage/purpose (ie: email, phone, etc.)
• Use consent information in CRM
• Outbound integration with Digital Marketing Tools
• Outbound integration with Call Centers
• OOB Campaign Activity
• NB: CRM OOB Usage is per contact/lead not contact point
S
Consent and data access controls–
Dynamics 365 design options/considerations
• Consent Audit Log
• Not sufficient if records can be deleted -> No delete
• Optin vs Optout
• Right to be forgotten, portability & access own data
• Properly identify the person (see Governance)
• It’s easier to delete data for non customers but easier to identify customers
• Use a Unique identifier to find all related data in all systems (ie: CRM GUID is good option)
• Not all data CAN be deleted as some are needed for operational or legal archiving
• Bulk Delete is often not enough, think about other data retentions systems (DHW, BI, Backups,
Excel, etc..)
S
5/3/2018
10
Sample
Implementation
CRM Data
Structure
S
Impacted areas in Dynamics 365
Data classification
(PII and sensitive
data)
Consent and data
access controls
Auditing,
monitoring,
security and
reporting
Governance
J
5/3/2018
11
Auditing, monitoring, security and reporting
GDPR requires:
• Pro-active risk based approach: “Always monitoring” and
“Intelligent” breach detection and notification
• Robust procedures for reporting breaches & processes for
reviewing compliance
• Compliance investigations will look at controls, monitoring,
auditing and effective reporting
• For hosted solutions : accountability & reporting on every
person/entity with access to the data (full supply chain)
J
Auditing, monitoring and reporting
Dynamics 365 design options/considerations
• Auditing functionality available on customer entities (contacts, leads,
accounts,custom entities)
• For CRM Online –Activity Log Management available
• Document security mechanism incl. authentication & authorization
• CRM data access security model: system and business roles
• What about dev/test/acc/prod?
• …
• Transparent Data Encryption – change key … and then back it up
• For on premise – SQL Enterprise Edition required
• Cloud vs on premise
J
5/3/2018
12
Impacted areas in Dynamics 365
Data classification
(PII and sensitive
data)
Consent and data
access controls
Auditing,
monitoring,
security and
reporting
Governance
S
Governance
Dynamics 365 design options/considerations
What are existing policies, roles & responsibilities (shared responsibility controller and processor)
Dynamics 365 for Customer Services can help the Data Privacy Office/Officer
• Manage the requests and respects SLA’s.
• Find all pertaining information (as most/all is in CRM and/or the primary links are)
• Communicate the information to the parties (Notification Obligation)
Some Examples of Case Business Flows
Data Breach Information (72h delay)
Right to delete
Right for information
Right for rectification
Right for portability
Right to object
Manual Requests for Optout
…
S
5/3/2018
13
References
• https://www.microsoft.com/en-us/trustcenter/cloudservices/dynamics365
• http://www.mohamedmostafa.co.uk/blog/category/gdpr/
• http://jopx.blogspot.be/2018/04/update-on-activity-log-management-for.html
• https://technet.microsoft.com/en-us/library/jj134930.aspx (Dynamics 365 security and compliance
planning guide)
• https://docs.microsoft.com/en-us/dynamics365/customer-engagement/portals/implement-gdpr
• https://www.eugdpr.org/
• https://docs.microsoft.com/en-us/dynamics365/get-started/gdpr/
S

More Related Content

What's hot

BigID Virtual MDM Data Sheet
BigID Virtual MDM Data SheetBigID Virtual MDM Data Sheet
BigID Virtual MDM Data SheetDimitri Sirota
 
Balancing Regulatory Transparency with Data Protection
Balancing Regulatory Transparency with Data ProtectionBalancing Regulatory Transparency with Data Protection
Balancing Regulatory Transparency with Data ProtectionLeigh Hill
 
BigID Data Sheet: GDPR Compliance
BigID Data Sheet: GDPR ComplianceBigID Data Sheet: GDPR Compliance
BigID Data Sheet: GDPR ComplianceBigID Inc
 
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital MarketersOne North
 
Common Data Protection Issues in Managing M&A Deals
Common Data Protection Issues in Managing M&A DealsCommon Data Protection Issues in Managing M&A Deals
Common Data Protection Issues in Managing M&A DealsMatheson Law Firm
 
Collibra Data Citizen '19 - Bridging Data Privacy with Data Governance
Collibra Data Citizen '19 - Bridging Data Privacy with Data Governance Collibra Data Citizen '19 - Bridging Data Privacy with Data Governance
Collibra Data Citizen '19 - Bridging Data Privacy with Data Governance BigID Inc
 
BigID Data Subject Rights Automation for GDPR & Privacy Data Sheet
BigID Data Subject Rights Automation for GDPR & Privacy Data SheetBigID Data Subject Rights Automation for GDPR & Privacy Data Sheet
BigID Data Subject Rights Automation for GDPR & Privacy Data SheetDimitri Sirota
 
Mastering Big Data: The Next Big Leap for Master Data Management
Mastering Big Data: The Next Big Leap for Master Data ManagementMastering Big Data: The Next Big Leap for Master Data Management
Mastering Big Data: The Next Big Leap for Master Data ManagementCognizant
 
The Right Steps to Becoming GDPR Compliant
The Right Steps to Becoming GDPR CompliantThe Right Steps to Becoming GDPR Compliant
The Right Steps to Becoming GDPR CompliantWSO2
 
Master Data Management
Master Data ManagementMaster Data Management
Master Data ManagementMoniqueO Opris
 
Denodo Data Innovation Award: Digital Transformation & Regulatory Excellence ...
Denodo Data Innovation Award: Digital Transformation & Regulatory Excellence ...Denodo Data Innovation Award: Digital Transformation & Regulatory Excellence ...
Denodo Data Innovation Award: Digital Transformation & Regulatory Excellence ...Denodo
 
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPRSrijan Technologies
 
BigID, OneTrust, IAPP Webinar: Bridging the Privacy Office with IT
BigID, OneTrust, IAPP Webinar: Bridging the Privacy Office with ITBigID, OneTrust, IAPP Webinar: Bridging the Privacy Office with IT
BigID, OneTrust, IAPP Webinar: Bridging the Privacy Office with ITBigID Inc
 
The Role of GDPR in Customer Identity and Access Management
The Role of GDPR in Customer Identity and Access ManagementThe Role of GDPR in Customer Identity and Access Management
The Role of GDPR in Customer Identity and Access ManagementWSO2
 
Internal vs. external identity access management
Internal vs. external identity access managementInternal vs. external identity access management
Internal vs. external identity access managementTatiana Grisham
 
Data Protection Officer Dashboard | GDPR
Data Protection Officer Dashboard | GDPRData Protection Officer Dashboard | GDPR
Data Protection Officer Dashboard | GDPRCorporater
 
Master data management and data warehousing
Master data management and data warehousingMaster data management and data warehousing
Master data management and data warehousingZahra Mansoori
 

What's hot (19)

BigID Virtual MDM Data Sheet
BigID Virtual MDM Data SheetBigID Virtual MDM Data Sheet
BigID Virtual MDM Data Sheet
 
Balancing Regulatory Transparency with Data Protection
Balancing Regulatory Transparency with Data ProtectionBalancing Regulatory Transparency with Data Protection
Balancing Regulatory Transparency with Data Protection
 
BigID Data Sheet: GDPR Compliance
BigID Data Sheet: GDPR ComplianceBigID Data Sheet: GDPR Compliance
BigID Data Sheet: GDPR Compliance
 
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
 
Common Data Protection Issues in Managing M&A Deals
Common Data Protection Issues in Managing M&A DealsCommon Data Protection Issues in Managing M&A Deals
Common Data Protection Issues in Managing M&A Deals
 
Collibra Data Citizen '19 - Bridging Data Privacy with Data Governance
Collibra Data Citizen '19 - Bridging Data Privacy with Data Governance Collibra Data Citizen '19 - Bridging Data Privacy with Data Governance
Collibra Data Citizen '19 - Bridging Data Privacy with Data Governance
 
BigID Data Subject Rights Automation for GDPR & Privacy Data Sheet
BigID Data Subject Rights Automation for GDPR & Privacy Data SheetBigID Data Subject Rights Automation for GDPR & Privacy Data Sheet
BigID Data Subject Rights Automation for GDPR & Privacy Data Sheet
 
Mastering Big Data: The Next Big Leap for Master Data Management
Mastering Big Data: The Next Big Leap for Master Data ManagementMastering Big Data: The Next Big Leap for Master Data Management
Mastering Big Data: The Next Big Leap for Master Data Management
 
The Right Steps to Becoming GDPR Compliant
The Right Steps to Becoming GDPR CompliantThe Right Steps to Becoming GDPR Compliant
The Right Steps to Becoming GDPR Compliant
 
Master Data Management
Master Data ManagementMaster Data Management
Master Data Management
 
Orion Laboratory
Orion Laboratory Orion Laboratory
Orion Laboratory
 
Denodo Data Innovation Award: Digital Transformation & Regulatory Excellence ...
Denodo Data Innovation Award: Digital Transformation & Regulatory Excellence ...Denodo Data Innovation Award: Digital Transformation & Regulatory Excellence ...
Denodo Data Innovation Award: Digital Transformation & Regulatory Excellence ...
 
bitrix24.es
bitrix24.esbitrix24.es
bitrix24.es
 
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
 
BigID, OneTrust, IAPP Webinar: Bridging the Privacy Office with IT
BigID, OneTrust, IAPP Webinar: Bridging the Privacy Office with ITBigID, OneTrust, IAPP Webinar: Bridging the Privacy Office with IT
BigID, OneTrust, IAPP Webinar: Bridging the Privacy Office with IT
 
The Role of GDPR in Customer Identity and Access Management
The Role of GDPR in Customer Identity and Access ManagementThe Role of GDPR in Customer Identity and Access Management
The Role of GDPR in Customer Identity and Access Management
 
Internal vs. external identity access management
Internal vs. external identity access managementInternal vs. external identity access management
Internal vs. external identity access management
 
Data Protection Officer Dashboard | GDPR
Data Protection Officer Dashboard | GDPRData Protection Officer Dashboard | GDPR
Data Protection Officer Dashboard | GDPR
 
Master data management and data warehousing
Master data management and data warehousingMaster data management and data warehousing
Master data management and data warehousing
 

Similar to GDPR and Dynamics 365 - the Waldorf and Statler perspective

Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"
Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"
Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"Ragnar Heil
 
Workable Enteprise Data Governance
Workable Enteprise Data GovernanceWorkable Enteprise Data Governance
Workable Enteprise Data GovernanceBhavendra Chavan
 
Maclear’s IT GRC Tools – Key Issues and Trends
Maclear’s  IT GRC Tools – Key Issues and TrendsMaclear’s  IT GRC Tools – Key Issues and Trends
Maclear’s IT GRC Tools – Key Issues and TrendsMaclear LLC
 
Big data initiative justification and prioritization framework
Big data initiative justification and prioritization frameworkBig data initiative justification and prioritization framework
Big data initiative justification and prioritization frameworkNeerajsabhnani
 
GDPR: 20 Million Reasons to Get Ready - Part 2: Living Compliance
GDPR: 20 Million Reasons to Get Ready - Part 2: Living ComplianceGDPR: 20 Million Reasons to Get Ready - Part 2: Living Compliance
GDPR: 20 Million Reasons to Get Ready - Part 2: Living ComplianceCloudera, Inc.
 
Enterprise Data World Webinars: Master Data Management: Ensuring Value is Del...
Enterprise Data World Webinars: Master Data Management: Ensuring Value is Del...Enterprise Data World Webinars: Master Data Management: Ensuring Value is Del...
Enterprise Data World Webinars: Master Data Management: Ensuring Value is Del...DATAVERSITY
 
Information Governance: Reducing Costs and Increasing Customer Satisfaction
Information Governance: Reducing Costs and Increasing Customer SatisfactionInformation Governance: Reducing Costs and Increasing Customer Satisfaction
Information Governance: Reducing Costs and Increasing Customer SatisfactionCapgemini
 
Is Your Agency Data Challenged?
Is Your Agency Data Challenged?Is Your Agency Data Challenged?
Is Your Agency Data Challenged?DLT Solutions
 
Cracking the Code- Expert Tips for Mastering GRC CollabDays Bletchley Sept 23...
Cracking the Code- Expert Tips for Mastering GRC CollabDays Bletchley Sept 23...Cracking the Code- Expert Tips for Mastering GRC CollabDays Bletchley Sept 23...
Cracking the Code- Expert Tips for Mastering GRC CollabDays Bletchley Sept 23...Nikki Chapple
 
Data- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerData- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerCapgemini
 
Digital Marketing Analytics Certification - Session One
Digital Marketing Analytics Certification - Session OneDigital Marketing Analytics Certification - Session One
Digital Marketing Analytics Certification - Session OneBrand Digital, Inc
 
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPRDigital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPRRichard Veryard
 
Labelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & SensitivityLabelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & SensitivityDrew Madelung
 
[Webinar Slides] Data Explosion in Your Organization? Harness It with a Compr...
[Webinar Slides] Data Explosion in Your Organization? Harness It with a Compr...[Webinar Slides] Data Explosion in Your Organization? Harness It with a Compr...
[Webinar Slides] Data Explosion in Your Organization? Harness It with a Compr...AIIM International
 
Metadata-Driven Cleanup of Files, Content, and Email Webinar
Metadata-Driven Cleanup of Files, Content, and Email WebinarMetadata-Driven Cleanup of Files, Content, and Email Webinar
Metadata-Driven Cleanup of Files, Content, and Email WebinarConcept Searching, Inc
 
Achieving Digital Transformation in Regulatory
Achieving Digital Transformation in RegulatoryAchieving Digital Transformation in Regulatory
Achieving Digital Transformation in RegulatoryCary Smithson
 
Emerging Data Quality Trends for Governing and Analyzing Big Data
Emerging Data Quality Trends for Governing and Analyzing Big DataEmerging Data Quality Trends for Governing and Analyzing Big Data
Emerging Data Quality Trends for Governing and Analyzing Big DataPrecisely
 
CRM Data Myths
CRM Data MythsCRM Data Myths
CRM Data MythsRingLead
 

Similar to GDPR and Dynamics 365 - the Waldorf and Statler perspective (20)

Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"
Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"
Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
Workable Enteprise Data Governance
Workable Enteprise Data GovernanceWorkable Enteprise Data Governance
Workable Enteprise Data Governance
 
Maclear’s IT GRC Tools – Key Issues and Trends
Maclear’s  IT GRC Tools – Key Issues and TrendsMaclear’s  IT GRC Tools – Key Issues and Trends
Maclear’s IT GRC Tools – Key Issues and Trends
 
Big data initiative justification and prioritization framework
Big data initiative justification and prioritization frameworkBig data initiative justification and prioritization framework
Big data initiative justification and prioritization framework
 
GDPR: 20 Million Reasons to Get Ready - Part 2: Living Compliance
GDPR: 20 Million Reasons to Get Ready - Part 2: Living ComplianceGDPR: 20 Million Reasons to Get Ready - Part 2: Living Compliance
GDPR: 20 Million Reasons to Get Ready - Part 2: Living Compliance
 
Enterprise Data World Webinars: Master Data Management: Ensuring Value is Del...
Enterprise Data World Webinars: Master Data Management: Ensuring Value is Del...Enterprise Data World Webinars: Master Data Management: Ensuring Value is Del...
Enterprise Data World Webinars: Master Data Management: Ensuring Value is Del...
 
Andy Malone - Microsoft office 365 security deep dive
Andy Malone - Microsoft office 365 security deep diveAndy Malone - Microsoft office 365 security deep dive
Andy Malone - Microsoft office 365 security deep dive
 
Information Governance: Reducing Costs and Increasing Customer Satisfaction
Information Governance: Reducing Costs and Increasing Customer SatisfactionInformation Governance: Reducing Costs and Increasing Customer Satisfaction
Information Governance: Reducing Costs and Increasing Customer Satisfaction
 
Is Your Agency Data Challenged?
Is Your Agency Data Challenged?Is Your Agency Data Challenged?
Is Your Agency Data Challenged?
 
Cracking the Code- Expert Tips for Mastering GRC CollabDays Bletchley Sept 23...
Cracking the Code- Expert Tips for Mastering GRC CollabDays Bletchley Sept 23...Cracking the Code- Expert Tips for Mastering GRC CollabDays Bletchley Sept 23...
Cracking the Code- Expert Tips for Mastering GRC CollabDays Bletchley Sept 23...
 
Data- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerData- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offer
 
Digital Marketing Analytics Certification - Session One
Digital Marketing Analytics Certification - Session OneDigital Marketing Analytics Certification - Session One
Digital Marketing Analytics Certification - Session One
 
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPRDigital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPR
 
Labelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & SensitivityLabelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & Sensitivity
 
[Webinar Slides] Data Explosion in Your Organization? Harness It with a Compr...
[Webinar Slides] Data Explosion in Your Organization? Harness It with a Compr...[Webinar Slides] Data Explosion in Your Organization? Harness It with a Compr...
[Webinar Slides] Data Explosion in Your Organization? Harness It with a Compr...
 
Metadata-Driven Cleanup of Files, Content, and Email Webinar
Metadata-Driven Cleanup of Files, Content, and Email WebinarMetadata-Driven Cleanup of Files, Content, and Email Webinar
Metadata-Driven Cleanup of Files, Content, and Email Webinar
 
Achieving Digital Transformation in Regulatory
Achieving Digital Transformation in RegulatoryAchieving Digital Transformation in Regulatory
Achieving Digital Transformation in Regulatory
 
Emerging Data Quality Trends for Governing and Analyzing Big Data
Emerging Data Quality Trends for Governing and Analyzing Big DataEmerging Data Quality Trends for Governing and Analyzing Big Data
Emerging Data Quality Trends for Governing and Analyzing Big Data
 
CRM Data Myths
CRM Data MythsCRM Data Myths
CRM Data Myths
 

More from Joris Poelmans

Dynamics Power! Saturday Brussels 2019 - transitioning to the unified interface
Dynamics Power! Saturday Brussels 2019 - transitioning to the unified interfaceDynamics Power! Saturday Brussels 2019 - transitioning to the unified interface
Dynamics Power! Saturday Brussels 2019 - transitioning to the unified interfaceJoris Poelmans
 
CRM UG Belux March 2017 - Power BI and Dynamics 365
CRM UG Belux March 2017 - Power BI and Dynamics 365CRM UG Belux March 2017 - Power BI and Dynamics 365
CRM UG Belux March 2017 - Power BI and Dynamics 365Joris Poelmans
 
Dynamics 365 Saturday Amsterdam 02/2018 - Dynamics 365 and chatbots
Dynamics 365 Saturday Amsterdam 02/2018 - Dynamics 365 and chatbotsDynamics 365 Saturday Amsterdam 02/2018 - Dynamics 365 and chatbots
Dynamics 365 Saturday Amsterdam 02/2018 - Dynamics 365 and chatbotsJoris Poelmans
 
What’s new on the Microsoft Azure Data Platform
What’s new on the Microsoft Azure Data Platform What’s new on the Microsoft Azure Data Platform
What’s new on the Microsoft Azure Data Platform Joris Poelmans
 
How to build your own Delve: combining machine learning, big data and SharePoint
How to build your own Delve: combining machine learning, big data and SharePointHow to build your own Delve: combining machine learning, big data and SharePoint
How to build your own Delve: combining machine learning, big data and SharePointJoris Poelmans
 
imec Share - An Office 365 customer case
imec Share - An Office 365 customer caseimec Share - An Office 365 customer case
imec Share - An Office 365 customer caseJoris Poelmans
 
IMEC Share - Innovate, collaborate and excel
IMEC Share - Innovate, collaborate and excelIMEC Share - Innovate, collaborate and excel
IMEC Share - Innovate, collaborate and excelJoris Poelmans
 
The future of business process apps - a Microsoft perspective
The future of business process apps - a Microsoft perspectiveThe future of business process apps - a Microsoft perspective
The future of business process apps - a Microsoft perspectiveJoris Poelmans
 
Yammer Social Data Mining
Yammer Social Data MiningYammer Social Data Mining
Yammer Social Data MiningJoris Poelmans
 
MSDN - SharePoint 2013 to app or not to app
MSDN - SharePoint 2013 to app or not to appMSDN - SharePoint 2013 to app or not to app
MSDN - SharePoint 2013 to app or not to appJoris Poelmans
 
Everything you always wanted to know about SharePoint 2013 Search relevance
Everything you always wanted to know about SharePoint 2013 Search relevanceEverything you always wanted to know about SharePoint 2013 Search relevance
Everything you always wanted to know about SharePoint 2013 Search relevanceJoris Poelmans
 
The Connected Company - Event Anders Vergaderen
The Connected Company - Event Anders VergaderenThe Connected Company - Event Anders Vergaderen
The Connected Company - Event Anders VergaderenJoris Poelmans
 
Building search-driven Windows 8 and Windows Phone 8 apps for SharePoint Serv...
Building search-driven Windows 8 and Windows Phone 8 apps for SharePoint Serv...Building search-driven Windows 8 and Windows Phone 8 apps for SharePoint Serv...
Building search-driven Windows 8 and Windows Phone 8 apps for SharePoint Serv...Joris Poelmans
 
Intro to MUI and variations in SharePoint 2010
Intro to MUI and variations in SharePoint 2010Intro to MUI and variations in SharePoint 2010
Intro to MUI and variations in SharePoint 2010Joris Poelmans
 
Building the SharePoint hot or not app ... or how not sell social to your boss
Building the SharePoint hot or not app ... or how not sell social to your bossBuilding the SharePoint hot or not app ... or how not sell social to your boss
Building the SharePoint hot or not app ... or how not sell social to your bossJoris Poelmans
 
SharePoint Server 2013 : The big five
SharePoint Server 2013 : The big fiveSharePoint Server 2013 : The big five
SharePoint Server 2013 : The big fiveJoris Poelmans
 
Apps for Office Introduction
Apps for Office IntroductionApps for Office Introduction
Apps for Office IntroductionJoris Poelmans
 
Fun with Social, Windows 8 and Javascript
Fun with Social, Windows 8 and JavascriptFun with Social, Windows 8 and Javascript
Fun with Social, Windows 8 and JavascriptJoris Poelmans
 
Exploring search driven applications with SharePoint 2013
Exploring search driven applications with SharePoint 2013Exploring search driven applications with SharePoint 2013
Exploring search driven applications with SharePoint 2013Joris Poelmans
 
SharePoint 2013 - What's new for Devs - Belgian IT Bootcamp 2012
SharePoint 2013 - What's new for Devs - Belgian IT Bootcamp 2012SharePoint 2013 - What's new for Devs - Belgian IT Bootcamp 2012
SharePoint 2013 - What's new for Devs - Belgian IT Bootcamp 2012Joris Poelmans
 

More from Joris Poelmans (20)

Dynamics Power! Saturday Brussels 2019 - transitioning to the unified interface
Dynamics Power! Saturday Brussels 2019 - transitioning to the unified interfaceDynamics Power! Saturday Brussels 2019 - transitioning to the unified interface
Dynamics Power! Saturday Brussels 2019 - transitioning to the unified interface
 
CRM UG Belux March 2017 - Power BI and Dynamics 365
CRM UG Belux March 2017 - Power BI and Dynamics 365CRM UG Belux March 2017 - Power BI and Dynamics 365
CRM UG Belux March 2017 - Power BI and Dynamics 365
 
Dynamics 365 Saturday Amsterdam 02/2018 - Dynamics 365 and chatbots
Dynamics 365 Saturday Amsterdam 02/2018 - Dynamics 365 and chatbotsDynamics 365 Saturday Amsterdam 02/2018 - Dynamics 365 and chatbots
Dynamics 365 Saturday Amsterdam 02/2018 - Dynamics 365 and chatbots
 
What’s new on the Microsoft Azure Data Platform
What’s new on the Microsoft Azure Data Platform What’s new on the Microsoft Azure Data Platform
What’s new on the Microsoft Azure Data Platform
 
How to build your own Delve: combining machine learning, big data and SharePoint
How to build your own Delve: combining machine learning, big data and SharePointHow to build your own Delve: combining machine learning, big data and SharePoint
How to build your own Delve: combining machine learning, big data and SharePoint
 
imec Share - An Office 365 customer case
imec Share - An Office 365 customer caseimec Share - An Office 365 customer case
imec Share - An Office 365 customer case
 
IMEC Share - Innovate, collaborate and excel
IMEC Share - Innovate, collaborate and excelIMEC Share - Innovate, collaborate and excel
IMEC Share - Innovate, collaborate and excel
 
The future of business process apps - a Microsoft perspective
The future of business process apps - a Microsoft perspectiveThe future of business process apps - a Microsoft perspective
The future of business process apps - a Microsoft perspective
 
Yammer Social Data Mining
Yammer Social Data MiningYammer Social Data Mining
Yammer Social Data Mining
 
MSDN - SharePoint 2013 to app or not to app
MSDN - SharePoint 2013 to app or not to appMSDN - SharePoint 2013 to app or not to app
MSDN - SharePoint 2013 to app or not to app
 
Everything you always wanted to know about SharePoint 2013 Search relevance
Everything you always wanted to know about SharePoint 2013 Search relevanceEverything you always wanted to know about SharePoint 2013 Search relevance
Everything you always wanted to know about SharePoint 2013 Search relevance
 
The Connected Company - Event Anders Vergaderen
The Connected Company - Event Anders VergaderenThe Connected Company - Event Anders Vergaderen
The Connected Company - Event Anders Vergaderen
 
Building search-driven Windows 8 and Windows Phone 8 apps for SharePoint Serv...
Building search-driven Windows 8 and Windows Phone 8 apps for SharePoint Serv...Building search-driven Windows 8 and Windows Phone 8 apps for SharePoint Serv...
Building search-driven Windows 8 and Windows Phone 8 apps for SharePoint Serv...
 
Intro to MUI and variations in SharePoint 2010
Intro to MUI and variations in SharePoint 2010Intro to MUI and variations in SharePoint 2010
Intro to MUI and variations in SharePoint 2010
 
Building the SharePoint hot or not app ... or how not sell social to your boss
Building the SharePoint hot or not app ... or how not sell social to your bossBuilding the SharePoint hot or not app ... or how not sell social to your boss
Building the SharePoint hot or not app ... or how not sell social to your boss
 
SharePoint Server 2013 : The big five
SharePoint Server 2013 : The big fiveSharePoint Server 2013 : The big five
SharePoint Server 2013 : The big five
 
Apps for Office Introduction
Apps for Office IntroductionApps for Office Introduction
Apps for Office Introduction
 
Fun with Social, Windows 8 and Javascript
Fun with Social, Windows 8 and JavascriptFun with Social, Windows 8 and Javascript
Fun with Social, Windows 8 and Javascript
 
Exploring search driven applications with SharePoint 2013
Exploring search driven applications with SharePoint 2013Exploring search driven applications with SharePoint 2013
Exploring search driven applications with SharePoint 2013
 
SharePoint 2013 - What's new for Devs - Belgian IT Bootcamp 2012
SharePoint 2013 - What's new for Devs - Belgian IT Bootcamp 2012SharePoint 2013 - What's new for Devs - Belgian IT Bootcamp 2012
SharePoint 2013 - What's new for Devs - Belgian IT Bootcamp 2012
 

Recently uploaded

Taming Distributed Systems: Key Insights from Wix's Large-Scale Experience - ...
Taming Distributed Systems: Key Insights from Wix's Large-Scale Experience - ...Taming Distributed Systems: Key Insights from Wix's Large-Scale Experience - ...
Taming Distributed Systems: Key Insights from Wix's Large-Scale Experience - ...Natan Silnitsky
 
Cyber security and its impact on E commerce
Cyber security and its impact on E commerceCyber security and its impact on E commerce
Cyber security and its impact on E commercemanigoyal112
 
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdf
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdfGOING AOT WITH GRAALVM – DEVOXX GREECE.pdf
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdfAlina Yurenko
 
A healthy diet for your Java application Devoxx France.pdf
A healthy diet for your Java application Devoxx France.pdfA healthy diet for your Java application Devoxx France.pdf
A healthy diet for your Java application Devoxx France.pdfMarharyta Nedzelska
 
Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...
Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...
Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...OnePlan Solutions
 
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...OnePlan Solutions
 
VK Business Profile - provides IT solutions and Web Development
VK Business Profile - provides IT solutions and Web DevelopmentVK Business Profile - provides IT solutions and Web Development
VK Business Profile - provides IT solutions and Web Developmentvyaparkranti
 
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)jennyeacort
 
Understanding Flamingo - DeepMind's VLM Architecture
Understanding Flamingo - DeepMind's VLM ArchitectureUnderstanding Flamingo - DeepMind's VLM Architecture
Understanding Flamingo - DeepMind's VLM Architecturerahul_net
 
Real-time Tracking and Monitoring with Cargo Cloud Solutions.pptx
Real-time Tracking and Monitoring with Cargo Cloud Solutions.pptxReal-time Tracking and Monitoring with Cargo Cloud Solutions.pptx
Real-time Tracking and Monitoring with Cargo Cloud Solutions.pptxRTS corp
 
Powering Real-Time Decisions with Continuous Data Streams
Powering Real-Time Decisions with Continuous Data StreamsPowering Real-Time Decisions with Continuous Data Streams
Powering Real-Time Decisions with Continuous Data StreamsSafe Software
 
Machine Learning Software Engineering Patterns and Their Engineering
Machine Learning Software Engineering Patterns and Their EngineeringMachine Learning Software Engineering Patterns and Their Engineering
Machine Learning Software Engineering Patterns and Their EngineeringHironori Washizaki
 
Software Project Health Check: Best Practices and Techniques for Your Product...
Software Project Health Check: Best Practices and Techniques for Your Product...Software Project Health Check: Best Practices and Techniques for Your Product...
Software Project Health Check: Best Practices and Techniques for Your Product...Velvetech LLC
 
MYjobs Presentation Django-based project
MYjobs Presentation Django-based projectMYjobs Presentation Django-based project
MYjobs Presentation Django-based projectAnoyGreter
 
Balasore Best It Company|| Top 10 IT Company || Balasore Software company Odisha
Balasore Best It Company|| Top 10 IT Company || Balasore Software company OdishaBalasore Best It Company|| Top 10 IT Company || Balasore Software company Odisha
Balasore Best It Company|| Top 10 IT Company || Balasore Software company Odishasmiwainfosol
 
Post Quantum Cryptography – The Impact on Identity
Post Quantum Cryptography – The Impact on IdentityPost Quantum Cryptography – The Impact on Identity
Post Quantum Cryptography – The Impact on Identityteam-WIBU
 
CRM Contender Series: HubSpot vs. Salesforce
CRM Contender Series: HubSpot vs. SalesforceCRM Contender Series: HubSpot vs. Salesforce
CRM Contender Series: HubSpot vs. SalesforceBrainSell Technologies
 
Implementing Zero Trust strategy with Azure
Implementing Zero Trust strategy with AzureImplementing Zero Trust strategy with Azure
Implementing Zero Trust strategy with AzureDinusha Kumarasiri
 
How to submit a standout Adobe Champion Application
How to submit a standout Adobe Champion ApplicationHow to submit a standout Adobe Champion Application
How to submit a standout Adobe Champion ApplicationBradBedford3
 
Xen Safety Embedded OSS Summit April 2024 v4.pdf
Xen Safety Embedded OSS Summit April 2024 v4.pdfXen Safety Embedded OSS Summit April 2024 v4.pdf
Xen Safety Embedded OSS Summit April 2024 v4.pdfStefano Stabellini
 

Recently uploaded (20)

Taming Distributed Systems: Key Insights from Wix's Large-Scale Experience - ...
Taming Distributed Systems: Key Insights from Wix's Large-Scale Experience - ...Taming Distributed Systems: Key Insights from Wix's Large-Scale Experience - ...
Taming Distributed Systems: Key Insights from Wix's Large-Scale Experience - ...
 
Cyber security and its impact on E commerce
Cyber security and its impact on E commerceCyber security and its impact on E commerce
Cyber security and its impact on E commerce
 
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdf
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdfGOING AOT WITH GRAALVM – DEVOXX GREECE.pdf
GOING AOT WITH GRAALVM – DEVOXX GREECE.pdf
 
A healthy diet for your Java application Devoxx France.pdf
A healthy diet for your Java application Devoxx France.pdfA healthy diet for your Java application Devoxx France.pdf
A healthy diet for your Java application Devoxx France.pdf
 
Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...
Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...
Maximizing Efficiency and Profitability with OnePlan’s Professional Service A...
 
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...
 
VK Business Profile - provides IT solutions and Web Development
VK Business Profile - provides IT solutions and Web DevelopmentVK Business Profile - provides IT solutions and Web Development
VK Business Profile - provides IT solutions and Web Development
 
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)
 
Understanding Flamingo - DeepMind's VLM Architecture
Understanding Flamingo - DeepMind's VLM ArchitectureUnderstanding Flamingo - DeepMind's VLM Architecture
Understanding Flamingo - DeepMind's VLM Architecture
 
Real-time Tracking and Monitoring with Cargo Cloud Solutions.pptx
Real-time Tracking and Monitoring with Cargo Cloud Solutions.pptxReal-time Tracking and Monitoring with Cargo Cloud Solutions.pptx
Real-time Tracking and Monitoring with Cargo Cloud Solutions.pptx
 
Powering Real-Time Decisions with Continuous Data Streams
Powering Real-Time Decisions with Continuous Data StreamsPowering Real-Time Decisions with Continuous Data Streams
Powering Real-Time Decisions with Continuous Data Streams
 
Machine Learning Software Engineering Patterns and Their Engineering
Machine Learning Software Engineering Patterns and Their EngineeringMachine Learning Software Engineering Patterns and Their Engineering
Machine Learning Software Engineering Patterns and Their Engineering
 
Software Project Health Check: Best Practices and Techniques for Your Product...
Software Project Health Check: Best Practices and Techniques for Your Product...Software Project Health Check: Best Practices and Techniques for Your Product...
Software Project Health Check: Best Practices and Techniques for Your Product...
 
MYjobs Presentation Django-based project
MYjobs Presentation Django-based projectMYjobs Presentation Django-based project
MYjobs Presentation Django-based project
 
Balasore Best It Company|| Top 10 IT Company || Balasore Software company Odisha
Balasore Best It Company|| Top 10 IT Company || Balasore Software company OdishaBalasore Best It Company|| Top 10 IT Company || Balasore Software company Odisha
Balasore Best It Company|| Top 10 IT Company || Balasore Software company Odisha
 
Post Quantum Cryptography – The Impact on Identity
Post Quantum Cryptography – The Impact on IdentityPost Quantum Cryptography – The Impact on Identity
Post Quantum Cryptography – The Impact on Identity
 
CRM Contender Series: HubSpot vs. Salesforce
CRM Contender Series: HubSpot vs. SalesforceCRM Contender Series: HubSpot vs. Salesforce
CRM Contender Series: HubSpot vs. Salesforce
 
Implementing Zero Trust strategy with Azure
Implementing Zero Trust strategy with AzureImplementing Zero Trust strategy with Azure
Implementing Zero Trust strategy with Azure
 
How to submit a standout Adobe Champion Application
How to submit a standout Adobe Champion ApplicationHow to submit a standout Adobe Champion Application
How to submit a standout Adobe Champion Application
 
Xen Safety Embedded OSS Summit April 2024 v4.pdf
Xen Safety Embedded OSS Summit April 2024 v4.pdfXen Safety Embedded OSS Summit April 2024 v4.pdf
Xen Safety Embedded OSS Summit April 2024 v4.pdf
 

GDPR and Dynamics 365 - the Waldorf and Statler perspective

  • 1. 5/3/2018 1 GDPR and Dynamics 365 – the Waldorf and Statler perspective Joris Poelmans, Realdolmen, @jopxtwits Stephane Dorrekens, Business Elements, @stephanedujour Interactive session: • GDPR introduction & basics • Impact on Dynamics 365 • Real life examples Remarks: • Share your feedback • No simple answers • Inspired by sessions from @MimCRM (Mohamed Mostafa CRM MVP) • Not an exclusive list of considerations or solution design approaches • Disclaimer: no warranty! J
  • 2. 5/3/2018 2 EU launched Data Protection Directive back in 1995 When <1% of EU citizens accessed the internet J Things are about to change … • Extension of existing privacy practices • Enforcement of regulation vs recommendations & guidelines J
  • 3. 5/3/2018 3 New Framework: GDPR  Into effect on May 25th 2018  Modernize the obsolete 95 directive  Create a unified EU law to replace the current haywire of inconsistent framework  Applies both to processors and controllers  Administrative sanctions – up to 20 mio EUR or 4% of yearly turnover J Data processing must comply with 6 GDPR principles 1. Lawfulness, fairness and transparency 2. Purpose limitation 3. Retention 4. Integrity and confidentiality 5. Data minimization 6. Accuracy J “the controller shall be responsible for, and be able to demonstrate, compliance with the principles”
  • 4. 5/3/2018 4 What is processing? S Key changes in GDPR • Single set of rules across EU – territorial scope • One stop shop • New right for individuals: • Subject consent expands • Insight into data • Right to be forgotten • Extra accountability and responsibility for data controllers • Data portability • Data breach notification • Data Protection Impact Assessments • Appointing a Data Protection Officer • Higher sanctions (€€€) S
  • 5. 5/3/2018 5 Impacted areas in Dynamics 365 Data classification (PII and sensitive data) Consent and data access controls Auditing, monitoring, security and reporting Governance S Impacted areas in Dynamics 365 Data classification (PII and sensitive data) Consent and data access controls Auditing, monitoring, security and reporting Governance J
  • 6. 5/3/2018 6 Data classification – PII and sensitive data Factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity (hobbies and leisure, …) Name, address,email, date of birth Identification number (e.g. RRN) Location data (address, GPS/geolocation) Online identifiers (IP addresses, cookies, …) J Sensitive: racial or ethnic origin, political opinions, religious or philosophical beliefs, genetic or biometric data, health data, union membership, sexual orientation, etc … Data classification – challenge of duplicate/incomplete customer records J Mia Smith m.smith@hotmail.com Ms. Smith mia.smith@gmail.com Ms. Mia Smith mia.smith@gmail.com 25/5/1992 003277979794
  • 7. 5/3/2018 7 Data classification – deduplication using machine learning • Video- https://www.tamr.com/video/tamr-helping-toyota-motor-europe-create-connected- seamless-customer-experience/ J Data classification – Dynamics 365 design options/considerations • The 5 Ws of personal data • Use multiple forms: minimum & full, separate non-sensitive and sensitive data, apply field level security • Limit/remove data export privileges • Security roles, access teams, field level security, business units • Consider storing sensitive data in data warehouse for aggregate reporting only • Run regular “Bulk delete” jobs to satisfy your data retention policies (taking into account interactions/transactions) • What about file and email attachments? J
  • 8. 5/3/2018 8 Impacted areas in Dynamics 365 Data classification (PII and sensitive data) Consent and data access controls Auditing, monitoring, security and reporting Governance S Consent and data access controls S
  • 9. 5/3/2018 9 Consent and data access controls– Dynamics 365 design options/considerations • Capture consent information in CRM • Web Site (CRM Portal, Customer Web Sites,..) • Landing Pages (Dynamics Marketing, Click Dimensions, Adobe,..) • Self Service Portals (ie: Myxxxx) • Internal Systems (ie: DWH, Mainframe, etc..) • NB: For GDPR - consent is not per person but by contact point per usage/purpose (ie: email, phone, etc.) • Use consent information in CRM • Outbound integration with Digital Marketing Tools • Outbound integration with Call Centers • OOB Campaign Activity • NB: CRM OOB Usage is per contact/lead not contact point S Consent and data access controls– Dynamics 365 design options/considerations • Consent Audit Log • Not sufficient if records can be deleted -> No delete • Optin vs Optout • Right to be forgotten, portability & access own data • Properly identify the person (see Governance) • It’s easier to delete data for non customers but easier to identify customers • Use a Unique identifier to find all related data in all systems (ie: CRM GUID is good option) • Not all data CAN be deleted as some are needed for operational or legal archiving • Bulk Delete is often not enough, think about other data retentions systems (DHW, BI, Backups, Excel, etc..) S
  • 10. 5/3/2018 10 Sample Implementation CRM Data Structure S Impacted areas in Dynamics 365 Data classification (PII and sensitive data) Consent and data access controls Auditing, monitoring, security and reporting Governance J
  • 11. 5/3/2018 11 Auditing, monitoring, security and reporting GDPR requires: • Pro-active risk based approach: “Always monitoring” and “Intelligent” breach detection and notification • Robust procedures for reporting breaches & processes for reviewing compliance • Compliance investigations will look at controls, monitoring, auditing and effective reporting • For hosted solutions : accountability & reporting on every person/entity with access to the data (full supply chain) J Auditing, monitoring and reporting Dynamics 365 design options/considerations • Auditing functionality available on customer entities (contacts, leads, accounts,custom entities) • For CRM Online –Activity Log Management available • Document security mechanism incl. authentication & authorization • CRM data access security model: system and business roles • What about dev/test/acc/prod? • … • Transparent Data Encryption – change key … and then back it up • For on premise – SQL Enterprise Edition required • Cloud vs on premise J
  • 12. 5/3/2018 12 Impacted areas in Dynamics 365 Data classification (PII and sensitive data) Consent and data access controls Auditing, monitoring, security and reporting Governance S Governance Dynamics 365 design options/considerations What are existing policies, roles & responsibilities (shared responsibility controller and processor) Dynamics 365 for Customer Services can help the Data Privacy Office/Officer • Manage the requests and respects SLA’s. • Find all pertaining information (as most/all is in CRM and/or the primary links are) • Communicate the information to the parties (Notification Obligation) Some Examples of Case Business Flows Data Breach Information (72h delay) Right to delete Right for information Right for rectification Right for portability Right to object Manual Requests for Optout … S
  • 13. 5/3/2018 13 References • https://www.microsoft.com/en-us/trustcenter/cloudservices/dynamics365 • http://www.mohamedmostafa.co.uk/blog/category/gdpr/ • http://jopx.blogspot.be/2018/04/update-on-activity-log-management-for.html • https://technet.microsoft.com/en-us/library/jj134930.aspx (Dynamics 365 security and compliance planning guide) • https://docs.microsoft.com/en-us/dynamics365/customer-engagement/portals/implement-gdpr • https://www.eugdpr.org/ • https://docs.microsoft.com/en-us/dynamics365/get-started/gdpr/ S