SlideShare a Scribd company logo
Digital Security and Data
Protection considerations for
Hospitality Brands and Bloggers
…and the GDPR stuff you need to know
Presented by: Omo Osagiede (@borderless_i)
Security & Privacy
• Why is this important?
• Top security concerns
• The industry response
• The blogger response
• Staying GDPR compliant
WHY IS THIS IMPORTANT?
DATA SECURITY DATA PRIVACY
CYBER CRIME
Bloggers
Brands
The context…
Hilton (2014) Hyatt (2016) IHG/Sabre (2017)
Threat
Stolen
Compromised
Malware
Card holder names,
numbers, security
codes, experts dates
Social engineering Unstated
Card holder names,
numbers, security
codes, experts dates
Point of Sale Point of Sale
Card holder info
+ customer
personal data
Reservations system
providing services to
over 30,000 hotels,
airlines and OTAs
Still some
way to go…
“81% of travel sites did
not provide users with
password strength
assessment tools during
the account creation
process.”
Source: dashlane.com - Travel Password
Power Rankings 2018
Airbnb
Momondo, Priceline,
Kayak, Avis
Trivago, Trip Advisor,
American Airlines,
Norwegian Cruise Line ZERO
TOP INDUSTRY &
BLOGGER
CONCERNS
Where are travel/
hospitality brands
coming unstuck?
What are the
main cyber
security & privacy
threats impacting
industry?
90%
3%
3%
3%
Source: 2018 Verizon Data Breach Incident Report (DBIR)
Top security concerns for bloggers
You could end up…
• Spreading malware to visitors
• Losing readership and trust
• Getting penalised by Google
• Losing revenue (if monetised)
THE INDUSTRY RESPONSE
Challenge
your
brand’s
approach!
Payment Card Industry
Data Security Standards
(PCI DSS)
Good practice security tips (for industry)
Identify all your data
assets
Secure your IT/non-
IT supply chain
Protect your PoS
systems from malware
Educate your staff
and customers
Harden your websites,
apps, entry points
Have an incident
response plan
THE BLOGGER RESPONSE
Good practice security tips (for bloggers)
1. Do not use generic
admin accounts
2. Control access to
your admin panel
3. Set strong passwords
+ use multi-factor
authentication
4. Leverage hosting
provider + WP resources
5. Always update to the
latest version
6. Be careful with plugins!
7. Backup, backup, backup!
THE GDPR STUFF
YOU NEED TO KNOW
What types of personal data processing do you do?
#1. Website
data processing
(comments,
subscriptions,
tracking)
#4. Mailing lists/
Newsletters#2. Social Media
(inc promotions, DMs)
#3. Marketing
Campaigns
• Email sign up and contact forms (names,
physical addresses, email)
• Blog comments (name, IP address, email)
• Social media including social groups
• Third party plugins
• Profiling and tracking cookies
• Campaigns and promotions
• Mobile apps
Sources of
personal
data…
6 key
questions to
ask about
personal
data
1. What are you collecting?
2. Why are you collecting it?
3. How are you protecting it?
4. Where is it located?
5. How long are you keeping it for?
6. Who are you sharing it with?
GDPR THINGS TO DO
*Applies to bloggers and brand BUT large organisations need a broader approach
Privacy on your website
• Update and publish privacy policies
• Make them visible!
• Audit and declare cookies
• Audit your plugins (update/remove)
• Move to https (if you haven’t already)
• Only use sanitised themes
• Review affiliate marketing
Word Press Google Analytics
• Install the GDPR
Compliance plugin
• Cookie consent plugin
• Secure your backend/
admin panel
Developer tools
• Implement data retention
options (14 months)
• User deletion API
• Google Fonts
Email subscription lists
“Respect the right
to object to
processing (i.e.,
direct marketing,
profiling,
tracking)”
Dont’sDo’s
Affirmative opt-in only
Remove data if unsure
Communicate privacy
policies
Contact opt-outs
Buy or sell data lists
MailChimp (or other)
• Switch to GDPR-friendly/customisable
forms (lists, landing pages, pop-ups).
• Explore tools that help you better
manage data subject rights e.g. right to
access, erasure, rectification.
• Consider enabling double opt-in
• Review your use of automation
• Review social media plugins
• Do you collect personal data in
your DMs?
• Review group membership/
groups (e.g., Facebook)
What about social media?
• Clarify requests from PRs/brands for data.
• Don’t transfer follower data without
consent.
• Don’t automatically sign-up campaign
participants to email marketing lists.
• Use compliant third party campaign
management tools.
• Publish your privacy policy to users.
When running campaigns…
Three takeaways
1. PROTECT your brand
against online threats.
2. KNOW what personal
data you process.
3. ASSUME nothing! @borderless_i

More Related Content

What's hot

BigID, OneTrust, IAPP Webinar: Bridging the Privacy Office with IT
BigID, OneTrust, IAPP Webinar: Bridging the Privacy Office with ITBigID, OneTrust, IAPP Webinar: Bridging the Privacy Office with IT
BigID, OneTrust, IAPP Webinar: Bridging the Privacy Office with IT
BigID Inc
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
Cobweb
 
BigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar SlidesBigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar Slides
Dimitri Sirota
 
BigID GDPR Privacy Automation Data Sheet
BigID GDPR Privacy Automation Data SheetBigID GDPR Privacy Automation Data Sheet
BigID GDPR Privacy Automation Data Sheet
Dimitri Sirota
 
Tackling the GDPR Dell EMC Index Engines Webinar
Tackling the GDPR Dell EMC Index Engines WebinarTackling the GDPR Dell EMC Index Engines Webinar
Tackling the GDPR Dell EMC Index Engines Webinar
Index Engines Inc.
 
BigID's Smart Data Labeling and Tagging
BigID's Smart Data Labeling and TaggingBigID's Smart Data Labeling and Tagging
BigID's Smart Data Labeling and Tagging
Dimitri Sirota
 
BigID DataSheet: Data Access Intelligence
BigID DataSheet: Data Access IntelligenceBigID DataSheet: Data Access Intelligence
BigID DataSheet: Data Access Intelligence
BigID Inc
 
ISACA Houston - How to de-classify data and rethink transfer of data between ...
ISACA Houston - How to de-classify data and rethink transfer of data between ...ISACA Houston - How to de-classify data and rethink transfer of data between ...
ISACA Houston - How to de-classify data and rethink transfer of data between ...
Ulf Mattsson
 
BigID Data Sheet HIPAA Data Security & Privacy
BigID Data Sheet HIPAA Data Security & Privacy BigID Data Sheet HIPAA Data Security & Privacy
BigID Data Sheet HIPAA Data Security & Privacy
BigID Inc
 
Getting Started with GDPR Compliance
Getting Started with GDPR ComplianceGetting Started with GDPR Compliance
Getting Started with GDPR Compliance
DATAVERSITY
 
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and GovernanceGeek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
IDERA Software
 
Piwik PRO The Real Cost of Data Privacy
Piwik PRO The Real Cost of Data Privacy Piwik PRO The Real Cost of Data Privacy
Piwik PRO The Real Cost of Data Privacy
Piwik PRO
 
Isaca atlanta - practical data security and privacy
Isaca atlanta - practical data security and privacyIsaca atlanta - practical data security and privacy
Isaca atlanta - practical data security and privacy
Ulf Mattsson
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
CIO Edge
 
BigID Data Inventory & Data Mapping Data Sheet
BigID Data Inventory & Data Mapping Data SheetBigID Data Inventory & Data Mapping Data Sheet
BigID Data Inventory & Data Mapping Data Sheet
Dimitri Sirota
 
What I learned at the Infosecurity ISACA North America Conference 2019
What I learned at the Infosecurity ISACA North America Conference 2019What I learned at the Infosecurity ISACA North America Conference 2019
What I learned at the Infosecurity ISACA North America Conference 2019
Ulf Mattsson
 
Privacy preserving computing and secure multi-party computation ISACA Atlanta
Privacy preserving computing and secure multi-party computation ISACA AtlantaPrivacy preserving computing and secure multi-party computation ISACA Atlanta
Privacy preserving computing and secure multi-party computation ISACA Atlanta
Ulf Mattsson
 
ISACA Houston - Practical data privacy and de-identification techniques
ISACA Houston  - Practical data privacy and de-identification techniquesISACA Houston  - Practical data privacy and de-identification techniques
ISACA Houston - Practical data privacy and de-identification techniques
Ulf Mattsson
 
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
Jean-Michel Franco
 
Splunk: How Machine Data Supports GDPR Compliance
Splunk: How Machine Data Supports GDPR ComplianceSplunk: How Machine Data Supports GDPR Compliance
Splunk: How Machine Data Supports GDPR Compliance
MarketingArrowECS_CZ
 

What's hot (20)

BigID, OneTrust, IAPP Webinar: Bridging the Privacy Office with IT
BigID, OneTrust, IAPP Webinar: Bridging the Privacy Office with ITBigID, OneTrust, IAPP Webinar: Bridging the Privacy Office with IT
BigID, OneTrust, IAPP Webinar: Bridging the Privacy Office with IT
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
BigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar SlidesBigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar Slides
 
BigID GDPR Privacy Automation Data Sheet
BigID GDPR Privacy Automation Data SheetBigID GDPR Privacy Automation Data Sheet
BigID GDPR Privacy Automation Data Sheet
 
Tackling the GDPR Dell EMC Index Engines Webinar
Tackling the GDPR Dell EMC Index Engines WebinarTackling the GDPR Dell EMC Index Engines Webinar
Tackling the GDPR Dell EMC Index Engines Webinar
 
BigID's Smart Data Labeling and Tagging
BigID's Smart Data Labeling and TaggingBigID's Smart Data Labeling and Tagging
BigID's Smart Data Labeling and Tagging
 
BigID DataSheet: Data Access Intelligence
BigID DataSheet: Data Access IntelligenceBigID DataSheet: Data Access Intelligence
BigID DataSheet: Data Access Intelligence
 
ISACA Houston - How to de-classify data and rethink transfer of data between ...
ISACA Houston - How to de-classify data and rethink transfer of data between ...ISACA Houston - How to de-classify data and rethink transfer of data between ...
ISACA Houston - How to de-classify data and rethink transfer of data between ...
 
BigID Data Sheet HIPAA Data Security & Privacy
BigID Data Sheet HIPAA Data Security & Privacy BigID Data Sheet HIPAA Data Security & Privacy
BigID Data Sheet HIPAA Data Security & Privacy
 
Getting Started with GDPR Compliance
Getting Started with GDPR ComplianceGetting Started with GDPR Compliance
Getting Started with GDPR Compliance
 
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and GovernanceGeek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
 
Piwik PRO The Real Cost of Data Privacy
Piwik PRO The Real Cost of Data Privacy Piwik PRO The Real Cost of Data Privacy
Piwik PRO The Real Cost of Data Privacy
 
Isaca atlanta - practical data security and privacy
Isaca atlanta - practical data security and privacyIsaca atlanta - practical data security and privacy
Isaca atlanta - practical data security and privacy
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
 
BigID Data Inventory & Data Mapping Data Sheet
BigID Data Inventory & Data Mapping Data SheetBigID Data Inventory & Data Mapping Data Sheet
BigID Data Inventory & Data Mapping Data Sheet
 
What I learned at the Infosecurity ISACA North America Conference 2019
What I learned at the Infosecurity ISACA North America Conference 2019What I learned at the Infosecurity ISACA North America Conference 2019
What I learned at the Infosecurity ISACA North America Conference 2019
 
Privacy preserving computing and secure multi-party computation ISACA Atlanta
Privacy preserving computing and secure multi-party computation ISACA AtlantaPrivacy preserving computing and secure multi-party computation ISACA Atlanta
Privacy preserving computing and secure multi-party computation ISACA Atlanta
 
ISACA Houston - Practical data privacy and de-identification techniques
ISACA Houston  - Practical data privacy and de-identification techniquesISACA Houston  - Practical data privacy and de-identification techniques
ISACA Houston - Practical data privacy and de-identification techniques
 
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
 
Splunk: How Machine Data Supports GDPR Compliance
Splunk: How Machine Data Supports GDPR ComplianceSplunk: How Machine Data Supports GDPR Compliance
Splunk: How Machine Data Supports GDPR Compliance
 

Similar to TBEX 2018 - Digital Security and GDPR Considerations for the Travel and Hospitality Industry

#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
One North
 
Digital Marketing Analytics Certification - Session One
Digital Marketing Analytics Certification - Session OneDigital Marketing Analytics Certification - Session One
Digital Marketing Analytics Certification - Session One
Brand Digital, Inc
 
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in ComplianceThe GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
ObservePoint
 
Sophie's Privacy - a story about GDPR
Sophie's Privacy - a story about GDPRSophie's Privacy - a story about GDPR
Sophie's Privacy - a story about GDPR
Hans Demeyer
 
Digital Marketing Training
Digital Marketing TrainingDigital Marketing Training
Digital Marketing Training
PiyushPahadi
 
Online Listening and Opinion Analytics for Customer Care
Online Listening and Opinion Analytics for Customer CareOnline Listening and Opinion Analytics for Customer Care
Online Listening and Opinion Analytics for Customer Care
Hugo Zaragoza
 
Addressable Audiences: Data Considerations for People-Based Marketing
Addressable Audiences: Data Considerations for People-Based MarketingAddressable Audiences: Data Considerations for People-Based Marketing
Addressable Audiences: Data Considerations for People-Based Marketing
Nicole Tabatabai
 
The Big Picture of Digital Marketing - Guest Lecture at PPM School of Managem...
The Big Picture of Digital Marketing - Guest Lecture at PPM School of Managem...The Big Picture of Digital Marketing - Guest Lecture at PPM School of Managem...
The Big Picture of Digital Marketing - Guest Lecture at PPM School of Managem...
Indra Jaya
 
Webinar Deck: Building Customer Relationships in an Omni-Channel World
Webinar Deck: Building Customer Relationships in an Omni-Channel WorldWebinar Deck: Building Customer Relationships in an Omni-Channel World
Webinar Deck: Building Customer Relationships in an Omni-Channel World
Ensighten
 
6: privacy terms
6: privacy terms6: privacy terms
6: privacy terms
COMP 113
 
Common Sense and Communities
Common Sense and Communities Common Sense and Communities
Common Sense and Communities
Magnet 360
 
Data Breaches and Security Rights in SharePoint Webinar
Data Breaches and Security Rights in SharePoint WebinarData Breaches and Security Rights in SharePoint Webinar
Data Breaches and Security Rights in SharePoint Webinar
Concept Searching, Inc
 
Introduction to Digital Marketing - 2015
Introduction to Digital Marketing - 2015Introduction to Digital Marketing - 2015
Introduction to Digital Marketing - 2015
Edwin Korver
 
Discovery, Risk, and Insight in a Metadata-Driven World Webinar
Discovery, Risk, and Insight in a Metadata-Driven World WebinarDiscovery, Risk, and Insight in a Metadata-Driven World Webinar
Discovery, Risk, and Insight in a Metadata-Driven World Webinar
Concept Searching, Inc
 
GDPR, User Data, Privacy, and Your Apps
GDPR, User Data, Privacy, and Your AppsGDPR, User Data, Privacy, and Your Apps
GDPR, User Data, Privacy, and Your Apps
Carl Brown
 
Implications of GDPR in Conjunction with UMA
Implications of GDPR in Conjunction with UMAImplications of GDPR in Conjunction with UMA
Implications of GDPR in Conjunction with UMA
ForgeRock
 
What Does the Future of the Web Look Like?
What Does the Future of the Web Look Like?What Does the Future of the Web Look Like?
What Does the Future of the Web Look Like?
Tinuiti
 
Social Media for B2B
Social Media for B2BSocial Media for B2B
Social Media for B2B
Amit Klein
 
The Privacy Illusion
The Privacy IllusionThe Privacy Illusion
The Privacy Illusion
Mary Aviles
 
BusinessGPT - SECURITY AND GOVERNANCE FOR GENERATIVE AI.pptx
BusinessGPT  - SECURITY AND GOVERNANCE  FOR GENERATIVE AI.pptxBusinessGPT  - SECURITY AND GOVERNANCE  FOR GENERATIVE AI.pptx
BusinessGPT - SECURITY AND GOVERNANCE FOR GENERATIVE AI.pptx
AGATSoftware
 

Similar to TBEX 2018 - Digital Security and GDPR Considerations for the Travel and Hospitality Industry (20)

#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
 
Digital Marketing Analytics Certification - Session One
Digital Marketing Analytics Certification - Session OneDigital Marketing Analytics Certification - Session One
Digital Marketing Analytics Certification - Session One
 
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in ComplianceThe GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
 
Sophie's Privacy - a story about GDPR
Sophie's Privacy - a story about GDPRSophie's Privacy - a story about GDPR
Sophie's Privacy - a story about GDPR
 
Digital Marketing Training
Digital Marketing TrainingDigital Marketing Training
Digital Marketing Training
 
Online Listening and Opinion Analytics for Customer Care
Online Listening and Opinion Analytics for Customer CareOnline Listening and Opinion Analytics for Customer Care
Online Listening and Opinion Analytics for Customer Care
 
Addressable Audiences: Data Considerations for People-Based Marketing
Addressable Audiences: Data Considerations for People-Based MarketingAddressable Audiences: Data Considerations for People-Based Marketing
Addressable Audiences: Data Considerations for People-Based Marketing
 
The Big Picture of Digital Marketing - Guest Lecture at PPM School of Managem...
The Big Picture of Digital Marketing - Guest Lecture at PPM School of Managem...The Big Picture of Digital Marketing - Guest Lecture at PPM School of Managem...
The Big Picture of Digital Marketing - Guest Lecture at PPM School of Managem...
 
Webinar Deck: Building Customer Relationships in an Omni-Channel World
Webinar Deck: Building Customer Relationships in an Omni-Channel WorldWebinar Deck: Building Customer Relationships in an Omni-Channel World
Webinar Deck: Building Customer Relationships in an Omni-Channel World
 
6: privacy terms
6: privacy terms6: privacy terms
6: privacy terms
 
Common Sense and Communities
Common Sense and Communities Common Sense and Communities
Common Sense and Communities
 
Data Breaches and Security Rights in SharePoint Webinar
Data Breaches and Security Rights in SharePoint WebinarData Breaches and Security Rights in SharePoint Webinar
Data Breaches and Security Rights in SharePoint Webinar
 
Introduction to Digital Marketing - 2015
Introduction to Digital Marketing - 2015Introduction to Digital Marketing - 2015
Introduction to Digital Marketing - 2015
 
Discovery, Risk, and Insight in a Metadata-Driven World Webinar
Discovery, Risk, and Insight in a Metadata-Driven World WebinarDiscovery, Risk, and Insight in a Metadata-Driven World Webinar
Discovery, Risk, and Insight in a Metadata-Driven World Webinar
 
GDPR, User Data, Privacy, and Your Apps
GDPR, User Data, Privacy, and Your AppsGDPR, User Data, Privacy, and Your Apps
GDPR, User Data, Privacy, and Your Apps
 
Implications of GDPR in Conjunction with UMA
Implications of GDPR in Conjunction with UMAImplications of GDPR in Conjunction with UMA
Implications of GDPR in Conjunction with UMA
 
What Does the Future of the Web Look Like?
What Does the Future of the Web Look Like?What Does the Future of the Web Look Like?
What Does the Future of the Web Look Like?
 
Social Media for B2B
Social Media for B2BSocial Media for B2B
Social Media for B2B
 
The Privacy Illusion
The Privacy IllusionThe Privacy Illusion
The Privacy Illusion
 
BusinessGPT - SECURITY AND GOVERNANCE FOR GENERATIVE AI.pptx
BusinessGPT  - SECURITY AND GOVERNANCE  FOR GENERATIVE AI.pptxBusinessGPT  - SECURITY AND GOVERNANCE  FOR GENERATIVE AI.pptx
BusinessGPT - SECURITY AND GOVERNANCE FOR GENERATIVE AI.pptx
 

Recently uploaded

The Power of a Glamping Go-To-Market Accelerator Plan.pptx
The Power of a Glamping Go-To-Market Accelerator Plan.pptxThe Power of a Glamping Go-To-Market Accelerator Plan.pptx
The Power of a Glamping Go-To-Market Accelerator Plan.pptx
RezStream
 
Assessing the Influence of Transportation on the Tourism Industry in Nigeria
Assessing the Influence of Transportation on the  Tourism Industry in NigeriaAssessing the Influence of Transportation on the  Tourism Industry in Nigeria
Assessing the Influence of Transportation on the Tourism Industry in Nigeria
gsochially
 
How To Talk To a Live Person at American Airlines
How To Talk To a Live Person at American AirlinesHow To Talk To a Live Person at American Airlines
How To Talk To a Live Person at American Airlines
flyn goo
 
Hidden Gems of Europe - DISCOVERING THE CONTINENT'S BEST-KEPT SECRETS
Hidden Gems of Europe - DISCOVERING THE CONTINENT'S BEST-KEPT SECRETSHidden Gems of Europe - DISCOVERING THE CONTINENT'S BEST-KEPT SECRETS
Hidden Gems of Europe - DISCOVERING THE CONTINENT'S BEST-KEPT SECRETS
Kamil Uğraş TÜRKOĞLU
 
Uk Visa Complete Guide and application process
Uk Visa Complete Guide and application processUk Visa Complete Guide and application process
Uk Visa Complete Guide and application process
pandeypratikwgblindi
 
在线办理(BU毕业证书)波士顿大学毕业证录取通知书一模一样
在线办理(BU毕业证书)波士顿大学毕业证录取通知书一模一样在线办理(BU毕业证书)波士顿大学毕业证录取通知书一模一样
在线办理(BU毕业证书)波士顿大学毕业证录取通知书一模一样
v6ldcxuq
 
Wayanad-The-Touristry-Heaven to the tour.pptx
Wayanad-The-Touristry-Heaven to the tour.pptxWayanad-The-Touristry-Heaven to the tour.pptx
Wayanad-The-Touristry-Heaven to the tour.pptx
cosmo-soil
 

Recently uploaded (7)

The Power of a Glamping Go-To-Market Accelerator Plan.pptx
The Power of a Glamping Go-To-Market Accelerator Plan.pptxThe Power of a Glamping Go-To-Market Accelerator Plan.pptx
The Power of a Glamping Go-To-Market Accelerator Plan.pptx
 
Assessing the Influence of Transportation on the Tourism Industry in Nigeria
Assessing the Influence of Transportation on the  Tourism Industry in NigeriaAssessing the Influence of Transportation on the  Tourism Industry in Nigeria
Assessing the Influence of Transportation on the Tourism Industry in Nigeria
 
How To Talk To a Live Person at American Airlines
How To Talk To a Live Person at American AirlinesHow To Talk To a Live Person at American Airlines
How To Talk To a Live Person at American Airlines
 
Hidden Gems of Europe - DISCOVERING THE CONTINENT'S BEST-KEPT SECRETS
Hidden Gems of Europe - DISCOVERING THE CONTINENT'S BEST-KEPT SECRETSHidden Gems of Europe - DISCOVERING THE CONTINENT'S BEST-KEPT SECRETS
Hidden Gems of Europe - DISCOVERING THE CONTINENT'S BEST-KEPT SECRETS
 
Uk Visa Complete Guide and application process
Uk Visa Complete Guide and application processUk Visa Complete Guide and application process
Uk Visa Complete Guide and application process
 
在线办理(BU毕业证书)波士顿大学毕业证录取通知书一模一样
在线办理(BU毕业证书)波士顿大学毕业证录取通知书一模一样在线办理(BU毕业证书)波士顿大学毕业证录取通知书一模一样
在线办理(BU毕业证书)波士顿大学毕业证录取通知书一模一样
 
Wayanad-The-Touristry-Heaven to the tour.pptx
Wayanad-The-Touristry-Heaven to the tour.pptxWayanad-The-Touristry-Heaven to the tour.pptx
Wayanad-The-Touristry-Heaven to the tour.pptx
 

TBEX 2018 - Digital Security and GDPR Considerations for the Travel and Hospitality Industry

  • 1.
  • 2. Digital Security and Data Protection considerations for Hospitality Brands and Bloggers …and the GDPR stuff you need to know Presented by: Omo Osagiede (@borderless_i)
  • 3. Security & Privacy • Why is this important? • Top security concerns • The industry response • The blogger response • Staying GDPR compliant
  • 4. WHY IS THIS IMPORTANT?
  • 5. DATA SECURITY DATA PRIVACY CYBER CRIME Bloggers Brands The context…
  • 6. Hilton (2014) Hyatt (2016) IHG/Sabre (2017) Threat Stolen Compromised Malware Card holder names, numbers, security codes, experts dates Social engineering Unstated Card holder names, numbers, security codes, experts dates Point of Sale Point of Sale Card holder info + customer personal data Reservations system providing services to over 30,000 hotels, airlines and OTAs
  • 7. Still some way to go… “81% of travel sites did not provide users with password strength assessment tools during the account creation process.” Source: dashlane.com - Travel Password Power Rankings 2018 Airbnb Momondo, Priceline, Kayak, Avis Trivago, Trip Advisor, American Airlines, Norwegian Cruise Line ZERO
  • 9. Where are travel/ hospitality brands coming unstuck?
  • 10. What are the main cyber security & privacy threats impacting industry? 90% 3% 3% 3% Source: 2018 Verizon Data Breach Incident Report (DBIR)
  • 11. Top security concerns for bloggers You could end up… • Spreading malware to visitors • Losing readership and trust • Getting penalised by Google • Losing revenue (if monetised)
  • 14. Good practice security tips (for industry) Identify all your data assets Secure your IT/non- IT supply chain Protect your PoS systems from malware Educate your staff and customers Harden your websites, apps, entry points Have an incident response plan
  • 16. Good practice security tips (for bloggers) 1. Do not use generic admin accounts 2. Control access to your admin panel 3. Set strong passwords + use multi-factor authentication 4. Leverage hosting provider + WP resources 5. Always update to the latest version 6. Be careful with plugins! 7. Backup, backup, backup!
  • 17. THE GDPR STUFF YOU NEED TO KNOW
  • 18. What types of personal data processing do you do? #1. Website data processing (comments, subscriptions, tracking) #4. Mailing lists/ Newsletters#2. Social Media (inc promotions, DMs) #3. Marketing Campaigns
  • 19. • Email sign up and contact forms (names, physical addresses, email) • Blog comments (name, IP address, email) • Social media including social groups • Third party plugins • Profiling and tracking cookies • Campaigns and promotions • Mobile apps Sources of personal data…
  • 20. 6 key questions to ask about personal data 1. What are you collecting? 2. Why are you collecting it? 3. How are you protecting it? 4. Where is it located? 5. How long are you keeping it for? 6. Who are you sharing it with?
  • 21. GDPR THINGS TO DO *Applies to bloggers and brand BUT large organisations need a broader approach
  • 22. Privacy on your website • Update and publish privacy policies • Make them visible! • Audit and declare cookies • Audit your plugins (update/remove) • Move to https (if you haven’t already) • Only use sanitised themes • Review affiliate marketing
  • 23. Word Press Google Analytics • Install the GDPR Compliance plugin • Cookie consent plugin • Secure your backend/ admin panel Developer tools • Implement data retention options (14 months) • User deletion API • Google Fonts
  • 24. Email subscription lists “Respect the right to object to processing (i.e., direct marketing, profiling, tracking)” Dont’sDo’s Affirmative opt-in only Remove data if unsure Communicate privacy policies Contact opt-outs Buy or sell data lists
  • 25. MailChimp (or other) • Switch to GDPR-friendly/customisable forms (lists, landing pages, pop-ups). • Explore tools that help you better manage data subject rights e.g. right to access, erasure, rectification. • Consider enabling double opt-in
  • 26. • Review your use of automation • Review social media plugins • Do you collect personal data in your DMs? • Review group membership/ groups (e.g., Facebook) What about social media?
  • 27. • Clarify requests from PRs/brands for data. • Don’t transfer follower data without consent. • Don’t automatically sign-up campaign participants to email marketing lists. • Use compliant third party campaign management tools. • Publish your privacy policy to users. When running campaigns…
  • 28. Three takeaways 1. PROTECT your brand against online threats. 2. KNOW what personal data you process. 3. ASSUME nothing! @borderless_i