SlideShare a Scribd company logo
GDPR Readiness for Software Usage Analytics
November 7, 2017
Vic DeMarines
VP, Products & Strategy
Revulytics
Bob Siegel
President
Privacy Ref
Topics
• What is Software Usage Analytics?
• What is GDPR?
• Privacy Concepts, Personal Information Defined
• Data Controllers and Processors
• GDPR and Protecting and Improving Your Software
• How Revulytics Customers are Addressing These Issues
2
About Revulytics
Compliance Analytics
• Identify and quantify
software use and misuse
• Create actionable
intelligence
• Turn intelligence into direct
revenue
Usage Analytics
• Anonymous feature tracking
and analysis of product
usage
• Increase customer
acquisition and retention
• Generate revenue with better
products
3
• Recognized as 2017 Gartner Cool Vendor
• More than 100 customers including Fortune 500 companies
• Technology deployed to over 50M machines in more than 200 countries
• Our data has supported more than $1.8 billion in new license revenue since 2010
Software Usage Intelligence Solution Architecture
4
Cloud Service
Usage Intelligence
Reporting Dashboard
Data
Analytics
Engine
Integrated
Applications
Configured to focus
on feature adoption
ReachOut
In Application messaging
Compliance Intelligence Solution Architecture
5
Cloud Service
Compliance Dashboard
on Force.com
Integrated
Applications
Configured to
identify
organizations and
true location Gateway
Servers
Revulytics Data
Optimizer and Analysts
Revulytics Recovery
Services
What is GDPR?
• General Data Privacy Regulation
– Replaces the EU Privacy Directive (Directive 95/46/EC)
– A pan-EU law
– Becomes effective on May 25, 2018
• Five Principles
– Lawfulness, fairness, and transparency
– Purpose limitation
– Data minimization and proportionality
– Storage limitation
– Accountability
• Privacy Shield
6
Privacy Concepts, Personal Information Defined
• Data subject
• Legal basis for processing
• Data transfer
7
Personal Information…
any information related to an identified or identifiable data subject
• Privacy Policy
• Privacy Notice
Other Key Concepts
• Name
• Age/Birthdate
• Gender
• Employer
• User-id
• Email address
• User name
• Machine name
• IP Address
Revulytics
Applicable
Is IP Address Personal Information
• Court of Justice of the European Union opinion
– Breyer v Bundesrepublik Deutschland, Case C-582/14, 12 May 2016
– IP address combined with ISP records would constitute personal data in
the hands of the website provider
• Broader applicability: even if you’re not an ISP, it may be applicable
– “could keep [the IP address] indefinitely and could request at any time
from the Internet access service provider additional data to combine with
the IP address in order identify the user”
• Revulytics customer impact
– Usage Intelligence: IP address only collected for location and is then
deleted from system
– Compliance Intelligence: A key piece of information to track compliance
8
Data Controllers and Processors
9
Data Protection Authority / Supervisory Authority
Data Subject
Data
Controller
Data
Processor
End-user
Your
Company
Revulytics
GDPR and Protecting and Improving Your Software
Lawfulness, fairness, and transparency
• Lawfully processing information
– Consent (Article 7)
– Legitimate interest of the controller or a third party
(Article 6)
• Fairness and transparency
– Include legal basis in your privacy notice
– State that it will be shared with a third party
(Revulytics)
– State that processing may occur in the United States
10
GDPR and Protecting and Improving Your Software
Other principles
• Purpose limitation
• Data minimization and proportionality
• Storage limitation
• Accountability
11
GDPR and Protecting and Improving Your Software
Best practices and Revulytics products
• Revulytics Compliance Intelligence
– Use legitimate interests as a legal basis
• Consent not required
– Be transparent in your privacy notice
– Define a reasonable retention period with Compliance Intelligence
12
GDPR and Protecting and Improving Your Software
Best practices and Revulytics products
• Revulytics Usage Intelligence
– Legitimate interests as a legal basis is an option
• Consent not required: use of data to improve products
– However, sensitivity of the environment may guide you towards consent
• Example: Microsoft and Windows 10
• Consent requirements
• Separate screen (not buried in a EULA)
• Mechanism to change preference (opt-in or opt-out) at a later time
– Collecting additional information
• Avoid or limit collecting personal information
• Usage Intelligence does not retain personal information by default
– Be transparent in your privacy notice
– Define a reasonable retention period with Usage Intelligence if collecting
personal information
13
GDPR and Protecting and Improving Your Software
Best practices and Revulytics products
• ReachOut functionality
– You may send messages and surveys to the end-users
• You have an existing business relationship
• Contents must be related to the software being used
– An opt-out mechanism must be supplied and respected
• Allow end users to opt-in at a later time as well
14
GDPR and Protecting and Improving Your Software
Best practices for your privacy notice
• Privacy notice requirements will vary based on
your software
• Be transparent about the information being
collected
• Link to the privacy notice where end users will
expect to find it
15
How Revulytics Customers Address These Issues
Data Needed for Compliance
16
Consumer piracy
Lower product ASP
Piracy Response
In-Application Messaging
Direct Compliance
Audit
Specialize software
Enterprise organizations
Higher product ASP
SMB
Compliance Approach
Data Collection Meter
How Revulytics Customers Address These Issues
• Wi-Fi SSID adds to the Domain Data and provides location intelligence
17
Best Practices
• Compliance Intelligence
– Transparency and Privacy Policy key
• Include extent of data collected, include description of data being collected
• Note sharing of data with third party for your compliance program
• 100% focused on compliance
– Have a FAQ or whitepaper available that positions the deployment
• Usage Intelligence
– Implement opt-out functionality within the application, available to the user post-
installation
– Product related in-application messaging
– Consider custom data being collected
• Best practices - not a legal opinion
– Include your usage and compliance data collection in your own GDPR
assessment
– Revulytics assessing its business and platform for GDPR compliance
18
Conclusion
• To view the full webinar recording and slides, check
out the link in the comments.
• Also , read the white paper, “Privacy, Piracy, and
Product Usage GDPR Readiness for Software
Usage Analytics”
19
Vic DeMarines
VP, Products & Strategy
Revulytics
vdemarines@revulytics.com
Bob Siegel
President
Privacy Ref
bob.siegel@privacyref.com

More Related Content

What's hot

GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701
GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701
GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701
PECB
 
GDPR: The Regulator's Perspective, Peter Brown, ICO
GDPR: The Regulator's Perspective, Peter Brown, ICOGDPR: The Regulator's Perspective, Peter Brown, ICO
GDPR: The Regulator's Perspective, Peter Brown, ICO
BCS Data Management Specialist Group
 
The GDPR timeline - Stephen Bailey, NCC Group
The GDPR timeline - Stephen Bailey, NCC GroupThe GDPR timeline - Stephen Bailey, NCC Group
The GDPR timeline - Stephen Bailey, NCC Group
BCS Data Management Specialist Group
 
A Brief Overview on GDPR
A Brief Overview on GDPRA Brief Overview on GDPR
A Brief Overview on GDPR
Neha Patel
 
Data security and privacy
Data security and privacyData security and privacy
Data security and privacy
rajab ssemwogerere
 
EU's General Data Protection Regulation (GDPR)
EU's General Data Protection Regulation (GDPR)EU's General Data Protection Regulation (GDPR)
EU's General Data Protection Regulation (GDPR)
Kimberly Simon MBA
 
GDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to KnowGDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to Know
Piwik PRO
 
Finding Data at Risk for CCPA Compliance
Finding Data at Risk for CCPA ComplianceFinding Data at Risk for CCPA Compliance
Finding Data at Risk for CCPA Compliance
Precisely
 
Preparing for GDPR Compliance...
Preparing for GDPR Compliance...Preparing for GDPR Compliance...
Preparing for GDPR Compliance...
James Ward
 
Data Protection Officer Dashboard | GDPR
Data Protection Officer Dashboard | GDPRData Protection Officer Dashboard | GDPR
Data Protection Officer Dashboard | GDPR
Corporater
 
Effective data protection for businesses with multiple locations
Effective data protection for businesses with multiple locationsEffective data protection for businesses with multiple locations
Effective data protection for businesses with multiple locations
InTechnology Managed Services (part of Redcentric)
 
7 Key GDPR Requirements & the Role of Data Governance
7 Key GDPR Requirements & the Role of Data Governance7 Key GDPR Requirements & the Role of Data Governance
7 Key GDPR Requirements & the Role of Data Governance
DATUM LLC
 
Understanding gdpr compliance gdpr analytics tools
Understanding gdpr compliance  gdpr analytics toolsUnderstanding gdpr compliance  gdpr analytics tools
Understanding gdpr compliance gdpr analytics tools
RominaMariaBaltariu
 
Mastering Article 30 Compliance: Conducting, Maintaining & Reporting on your ...
Mastering Article 30 Compliance: Conducting, Maintaining & Reporting on your ...Mastering Article 30 Compliance: Conducting, Maintaining & Reporting on your ...
Mastering Article 30 Compliance: Conducting, Maintaining & Reporting on your ...
TrustArc
 
HealthCare Compliance - HIPAA & HITRUST
HealthCare Compliance - HIPAA & HITRUSTHealthCare Compliance - HIPAA & HITRUST
HealthCare Compliance - HIPAA & HITRUST
Kimberly Simon MBA
 
GDPR Jennifer Rose
GDPR Jennifer RoseGDPR Jennifer Rose
GDPR Jennifer Rose
Jennifer Rose
 
How to Collect and Process Data Under GDPR?
How to Collect and Process Data Under GDPR?How to Collect and Process Data Under GDPR?
How to Collect and Process Data Under GDPR?
Piwik PRO
 
Data protection and privacy in the world of database DevOps
Data protection and privacy in the world of database DevOpsData protection and privacy in the world of database DevOps
Data protection and privacy in the world of database DevOps
Red Gate Software
 
Seeley "Necessary Protections of Privacy"
Seeley "Necessary Protections of Privacy"Seeley "Necessary Protections of Privacy"
Seeley "Necessary Protections of Privacy"
National Information Standards Organization (NISO)
 
A practical guide to GDPR preparation
A practical guide to GDPR preparationA practical guide to GDPR preparation
A practical guide to GDPR preparation
Promapp Solutions
 

What's hot (20)

GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701
GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701
GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701
 
GDPR: The Regulator's Perspective, Peter Brown, ICO
GDPR: The Regulator's Perspective, Peter Brown, ICOGDPR: The Regulator's Perspective, Peter Brown, ICO
GDPR: The Regulator's Perspective, Peter Brown, ICO
 
The GDPR timeline - Stephen Bailey, NCC Group
The GDPR timeline - Stephen Bailey, NCC GroupThe GDPR timeline - Stephen Bailey, NCC Group
The GDPR timeline - Stephen Bailey, NCC Group
 
A Brief Overview on GDPR
A Brief Overview on GDPRA Brief Overview on GDPR
A Brief Overview on GDPR
 
Data security and privacy
Data security and privacyData security and privacy
Data security and privacy
 
EU's General Data Protection Regulation (GDPR)
EU's General Data Protection Regulation (GDPR)EU's General Data Protection Regulation (GDPR)
EU's General Data Protection Regulation (GDPR)
 
GDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to KnowGDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to Know
 
Finding Data at Risk for CCPA Compliance
Finding Data at Risk for CCPA ComplianceFinding Data at Risk for CCPA Compliance
Finding Data at Risk for CCPA Compliance
 
Preparing for GDPR Compliance...
Preparing for GDPR Compliance...Preparing for GDPR Compliance...
Preparing for GDPR Compliance...
 
Data Protection Officer Dashboard | GDPR
Data Protection Officer Dashboard | GDPRData Protection Officer Dashboard | GDPR
Data Protection Officer Dashboard | GDPR
 
Effective data protection for businesses with multiple locations
Effective data protection for businesses with multiple locationsEffective data protection for businesses with multiple locations
Effective data protection for businesses with multiple locations
 
7 Key GDPR Requirements & the Role of Data Governance
7 Key GDPR Requirements & the Role of Data Governance7 Key GDPR Requirements & the Role of Data Governance
7 Key GDPR Requirements & the Role of Data Governance
 
Understanding gdpr compliance gdpr analytics tools
Understanding gdpr compliance  gdpr analytics toolsUnderstanding gdpr compliance  gdpr analytics tools
Understanding gdpr compliance gdpr analytics tools
 
Mastering Article 30 Compliance: Conducting, Maintaining & Reporting on your ...
Mastering Article 30 Compliance: Conducting, Maintaining & Reporting on your ...Mastering Article 30 Compliance: Conducting, Maintaining & Reporting on your ...
Mastering Article 30 Compliance: Conducting, Maintaining & Reporting on your ...
 
HealthCare Compliance - HIPAA & HITRUST
HealthCare Compliance - HIPAA & HITRUSTHealthCare Compliance - HIPAA & HITRUST
HealthCare Compliance - HIPAA & HITRUST
 
GDPR Jennifer Rose
GDPR Jennifer RoseGDPR Jennifer Rose
GDPR Jennifer Rose
 
How to Collect and Process Data Under GDPR?
How to Collect and Process Data Under GDPR?How to Collect and Process Data Under GDPR?
How to Collect and Process Data Under GDPR?
 
Data protection and privacy in the world of database DevOps
Data protection and privacy in the world of database DevOpsData protection and privacy in the world of database DevOps
Data protection and privacy in the world of database DevOps
 
Seeley "Necessary Protections of Privacy"
Seeley "Necessary Protections of Privacy"Seeley "Necessary Protections of Privacy"
Seeley "Necessary Protections of Privacy"
 
A practical guide to GDPR preparation
A practical guide to GDPR preparationA practical guide to GDPR preparation
A practical guide to GDPR preparation
 

Similar to GDPR Readiness for Software Usage Analytics

Using GDPR to Transform Customer Experience
Using GDPR to Transform Customer ExperienceUsing GDPR to Transform Customer Experience
Using GDPR to Transform Customer Experience
MongoDB
 
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
One North
 
Whos role is it anyway
Whos role is it anywayWhos role is it anyway
Whos role is it anyway
IRIS
 
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdpr
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdprSharp Cookie Advisors legal_botar_ai_dataskydd_gdpr
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdpr
Sharp Cookie Advisors
 
Toreon adding privacy by design in secure application development oss18 v20...
Toreon adding privacy by design in secure application development   oss18 v20...Toreon adding privacy by design in secure application development   oss18 v20...
Toreon adding privacy by design in secure application development oss18 v20...
Sebastien Deleersnyder
 
GDPR- The Buck Stops Here
GDPR-  The Buck Stops HereGDPR-  The Buck Stops Here
GDPR- The Buck Stops Here
Kellyn Pot'Vin-Gorman
 
Michael Josephs
Michael JosephsMichael Josephs
Michael Josephs
daveGBE
 
How Cloudera SDX can aid GDPR compliance
How Cloudera SDX can aid GDPR complianceHow Cloudera SDX can aid GDPR compliance
How Cloudera SDX can aid GDPR compliance
Cloudera, Inc.
 
Iron Mountain® Policy Center Solution Enterprise Edition
Iron Mountain® Policy Center Solution Enterprise EditionIron Mountain® Policy Center Solution Enterprise Edition
Iron Mountain® Policy Center Solution Enterprise Edition
InfoGoTo
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firms
accenture
 
Countdown to CCPA: 48 Days Until Your IBM i Data Needs to Be Secured
Countdown to CCPA: 48 Days Until Your IBM i Data Needs to Be SecuredCountdown to CCPA: 48 Days Until Your IBM i Data Needs to Be Secured
Countdown to CCPA: 48 Days Until Your IBM i Data Needs to Be Secured
Precisely
 
Privacy Policies: Guide to Protecting User Data
Privacy Policies: Guide to Protecting User DataPrivacy Policies: Guide to Protecting User Data
Privacy Policies: Guide to Protecting User Data
PrivacyCenter.cloud
 
GDPR Noncompliance: Avoid the Risk with Data Virtualization
GDPR Noncompliance: Avoid the Risk with Data VirtualizationGDPR Noncompliance: Avoid the Risk with Data Virtualization
GDPR Noncompliance: Avoid the Risk with Data Virtualization
Denodo
 
Hadoop: Making it work for the Business Unit
Hadoop: Making it work for the Business UnitHadoop: Making it work for the Business Unit
Hadoop: Making it work for the Business UnitDataWorks Summit
 
General Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) ComplianceGeneral Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) Compliance
accenture
 
Why We Require GDPR?
Why We Require GDPR?Why We Require GDPR?
Why We Require GDPR?
Jatin Kochhar
 
Prepare Your Firm for GDPR
Prepare Your Firm for GDPRPrepare Your Firm for GDPR
Prepare Your Firm for GDPR
MyComplianceOffice
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
Vuzion
 
Partner enablement GDPR
Partner enablement GDPRPartner enablement GDPR
Partner enablement GDPR
Juan Niekerk
 
Hadoop and Financial Services
Hadoop and Financial ServicesHadoop and Financial Services
Hadoop and Financial Services
Cloudera, Inc.
 

Similar to GDPR Readiness for Software Usage Analytics (20)

Using GDPR to Transform Customer Experience
Using GDPR to Transform Customer ExperienceUsing GDPR to Transform Customer Experience
Using GDPR to Transform Customer Experience
 
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
 
Whos role is it anyway
Whos role is it anywayWhos role is it anyway
Whos role is it anyway
 
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdpr
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdprSharp Cookie Advisors legal_botar_ai_dataskydd_gdpr
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdpr
 
Toreon adding privacy by design in secure application development oss18 v20...
Toreon adding privacy by design in secure application development   oss18 v20...Toreon adding privacy by design in secure application development   oss18 v20...
Toreon adding privacy by design in secure application development oss18 v20...
 
GDPR- The Buck Stops Here
GDPR-  The Buck Stops HereGDPR-  The Buck Stops Here
GDPR- The Buck Stops Here
 
Michael Josephs
Michael JosephsMichael Josephs
Michael Josephs
 
How Cloudera SDX can aid GDPR compliance
How Cloudera SDX can aid GDPR complianceHow Cloudera SDX can aid GDPR compliance
How Cloudera SDX can aid GDPR compliance
 
Iron Mountain® Policy Center Solution Enterprise Edition
Iron Mountain® Policy Center Solution Enterprise EditionIron Mountain® Policy Center Solution Enterprise Edition
Iron Mountain® Policy Center Solution Enterprise Edition
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firms
 
Countdown to CCPA: 48 Days Until Your IBM i Data Needs to Be Secured
Countdown to CCPA: 48 Days Until Your IBM i Data Needs to Be SecuredCountdown to CCPA: 48 Days Until Your IBM i Data Needs to Be Secured
Countdown to CCPA: 48 Days Until Your IBM i Data Needs to Be Secured
 
Privacy Policies: Guide to Protecting User Data
Privacy Policies: Guide to Protecting User DataPrivacy Policies: Guide to Protecting User Data
Privacy Policies: Guide to Protecting User Data
 
GDPR Noncompliance: Avoid the Risk with Data Virtualization
GDPR Noncompliance: Avoid the Risk with Data VirtualizationGDPR Noncompliance: Avoid the Risk with Data Virtualization
GDPR Noncompliance: Avoid the Risk with Data Virtualization
 
Hadoop: Making it work for the Business Unit
Hadoop: Making it work for the Business UnitHadoop: Making it work for the Business Unit
Hadoop: Making it work for the Business Unit
 
General Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) ComplianceGeneral Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) Compliance
 
Why We Require GDPR?
Why We Require GDPR?Why We Require GDPR?
Why We Require GDPR?
 
Prepare Your Firm for GDPR
Prepare Your Firm for GDPRPrepare Your Firm for GDPR
Prepare Your Firm for GDPR
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 
Partner enablement GDPR
Partner enablement GDPRPartner enablement GDPR
Partner enablement GDPR
 
Hadoop and Financial Services
Hadoop and Financial ServicesHadoop and Financial Services
Hadoop and Financial Services
 

Recently uploaded

WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital TransformationWSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2
 
Into the Box 2024 - Keynote Day 2 Slides.pdf
Into the Box 2024 - Keynote Day 2 Slides.pdfInto the Box 2024 - Keynote Day 2 Slides.pdf
Into the Box 2024 - Keynote Day 2 Slides.pdf
Ortus Solutions, Corp
 
Cyaniclab : Software Development Agency Portfolio.pdf
Cyaniclab : Software Development Agency Portfolio.pdfCyaniclab : Software Development Agency Portfolio.pdf
Cyaniclab : Software Development Agency Portfolio.pdf
Cyanic lab
 
Designing for Privacy in Amazon Web Services
Designing for Privacy in Amazon Web ServicesDesigning for Privacy in Amazon Web Services
Designing for Privacy in Amazon Web Services
KrzysztofKkol1
 
Providing Globus Services to Users of JASMIN for Environmental Data Analysis
Providing Globus Services to Users of JASMIN for Environmental Data AnalysisProviding Globus Services to Users of JASMIN for Environmental Data Analysis
Providing Globus Services to Users of JASMIN for Environmental Data Analysis
Globus
 
Developing Distributed High-performance Computing Capabilities of an Open Sci...
Developing Distributed High-performance Computing Capabilities of an Open Sci...Developing Distributed High-performance Computing Capabilities of an Open Sci...
Developing Distributed High-performance Computing Capabilities of an Open Sci...
Globus
 
Globus Compute Introduction - GlobusWorld 2024
Globus Compute Introduction - GlobusWorld 2024Globus Compute Introduction - GlobusWorld 2024
Globus Compute Introduction - GlobusWorld 2024
Globus
 
Large Language Models and the End of Programming
Large Language Models and the End of ProgrammingLarge Language Models and the End of Programming
Large Language Models and the End of Programming
Matt Welsh
 
How Does XfilesPro Ensure Security While Sharing Documents in Salesforce?
How Does XfilesPro Ensure Security While Sharing Documents in Salesforce?How Does XfilesPro Ensure Security While Sharing Documents in Salesforce?
How Does XfilesPro Ensure Security While Sharing Documents in Salesforce?
XfilesPro
 
Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus Compute wth IRI Workflows - GlobusWorld 2024Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus
 
Understanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSageUnderstanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSage
Globus
 
Lecture 1 Introduction to games development
Lecture 1 Introduction to games developmentLecture 1 Introduction to games development
Lecture 1 Introduction to games development
abdulrafaychaudhry
 
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Globus
 
Vitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume MontevideoVitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume Montevideo
Vitthal Shirke
 
Advanced Flow Concepts Every Developer Should Know
Advanced Flow Concepts Every Developer Should KnowAdvanced Flow Concepts Every Developer Should Know
Advanced Flow Concepts Every Developer Should Know
Peter Caitens
 
TROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERROR
TROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERRORTROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERROR
TROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERROR
Tier1 app
 
How Recreation Management Software Can Streamline Your Operations.pptx
How Recreation Management Software Can Streamline Your Operations.pptxHow Recreation Management Software Can Streamline Your Operations.pptx
How Recreation Management Software Can Streamline Your Operations.pptx
wottaspaceseo
 
Cracking the code review at SpringIO 2024
Cracking the code review at SpringIO 2024Cracking the code review at SpringIO 2024
Cracking the code review at SpringIO 2024
Paco van Beckhoven
 
Field Employee Tracking System| MiTrack App| Best Employee Tracking Solution|...
Field Employee Tracking System| MiTrack App| Best Employee Tracking Solution|...Field Employee Tracking System| MiTrack App| Best Employee Tracking Solution|...
Field Employee Tracking System| MiTrack App| Best Employee Tracking Solution|...
informapgpstrackings
 
Why React Native as a Strategic Advantage for Startup Innovation.pdf
Why React Native as a Strategic Advantage for Startup Innovation.pdfWhy React Native as a Strategic Advantage for Startup Innovation.pdf
Why React Native as a Strategic Advantage for Startup Innovation.pdf
ayushiqss
 

Recently uploaded (20)

WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital TransformationWSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
 
Into the Box 2024 - Keynote Day 2 Slides.pdf
Into the Box 2024 - Keynote Day 2 Slides.pdfInto the Box 2024 - Keynote Day 2 Slides.pdf
Into the Box 2024 - Keynote Day 2 Slides.pdf
 
Cyaniclab : Software Development Agency Portfolio.pdf
Cyaniclab : Software Development Agency Portfolio.pdfCyaniclab : Software Development Agency Portfolio.pdf
Cyaniclab : Software Development Agency Portfolio.pdf
 
Designing for Privacy in Amazon Web Services
Designing for Privacy in Amazon Web ServicesDesigning for Privacy in Amazon Web Services
Designing for Privacy in Amazon Web Services
 
Providing Globus Services to Users of JASMIN for Environmental Data Analysis
Providing Globus Services to Users of JASMIN for Environmental Data AnalysisProviding Globus Services to Users of JASMIN for Environmental Data Analysis
Providing Globus Services to Users of JASMIN for Environmental Data Analysis
 
Developing Distributed High-performance Computing Capabilities of an Open Sci...
Developing Distributed High-performance Computing Capabilities of an Open Sci...Developing Distributed High-performance Computing Capabilities of an Open Sci...
Developing Distributed High-performance Computing Capabilities of an Open Sci...
 
Globus Compute Introduction - GlobusWorld 2024
Globus Compute Introduction - GlobusWorld 2024Globus Compute Introduction - GlobusWorld 2024
Globus Compute Introduction - GlobusWorld 2024
 
Large Language Models and the End of Programming
Large Language Models and the End of ProgrammingLarge Language Models and the End of Programming
Large Language Models and the End of Programming
 
How Does XfilesPro Ensure Security While Sharing Documents in Salesforce?
How Does XfilesPro Ensure Security While Sharing Documents in Salesforce?How Does XfilesPro Ensure Security While Sharing Documents in Salesforce?
How Does XfilesPro Ensure Security While Sharing Documents in Salesforce?
 
Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus Compute wth IRI Workflows - GlobusWorld 2024Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus Compute wth IRI Workflows - GlobusWorld 2024
 
Understanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSageUnderstanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSage
 
Lecture 1 Introduction to games development
Lecture 1 Introduction to games developmentLecture 1 Introduction to games development
Lecture 1 Introduction to games development
 
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
 
Vitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume MontevideoVitthal Shirke Microservices Resume Montevideo
Vitthal Shirke Microservices Resume Montevideo
 
Advanced Flow Concepts Every Developer Should Know
Advanced Flow Concepts Every Developer Should KnowAdvanced Flow Concepts Every Developer Should Know
Advanced Flow Concepts Every Developer Should Know
 
TROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERROR
TROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERRORTROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERROR
TROUBLESHOOTING 9 TYPES OF OUTOFMEMORYERROR
 
How Recreation Management Software Can Streamline Your Operations.pptx
How Recreation Management Software Can Streamline Your Operations.pptxHow Recreation Management Software Can Streamline Your Operations.pptx
How Recreation Management Software Can Streamline Your Operations.pptx
 
Cracking the code review at SpringIO 2024
Cracking the code review at SpringIO 2024Cracking the code review at SpringIO 2024
Cracking the code review at SpringIO 2024
 
Field Employee Tracking System| MiTrack App| Best Employee Tracking Solution|...
Field Employee Tracking System| MiTrack App| Best Employee Tracking Solution|...Field Employee Tracking System| MiTrack App| Best Employee Tracking Solution|...
Field Employee Tracking System| MiTrack App| Best Employee Tracking Solution|...
 
Why React Native as a Strategic Advantage for Startup Innovation.pdf
Why React Native as a Strategic Advantage for Startup Innovation.pdfWhy React Native as a Strategic Advantage for Startup Innovation.pdf
Why React Native as a Strategic Advantage for Startup Innovation.pdf
 

GDPR Readiness for Software Usage Analytics

  • 1. GDPR Readiness for Software Usage Analytics November 7, 2017 Vic DeMarines VP, Products & Strategy Revulytics Bob Siegel President Privacy Ref
  • 2. Topics • What is Software Usage Analytics? • What is GDPR? • Privacy Concepts, Personal Information Defined • Data Controllers and Processors • GDPR and Protecting and Improving Your Software • How Revulytics Customers are Addressing These Issues 2
  • 3. About Revulytics Compliance Analytics • Identify and quantify software use and misuse • Create actionable intelligence • Turn intelligence into direct revenue Usage Analytics • Anonymous feature tracking and analysis of product usage • Increase customer acquisition and retention • Generate revenue with better products 3 • Recognized as 2017 Gartner Cool Vendor • More than 100 customers including Fortune 500 companies • Technology deployed to over 50M machines in more than 200 countries • Our data has supported more than $1.8 billion in new license revenue since 2010
  • 4. Software Usage Intelligence Solution Architecture 4 Cloud Service Usage Intelligence Reporting Dashboard Data Analytics Engine Integrated Applications Configured to focus on feature adoption ReachOut In Application messaging
  • 5. Compliance Intelligence Solution Architecture 5 Cloud Service Compliance Dashboard on Force.com Integrated Applications Configured to identify organizations and true location Gateway Servers Revulytics Data Optimizer and Analysts Revulytics Recovery Services
  • 6. What is GDPR? • General Data Privacy Regulation – Replaces the EU Privacy Directive (Directive 95/46/EC) – A pan-EU law – Becomes effective on May 25, 2018 • Five Principles – Lawfulness, fairness, and transparency – Purpose limitation – Data minimization and proportionality – Storage limitation – Accountability • Privacy Shield 6
  • 7. Privacy Concepts, Personal Information Defined • Data subject • Legal basis for processing • Data transfer 7 Personal Information… any information related to an identified or identifiable data subject • Privacy Policy • Privacy Notice Other Key Concepts • Name • Age/Birthdate • Gender • Employer • User-id • Email address • User name • Machine name • IP Address Revulytics Applicable
  • 8. Is IP Address Personal Information • Court of Justice of the European Union opinion – Breyer v Bundesrepublik Deutschland, Case C-582/14, 12 May 2016 – IP address combined with ISP records would constitute personal data in the hands of the website provider • Broader applicability: even if you’re not an ISP, it may be applicable – “could keep [the IP address] indefinitely and could request at any time from the Internet access service provider additional data to combine with the IP address in order identify the user” • Revulytics customer impact – Usage Intelligence: IP address only collected for location and is then deleted from system – Compliance Intelligence: A key piece of information to track compliance 8
  • 9. Data Controllers and Processors 9 Data Protection Authority / Supervisory Authority Data Subject Data Controller Data Processor End-user Your Company Revulytics
  • 10. GDPR and Protecting and Improving Your Software Lawfulness, fairness, and transparency • Lawfully processing information – Consent (Article 7) – Legitimate interest of the controller or a third party (Article 6) • Fairness and transparency – Include legal basis in your privacy notice – State that it will be shared with a third party (Revulytics) – State that processing may occur in the United States 10
  • 11. GDPR and Protecting and Improving Your Software Other principles • Purpose limitation • Data minimization and proportionality • Storage limitation • Accountability 11
  • 12. GDPR and Protecting and Improving Your Software Best practices and Revulytics products • Revulytics Compliance Intelligence – Use legitimate interests as a legal basis • Consent not required – Be transparent in your privacy notice – Define a reasonable retention period with Compliance Intelligence 12
  • 13. GDPR and Protecting and Improving Your Software Best practices and Revulytics products • Revulytics Usage Intelligence – Legitimate interests as a legal basis is an option • Consent not required: use of data to improve products – However, sensitivity of the environment may guide you towards consent • Example: Microsoft and Windows 10 • Consent requirements • Separate screen (not buried in a EULA) • Mechanism to change preference (opt-in or opt-out) at a later time – Collecting additional information • Avoid or limit collecting personal information • Usage Intelligence does not retain personal information by default – Be transparent in your privacy notice – Define a reasonable retention period with Usage Intelligence if collecting personal information 13
  • 14. GDPR and Protecting and Improving Your Software Best practices and Revulytics products • ReachOut functionality – You may send messages and surveys to the end-users • You have an existing business relationship • Contents must be related to the software being used – An opt-out mechanism must be supplied and respected • Allow end users to opt-in at a later time as well 14
  • 15. GDPR and Protecting and Improving Your Software Best practices for your privacy notice • Privacy notice requirements will vary based on your software • Be transparent about the information being collected • Link to the privacy notice where end users will expect to find it 15
  • 16. How Revulytics Customers Address These Issues Data Needed for Compliance 16 Consumer piracy Lower product ASP Piracy Response In-Application Messaging Direct Compliance Audit Specialize software Enterprise organizations Higher product ASP SMB Compliance Approach Data Collection Meter
  • 17. How Revulytics Customers Address These Issues • Wi-Fi SSID adds to the Domain Data and provides location intelligence 17
  • 18. Best Practices • Compliance Intelligence – Transparency and Privacy Policy key • Include extent of data collected, include description of data being collected • Note sharing of data with third party for your compliance program • 100% focused on compliance – Have a FAQ or whitepaper available that positions the deployment • Usage Intelligence – Implement opt-out functionality within the application, available to the user post- installation – Product related in-application messaging – Consider custom data being collected • Best practices - not a legal opinion – Include your usage and compliance data collection in your own GDPR assessment – Revulytics assessing its business and platform for GDPR compliance 18
  • 19. Conclusion • To view the full webinar recording and slides, check out the link in the comments. • Also , read the white paper, “Privacy, Piracy, and Product Usage GDPR Readiness for Software Usage Analytics” 19 Vic DeMarines VP, Products & Strategy Revulytics vdemarines@revulytics.com Bob Siegel President Privacy Ref bob.siegel@privacyref.com