SlideShare a Scribd company logo
1
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
v © TRUSTe Inc., 2017
ROI of Privacy: Building a Case for
Investment
April 27, 2017
2
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
Today’s Speakers
Emily Leach
Content Manager
International Association of Privacy Professionals (IAPP)
Paul Iagnocco,
Senior Privacy Consultant, TRUSTe
& former Chief Privacy Officer, Kellogg
Eleanor Treharne-Jones (Moderator)
VP Sales & Consulting
TRUSTe
Laurel Strand
Senior Privacy Consultant, TRUSTe
& former Senior Privacy Analyst at Intel
3
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
v © TRUSTe Inc., 2017
Consumers actually will cross the
street for a little privacy.
Trust has an effect on your bottom line.
4
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
SOME STATS:
51%
Are very concerned about
privacy
*Forrester
74%
Have limited their online
activity due to privacy
concerns
*TRUSTe
83%Only use
websites/vendors they
trust
*National Cyber
Security Alliance
89%
Avoid using companies
that don’t protect privacy
*TRUSTe
5
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
Consumers actually will cross the street for privacy.
• Young people are concerned and paying
attention to privacy protections.
• Many don’t understand how or think it’s a futile
venture to try to protect privacy.
• Losing customer trust = losing their business.
• Establishing your company as a trusted steward
of customers’ personal information is a way to set
yourself apart.
6
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
v © TRUSTe Inc., 2017
Everybody else is doing it.
Don’t be that one. You know, the one without a privacy program.
7
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
SOME STATS:
50%
Have increased privacy
involvement on security
teams
*IAPP/TRUSTe
$1MOn average, what U.S.
multinationals plan to
spend on GDPR
compliance
*PricewaterhouseCoopers
75K
Estimated number of
DPOs needed worldwide
to comply with the GDPR
*IAPP
$354
What companies spend
on privacy globally per
employee
*TRUSTe
8
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
• What does your company spend on privacy
including salaries?
– Under 250k
– 250k - 500k
– 500k – 1m
– 1m – 2m
– Over 2m
POLL QUESTION
9
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
Everybody else is doing it.
• Apple’s stand against the FBI in San Bernardino
case
• Microsoft fights to keep data safe that’s stored
on Irish server
• Amazon pushing back on a search warrant for
Echo voice data
• Big Tech companies file amicus brief against
Facebook gag order
10
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
v © TRUSTe Inc., 2017
Knowledge is power – and a business
asset.
Data is currency, and you should protect it as such.
11
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
SOME STATS:
9%Marketers that sell data or
data services to
customers and/or
partners
*Forrester
£3,241The financial value U.K.
individuals put on their
data
*Western Digital
$800M
Data broker Axciom’s
reported revenue for 2015
*NPR
$240
The dollar value U.S.
consumers put on a SSN
*Aricent/Frog Design
12
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
• Data is the new oil
• Data as currency
• Data driven economy
• Every company is a data company
• Data brokerage is a $200B industry
Knowledge is power – and a business asset.
13
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
• How many people are working on privacy in your
organization (full time + part time)?
– 1
– 2 – 3
– 4 – 10
– + 10
POLL QUESTION
14
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
v © TRUSTe Inc., 2017
Avoid fines and sanctions.
Regulators aren’t out to get the good-guys.
15
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
SOME STATS:
130+
Spam and
spyware cases addressed
by the FTC in 2016
*U.S. FTC
€20M
Potential fine for violating
the GDPR or 4% of annual
revenue
*GDPR
$2.5M2017 HHS HIPAA
settlement amount with a
wireless health services
provider
*U.S. HHS
£350K
GA recent fine levied by
the U.K. ICO for a spam
violation
*U.K. ICO
16
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
Avoid fines and sanctions.
• “… the mere fact that a breach occurred doesn’t mean a
company broke the law … We don’t impose strict liability for a
breach. We don’t expect companies to be perfect.”
— Maureen Olhausen, U.S. FTC
• “With our enforcement actions, we will consider what steps were
taken beforehand, how cooperative the organization is and the
size of the breach.”
— Aileen Chia, Singapore PDPC
• “If an organisation can’t demonstrate that good data protection is
a cornerstone of their business policy and practices, they’re
leaving themselves open to enforcement action that can damage
their public reputation and possibly their bank balance. That
makes data protection a boardroom issue.”
— Elizabeth Denham, U.K. ICO
17
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
v © TRUSTe Inc., 2017
Funding.
Venture Capitalists are big on privacy.
18
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
SOME STATS:
$4MThe seed funding Privacy
Labs received to give
users control of internet
data
*TechCrunch
$350M
The decrease in Yahoo’s
purchase price after the
revelation of its data
breaches
*CNN
$35MAmount of VC funding
three online privacy
companies received in
2010
*WSJ
$2.7MFunding for
CheckRecipient to use
machine learning to
prevent breaches
*TRUSTe
19
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
Funding.
• In 2015, VC firm Andreessen Horowitz hired Ted Ullyot to
launch a new policy to help its portfolio companies navigate
state and federal regulations when developing new data-
fueled services.
• “It’s definitely part of our due diligence … when we have
companies that are storing customer data, like public cloud
services. What are they doing with data retention and
protection?”
— Steve Herrod, General Catalyst
• “Privacy is entering the conversation much earlier, and data
privacy is very strongly tied to the overall information
security. These are discussions at a very high level.”
— Ursheet Parikh, Mayfield
20
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
v © TRUSTe Inc., 2017
Data breaches cost a lot. And they’re
largely preventable.
It’s become almost inevitable, so be prepared!
21
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
SOME STATS:
26%
Likelihood of a breach of
10,000+ records in the
next 24 months
*Ponemon
$4M
Average consolidated cost
of a data breach
*Ponemon
36M+
Number of U.S. records
compromised due to a
breach in 2016
*IDT911
$450BWhat cyber crime cost
the global economy in
2016
*Hiscox
22
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
Data Breaches.
• Human error continues to be a major contributor to
data breaches
• Having an incident response team can reduce the
cost of a breach by $16 per capita
• Training employees can reduce that cost by $9 per
capita
• The biggest financial consequence from a breach is
lost business
• This is not going away
23
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
v © TRUSTe Inc., 2017
Questions?
24
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
v © TRUSTe Inc., 2017
Emily Leach emily@iapp.org
Paul Iagnocco piagnocco@truste.com
Laurel Strand lstrand@truste.com
Eleanor Treharne-Jones eleanor@truste.com
Contacts
25
vPrivacy Insight Series - truste.com/insightseries
© TRUSTe Inc., 2017
v © TRUSTe Inc., 2017
Register now for the next webinar in our 2017 Winter/Spring Webinar Series
on May 23 “GDPR: DPIA & Data Breach Requirements – Assessing
Individual Harm”
See http://www.truste.com/insightseries for the 2017 Privacy Insight Series
and past webinar recordings.
Thank You!

More Related Content

What's hot

Cybersecurity Legal and Compliance Issues Business & IT Leaders Must Know -- ...
Cybersecurity Legal and Compliance Issues Business & IT Leaders Must Know -- ...Cybersecurity Legal and Compliance Issues Business & IT Leaders Must Know -- ...
Cybersecurity Legal and Compliance Issues Business & IT Leaders Must Know -- ...
Shawn Tuma
 

What's hot (20)

Managing Consent and Legitimate Interests Under the GDPR [Webinar Slides]
Managing Consent and Legitimate Interests Under the GDPR [Webinar Slides]Managing Consent and Legitimate Interests Under the GDPR [Webinar Slides]
Managing Consent and Legitimate Interests Under the GDPR [Webinar Slides]
 
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]
 
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
 
2021 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...
2021 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...2021 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...
2021 Global Privacy Survey: Emerging Trends, Benchmarking Research and Best P...
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
 
Splunk: How Machine Data Supports GDPR Compliance
Splunk: How Machine Data Supports GDPR ComplianceSplunk: How Machine Data Supports GDPR Compliance
Splunk: How Machine Data Supports GDPR Compliance
 
General Data Protection Regulation: Where are we now?
General Data Protection Regulation: Where are we now?General Data Protection Regulation: Where are we now?
General Data Protection Regulation: Where are we now?
 
Security Regulations & Guidelines: Is Your Business on the Path to Compliance?
Security Regulations & Guidelines:  Is Your Business on the Path to Compliance? Security Regulations & Guidelines:  Is Your Business on the Path to Compliance?
Security Regulations & Guidelines: Is Your Business on the Path to Compliance?
 
CWIN17 New-York / earning the currency of trust
CWIN17 New-York / earning the currency of trustCWIN17 New-York / earning the currency of trust
CWIN17 New-York / earning the currency of trust
 
5 Steps to Prepare for Digital Transformation & Real-Time Analytics
5 Steps to Prepare for Digital Transformation & Real-Time Analytics 5 Steps to Prepare for Digital Transformation & Real-Time Analytics
5 Steps to Prepare for Digital Transformation & Real-Time Analytics
 
Convince your board: How to prepare your business for List X
Convince your board: How to prepare your business for List XConvince your board: How to prepare your business for List X
Convince your board: How to prepare your business for List X
 
Cybersecurity Legal and Compliance Issues Business & IT Leaders Must Know -- ...
Cybersecurity Legal and Compliance Issues Business & IT Leaders Must Know -- ...Cybersecurity Legal and Compliance Issues Business & IT Leaders Must Know -- ...
Cybersecurity Legal and Compliance Issues Business & IT Leaders Must Know -- ...
 
Cloud Storage: How to Fight Off Data Security Threats & Stay Compliant
Cloud Storage: How to Fight Off Data Security Threats & Stay CompliantCloud Storage: How to Fight Off Data Security Threats & Stay Compliant
Cloud Storage: How to Fight Off Data Security Threats & Stay Compliant
 
The state of data privacy with dimensional research
The state of data privacy with dimensional research The state of data privacy with dimensional research
The state of data privacy with dimensional research
 
Webianr: GDPR: How to build a data protection framework
Webianr: GDPR: How to build a data protection frameworkWebianr: GDPR: How to build a data protection framework
Webianr: GDPR: How to build a data protection framework
 
Security, Risk, Compliance & Controls - Cybersecurity Legal Framework in Hong...
Security, Risk, Compliance & Controls - Cybersecurity Legal Framework in Hong...Security, Risk, Compliance & Controls - Cybersecurity Legal Framework in Hong...
Security, Risk, Compliance & Controls - Cybersecurity Legal Framework in Hong...
 
GDPR How to get started?
GDPR  How to get started?GDPR  How to get started?
GDPR How to get started?
 
GDPR: The Regulator's Perspective, Peter Brown, ICO
GDPR: The Regulator's Perspective, Peter Brown, ICOGDPR: The Regulator's Perspective, Peter Brown, ICO
GDPR: The Regulator's Perspective, Peter Brown, ICO
 
The EU General Protection Regulation and how Oracle can help
The EU General Protection Regulation and how Oracle can help The EU General Protection Regulation and how Oracle can help
The EU General Protection Regulation and how Oracle can help
 
New Strategies for More Effective Remote/Branch Office Data Protection
New Strategies for More Effective Remote/Branch Office Data ProtectionNew Strategies for More Effective Remote/Branch Office Data Protection
New Strategies for More Effective Remote/Branch Office Data Protection
 

Similar to ROI of Privacy: Building a Case for Investment [Webinar Slides]

Information Security vs. Data Governance vs. Data Protection: What Is the Rea...
Information Security vs. Data Governance vs. Data Protection: What Is the Rea...Information Security vs. Data Governance vs. Data Protection: What Is the Rea...
Information Security vs. Data Governance vs. Data Protection: What Is the Rea...
PECB
 
SecureWorld Expo Dallas - Cybersecurity Law: What Business and IT Leaders Nee...
SecureWorld Expo Dallas - Cybersecurity Law: What Business and IT Leaders Nee...SecureWorld Expo Dallas - Cybersecurity Law: What Business and IT Leaders Nee...
SecureWorld Expo Dallas - Cybersecurity Law: What Business and IT Leaders Nee...
Shawn Tuma
 

Similar to ROI of Privacy: Building a Case for Investment [Webinar Slides] (20)

Information Security vs. Data Governance vs. Data Protection: What Is the Rea...
Information Security vs. Data Governance vs. Data Protection: What Is the Rea...Information Security vs. Data Governance vs. Data Protection: What Is the Rea...
Information Security vs. Data Governance vs. Data Protection: What Is the Rea...
 
Identity Live Singapore: Transform Your Cybersecurity Capability
Identity Live Singapore: Transform Your Cybersecurity CapabilityIdentity Live Singapore: Transform Your Cybersecurity Capability
Identity Live Singapore: Transform Your Cybersecurity Capability
 
Corporate & Regulatory Compliance Boot Camp - Data Privacy Compliance
Corporate & Regulatory Compliance Boot Camp - Data Privacy ComplianceCorporate & Regulatory Compliance Boot Camp - Data Privacy Compliance
Corporate & Regulatory Compliance Boot Camp - Data Privacy Compliance
 
2019 08-21 Automating Privacy Management
2019 08-21 Automating Privacy Management2019 08-21 Automating Privacy Management
2019 08-21 Automating Privacy Management
 
Data Privacy Compliance
Data Privacy ComplianceData Privacy Compliance
Data Privacy Compliance
 
2016 Global data valuation survey
2016 Global data valuation survey2016 Global data valuation survey
2016 Global data valuation survey
 
ThinAir Endpoint Visibility Security HIMSS2018 Brian_Reed
ThinAir Endpoint Visibility Security HIMSS2018 Brian_ReedThinAir Endpoint Visibility Security HIMSS2018 Brian_Reed
ThinAir Endpoint Visibility Security HIMSS2018 Brian_Reed
 
A Day in the Life of a GDPR Breach
A Day in the Life of a GDPR BreachA Day in the Life of a GDPR Breach
A Day in the Life of a GDPR Breach
 
Ntxissacsc5 purple 3-cyber insurance essentials-shawn_tuma.pptx
Ntxissacsc5 purple 3-cyber insurance essentials-shawn_tuma.pptxNtxissacsc5 purple 3-cyber insurance essentials-shawn_tuma.pptx
Ntxissacsc5 purple 3-cyber insurance essentials-shawn_tuma.pptx
 
The Essentials of Cyber Insurance: A Panel of Industry Experts
The Essentials of Cyber Insurance: A Panel of Industry ExpertsThe Essentials of Cyber Insurance: A Panel of Industry Experts
The Essentials of Cyber Insurance: A Panel of Industry Experts
 
SecureWorld Expo Dallas - Cybersecurity Law: What Business and IT Leaders Nee...
SecureWorld Expo Dallas - Cybersecurity Law: What Business and IT Leaders Nee...SecureWorld Expo Dallas - Cybersecurity Law: What Business and IT Leaders Nee...
SecureWorld Expo Dallas - Cybersecurity Law: What Business and IT Leaders Nee...
 
Investing in Digital Threat Intelligence Management to Protect Your Assets ou...
Investing in Digital Threat Intelligence Management to Protect Your Assets ou...Investing in Digital Threat Intelligence Management to Protect Your Assets ou...
Investing in Digital Threat Intelligence Management to Protect Your Assets ou...
 
Webinar The Role of Trust in Digital policy 2016
Webinar The Role of Trust in Digital policy 2016Webinar The Role of Trust in Digital policy 2016
Webinar The Role of Trust in Digital policy 2016
 
FS-ISAC APAC Summit 2017 Singapore - Of Crown Jewels and Data Assets
FS-ISAC APAC Summit 2017 Singapore - Of Crown Jewels and Data AssetsFS-ISAC APAC Summit 2017 Singapore - Of Crown Jewels and Data Assets
FS-ISAC APAC Summit 2017 Singapore - Of Crown Jewels and Data Assets
 
The Privacy Advantage 2016 - Amit Pau
The Privacy Advantage 2016 - Amit PauThe Privacy Advantage 2016 - Amit Pau
The Privacy Advantage 2016 - Amit Pau
 
State of cybersecurity
State of cybersecurityState of cybersecurity
State of cybersecurity
 
Data Privacy Compliance (Series: Corporate & Regulatory Compliance Boot Camp)
Data Privacy Compliance (Series: Corporate & Regulatory Compliance Boot Camp)Data Privacy Compliance (Series: Corporate & Regulatory Compliance Boot Camp)
Data Privacy Compliance (Series: Corporate & Regulatory Compliance Boot Camp)
 
Is it time for an IT Assessment?
Is it time for an IT Assessment?Is it time for an IT Assessment?
Is it time for an IT Assessment?
 
Cyber attack response from the CEO perspective - Tallinn Estonia - Short Simu...
Cyber attack response from the CEO perspective - Tallinn Estonia - Short Simu...Cyber attack response from the CEO perspective - Tallinn Estonia - Short Simu...
Cyber attack response from the CEO perspective - Tallinn Estonia - Short Simu...
 
Getting Started with Data Governance? Use Process Models!
Getting Started with Data Governance? Use Process Models!Getting Started with Data Governance? Use Process Models!
Getting Started with Data Governance? Use Process Models!
 

More from TrustArc

TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc
 
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
TrustArc
 

More from TrustArc (20)

TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
 
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI Innovations
 
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
 
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
 
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
 
Nymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesNymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 States
 
CBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceCBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy Compliance
 
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfEverything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
 
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
 
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsPrivacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
 
Building Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsBuilding Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy Certifications
 
The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...
 
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
 
Artificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceArtificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI Governance
 
How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023
 

Recently uploaded

Agrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quizAgrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quiz
gaelcabigunda
 
Notes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.docNotes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.doc
BRELGOSIMAT
 

Recently uploaded (20)

Highlights_of_Bhartiya_Nyaya_Sanhita.pptx
Highlights_of_Bhartiya_Nyaya_Sanhita.pptxHighlights_of_Bhartiya_Nyaya_Sanhita.pptx
Highlights_of_Bhartiya_Nyaya_Sanhita.pptx
 
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
VIETNAM - DIRECT POWER PURCHASE AGREEMENTS (DPPA) - Latest development - What...
 
Agrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quizAgrarian Reform Policies in the Philippines: a quiz
Agrarian Reform Policies in the Philippines: a quiz
 
Charge and its essentials rules Under the CRPC, 1898
Charge and its essentials rules Under the CRPC, 1898Charge and its essentials rules Under the CRPC, 1898
Charge and its essentials rules Under the CRPC, 1898
 
DNA Testing in Civil and Criminal Matters.pptx
DNA Testing in Civil and Criminal Matters.pptxDNA Testing in Civil and Criminal Matters.pptx
DNA Testing in Civil and Criminal Matters.pptx
 
ADR in criminal proceeding in Bangladesh with global perspective.
ADR in criminal proceeding in Bangladesh with global perspective.ADR in criminal proceeding in Bangladesh with global perspective.
ADR in criminal proceeding in Bangladesh with global perspective.
 
indian evidence act.pdf.......very helpful for law student
indian evidence act.pdf.......very helpful for law studentindian evidence act.pdf.......very helpful for law student
indian evidence act.pdf.......very helpful for law student
 
The Main Procedures for Obtaining Cypriot Citizenship
The Main Procedures for Obtaining Cypriot CitizenshipThe Main Procedures for Obtaining Cypriot Citizenship
The Main Procedures for Obtaining Cypriot Citizenship
 
Abdul Hakim Shabazz Deposition Hearing in Federal Court
Abdul Hakim Shabazz Deposition Hearing in Federal CourtAbdul Hakim Shabazz Deposition Hearing in Federal Court
Abdul Hakim Shabazz Deposition Hearing in Federal Court
 
Debt Mapping Camp bebas riba to know how much our debt
Debt Mapping Camp bebas riba to know how much our debtDebt Mapping Camp bebas riba to know how much our debt
Debt Mapping Camp bebas riba to know how much our debt
 
Law of Torts and Nuisance Presentation.pptx
Law of Torts and Nuisance Presentation.pptxLaw of Torts and Nuisance Presentation.pptx
Law of Torts and Nuisance Presentation.pptx
 
Cold War - 1, talks about cold water bro
Cold War - 1, talks about cold water broCold War - 1, talks about cold water bro
Cold War - 1, talks about cold water bro
 
Secure Your Brand: File a Trademark Today
Secure Your Brand: File a Trademark TodaySecure Your Brand: File a Trademark Today
Secure Your Brand: File a Trademark Today
 
Everything You Should Know About Child Custody and Parenting While Living in ...
Everything You Should Know About Child Custody and Parenting While Living in ...Everything You Should Know About Child Custody and Parenting While Living in ...
Everything You Should Know About Child Custody and Parenting While Living in ...
 
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdfDonald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
 
Notes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.docNotes-on-Prescription-Obligations-and-Contracts.doc
Notes-on-Prescription-Obligations-and-Contracts.doc
 
PRECEDENT AS A SOURCE OF LAW (SAIF JAVED).pptx
PRECEDENT AS A SOURCE OF LAW (SAIF JAVED).pptxPRECEDENT AS A SOURCE OF LAW (SAIF JAVED).pptx
PRECEDENT AS A SOURCE OF LAW (SAIF JAVED).pptx
 
ALL EYES ON RAFAH BUT WHY Explain more.pdf
ALL EYES ON RAFAH BUT WHY Explain more.pdfALL EYES ON RAFAH BUT WHY Explain more.pdf
ALL EYES ON RAFAH BUT WHY Explain more.pdf
 
Military Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
Military Commissions details LtCol Thomas Jasper as Detailed Defense CounselMilitary Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
Military Commissions details LtCol Thomas Jasper as Detailed Defense Counsel
 
Types of Cybercrime and Its Impact on Society
Types of Cybercrime and Its Impact on SocietyTypes of Cybercrime and Its Impact on Society
Types of Cybercrime and Its Impact on Society
 

ROI of Privacy: Building a Case for Investment [Webinar Slides]

  • 1. 1 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 v © TRUSTe Inc., 2017 ROI of Privacy: Building a Case for Investment April 27, 2017
  • 2. 2 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 Today’s Speakers Emily Leach Content Manager International Association of Privacy Professionals (IAPP) Paul Iagnocco, Senior Privacy Consultant, TRUSTe & former Chief Privacy Officer, Kellogg Eleanor Treharne-Jones (Moderator) VP Sales & Consulting TRUSTe Laurel Strand Senior Privacy Consultant, TRUSTe & former Senior Privacy Analyst at Intel
  • 3. 3 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 v © TRUSTe Inc., 2017 Consumers actually will cross the street for a little privacy. Trust has an effect on your bottom line.
  • 4. 4 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 SOME STATS: 51% Are very concerned about privacy *Forrester 74% Have limited their online activity due to privacy concerns *TRUSTe 83%Only use websites/vendors they trust *National Cyber Security Alliance 89% Avoid using companies that don’t protect privacy *TRUSTe
  • 5. 5 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 Consumers actually will cross the street for privacy. • Young people are concerned and paying attention to privacy protections. • Many don’t understand how or think it’s a futile venture to try to protect privacy. • Losing customer trust = losing their business. • Establishing your company as a trusted steward of customers’ personal information is a way to set yourself apart.
  • 6. 6 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 v © TRUSTe Inc., 2017 Everybody else is doing it. Don’t be that one. You know, the one without a privacy program.
  • 7. 7 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 SOME STATS: 50% Have increased privacy involvement on security teams *IAPP/TRUSTe $1MOn average, what U.S. multinationals plan to spend on GDPR compliance *PricewaterhouseCoopers 75K Estimated number of DPOs needed worldwide to comply with the GDPR *IAPP $354 What companies spend on privacy globally per employee *TRUSTe
  • 8. 8 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 • What does your company spend on privacy including salaries? – Under 250k – 250k - 500k – 500k – 1m – 1m – 2m – Over 2m POLL QUESTION
  • 9. 9 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 Everybody else is doing it. • Apple’s stand against the FBI in San Bernardino case • Microsoft fights to keep data safe that’s stored on Irish server • Amazon pushing back on a search warrant for Echo voice data • Big Tech companies file amicus brief against Facebook gag order
  • 10. 10 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 v © TRUSTe Inc., 2017 Knowledge is power – and a business asset. Data is currency, and you should protect it as such.
  • 11. 11 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 SOME STATS: 9%Marketers that sell data or data services to customers and/or partners *Forrester £3,241The financial value U.K. individuals put on their data *Western Digital $800M Data broker Axciom’s reported revenue for 2015 *NPR $240 The dollar value U.S. consumers put on a SSN *Aricent/Frog Design
  • 12. 12 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 • Data is the new oil • Data as currency • Data driven economy • Every company is a data company • Data brokerage is a $200B industry Knowledge is power – and a business asset.
  • 13. 13 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 • How many people are working on privacy in your organization (full time + part time)? – 1 – 2 – 3 – 4 – 10 – + 10 POLL QUESTION
  • 14. 14 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 v © TRUSTe Inc., 2017 Avoid fines and sanctions. Regulators aren’t out to get the good-guys.
  • 15. 15 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 SOME STATS: 130+ Spam and spyware cases addressed by the FTC in 2016 *U.S. FTC €20M Potential fine for violating the GDPR or 4% of annual revenue *GDPR $2.5M2017 HHS HIPAA settlement amount with a wireless health services provider *U.S. HHS £350K GA recent fine levied by the U.K. ICO for a spam violation *U.K. ICO
  • 16. 16 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 Avoid fines and sanctions. • “… the mere fact that a breach occurred doesn’t mean a company broke the law … We don’t impose strict liability for a breach. We don’t expect companies to be perfect.” — Maureen Olhausen, U.S. FTC • “With our enforcement actions, we will consider what steps were taken beforehand, how cooperative the organization is and the size of the breach.” — Aileen Chia, Singapore PDPC • “If an organisation can’t demonstrate that good data protection is a cornerstone of their business policy and practices, they’re leaving themselves open to enforcement action that can damage their public reputation and possibly their bank balance. That makes data protection a boardroom issue.” — Elizabeth Denham, U.K. ICO
  • 17. 17 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 v © TRUSTe Inc., 2017 Funding. Venture Capitalists are big on privacy.
  • 18. 18 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 SOME STATS: $4MThe seed funding Privacy Labs received to give users control of internet data *TechCrunch $350M The decrease in Yahoo’s purchase price after the revelation of its data breaches *CNN $35MAmount of VC funding three online privacy companies received in 2010 *WSJ $2.7MFunding for CheckRecipient to use machine learning to prevent breaches *TRUSTe
  • 19. 19 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 Funding. • In 2015, VC firm Andreessen Horowitz hired Ted Ullyot to launch a new policy to help its portfolio companies navigate state and federal regulations when developing new data- fueled services. • “It’s definitely part of our due diligence … when we have companies that are storing customer data, like public cloud services. What are they doing with data retention and protection?” — Steve Herrod, General Catalyst • “Privacy is entering the conversation much earlier, and data privacy is very strongly tied to the overall information security. These are discussions at a very high level.” — Ursheet Parikh, Mayfield
  • 20. 20 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 v © TRUSTe Inc., 2017 Data breaches cost a lot. And they’re largely preventable. It’s become almost inevitable, so be prepared!
  • 21. 21 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 SOME STATS: 26% Likelihood of a breach of 10,000+ records in the next 24 months *Ponemon $4M Average consolidated cost of a data breach *Ponemon 36M+ Number of U.S. records compromised due to a breach in 2016 *IDT911 $450BWhat cyber crime cost the global economy in 2016 *Hiscox
  • 22. 22 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 Data Breaches. • Human error continues to be a major contributor to data breaches • Having an incident response team can reduce the cost of a breach by $16 per capita • Training employees can reduce that cost by $9 per capita • The biggest financial consequence from a breach is lost business • This is not going away
  • 23. 23 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 v © TRUSTe Inc., 2017 Questions?
  • 24. 24 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 v © TRUSTe Inc., 2017 Emily Leach emily@iapp.org Paul Iagnocco piagnocco@truste.com Laurel Strand lstrand@truste.com Eleanor Treharne-Jones eleanor@truste.com Contacts
  • 25. 25 vPrivacy Insight Series - truste.com/insightseries © TRUSTe Inc., 2017 v © TRUSTe Inc., 2017 Register now for the next webinar in our 2017 Winter/Spring Webinar Series on May 23 “GDPR: DPIA & Data Breach Requirements – Assessing Individual Harm” See http://www.truste.com/insightseries for the 2017 Privacy Insight Series and past webinar recordings. Thank You!