Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Transition to GDPR compliance

Transition to GDPR compliance

Talk for the Salford Centre for Professional Development GDPR conference. Focus on compliance culture and the opportunity the new General Data Protection Regulation offers to change that culture for one focused on users, engaging all staff and embedding strong feedback loops.

Blog post version at https://jystewart.net/2017/05/30/transition-beyond-gdpr-compliance/

jystewart

May 30, 2017
Tweet

More Decks by jystewart

Other Decks in Business

Transcript

  1. “we will bring forward a new data protection law, fit

    for our new data age, to ensure the very best standards for the safe, flexible and dynamic use of data and enshrining our global leadership in the ethical and proportionate regulation of data” Conservative and Unionist Party Manifesto 2017
  2. GDS

  3. @jystewart 1. Understand user needs 2. Do ongoing user research

    3. Have a multidisciplinary team 4. Use agile methods 5. Iterate and improve frequently 6. Evaluate tools and systems 7. Understand security and privacy issues 8. Make all new source code open 9. Use open standards and common platforms 10. Test the end-to-end service 11. Make a plan for being offline 12. Make sure users succeed first time 13. Make the user experience consistent with GOV.UK 14. Encourage everyone to use the digital service 15. Collect performance data 16. Identify performance indicators 17. Report performance data on the Performance Platform 18. Test with the minister https://www.gov.uk/service-manual/service-standard
  4. @jystewart The right… 1. To be informed 2. Of access

    3. To rectification 4. To erasure 5. To restrict processing 6. To data portability 7. To object 8. In relation to automated decision making and profiling. The principle of: 1. Lawfulness, fairness and transparency 2. Purpose limitation 3. Data minimisation 4. Accuracy 5. Storage limitation 6. Integrity and confidentiality 7. Accountability
  5. We need to engage with this as a design challenge

    https://newdigitalrights.projectsbyif.com/
  6. @jystewart This is an opportunity to build better cultures, focused

    on users, with strong feedback loops; to make our organisations more resilient
  7. @jystewart This is an opportunity to build better cultures, focused

    on users, with strong feedback loops; to make our organisations more resilient, and to win our users’ trust and loyalty
  8. @jystewart Too many organisations don't know what we have. We

    hoard data and we don’t build a culture of stewardship.
  9. @jystewart “If security doesn't work for people, it doesn't work”

    - Emma W from NCSC https://www.ncsc.gov.uk/blog-post/cyberuk-2017-people-strongest- link
  10. @jystewart "the controller and the processor shall implement appropriate technical

    and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate: a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.” - GDPR 32.1d