1. 程式人生 > >Tips for Success: GDPR Lessons Learned

Tips for Success: GDPR Lessons Learned

Security is our top priority at AWS, and from the beginning we have built security into the fabric of our services. With the introduction of GDPR (which becomes enforceable on May 25 of 2018), privacy and data protection have become even more ingrained into our security-centered culture. Three weeks ago, well ahead of the deadline, , meaning you can use AWS as a data processor as a way to help solve your GDPR challenges (be sure to visit our  for additional information).

When it comes to GDPR compliance, many customers are progressing nicely and much of the initial trepidation is gone. In my interactions with customers on this topic, a few themes have emerged as universal:

  • GDPR is important. You need to have a plan in place if you process personal data of EU data subjects, not only because it’s good governance, but because GDPR does carry significant penalties for non-compliance.
  • Solving this can be complex, potentially involving a lot of personnel and multiple tools. Your GDPR process will also likely span across disciplines – impacting people, processes, and technology.
  • Each customer is unique, and there are many methodologies around assessing your compliance with GDPR. It’s important to be aware of your own individual business attributes.

I thought it might be helpful to share some of our own lessons learned. In our experience in solving the GDPR challenge, the following were keys to our success:

  1. Get your senior leadership involved. We have a regular cadence of detailed status conversations about GDPR with our CEO, Andy Jassy. GDPR is high stakes, and the AWS leadership team knows it. If GDPR doesn’t have the attention it needs with the visibility of top management today, it’s time to escalate.
  2. Centralize the GDPR efforts. Driving all work streams centrally is key. This may sound obvious, but managing this in a distributed manner may result in duplicative effort and/or team members moving in a different direction.
  3. The most important single partner in solving GDPR is your legal team. Having non-legal people make assumptions about how to interpret GDPR for your unique environment is both risky and a potential waste of time and resources. You want to avoid analysis paralysis by getting proper legal advice, collaborating on a direction, and then moving forward with the proper urgency.
  4. Collaborate closely with tech leadership. The “process” people in your organization, the ones who already know how to approach governance problems, are typically comfortable jumping right in to GDPR. But technical teams, including data owners, have set up their software for to serve a specific business application. They may not even know what kind of data they are storing, processing, or transferring to other parts of the business. In the GDPR exercise they need to be aware of (or at least help facilitate) the tracking of data and data elements between systems. This isn’t a typical ask for technical teams, so be prepared to educate and to fully understand data flow.
  5. Don’t live by the established checklists. There are multiple methodologies to solving the compliance challenges of GDPR. At AWS, we ended up establishing core requirements, mapped out by data controller and data processor functions and then, in partnership with legal, decided upon a group of projects based on our known current state. Be careful about using a set methodology, tool or questionnaire to govern your efforts. These generic assessments can help educate, but letting them drive or limit your work could lead to missing something that is key to your own compliance. In this sense, a generic, “one size fits all” solution might not be helpful.
  6. Don’t be afraid to challenge prior orthodoxy. Many times we changed course based on new information. You shouldn’t be afraid to scrap an effort if you determine it’s not working. You should also not be afraid to escalate issues to senior leadership when needed. This is an executive issue.
  7. Look for ways to leverage your work beyond this compliance activity. GDPR requires serious effort, but are the results limited to GDPR compliance? Certainly not. You can use GDPR workflows as a way to ensure better governance moving forward. Privacy and security will require work for the foreseeable future, so make your governance program scalable and usable for other purposes.

One last tip that has made all the difference: think about protecting data subjects and work backwards from there. Customer focus drives us to ask, “what would customers and data subjects want and expect us to do?” Taking GDPR from a pure legal or compliance standpoint may be technically sufficient, but we believe the objectives of security and personal data protection require a more comprehensive view, and you can most effectively shape that view by starting with the individuals GDPR was meant to protect.

If you would like to find out more about our experiences, as well as how we can help you in your efforts, please reach out to us today.

-Chad Woolf

Vice President, AWS Security Assurance

Interested in additional AWS Security news? Follow the AWS Security Blog on Twitter.

相關推薦

Tips for Success: GDPR Lessons Learned

Security is our top priority at AWS, and from the beginning we have built security into the fabric of our services. With the introduction of GDPR

Tips for Shell

generate print over rate cat type perf const -m Tips for Shell There will be some case-based tips for Shell. 1. Replace the sequence sp

10 Tips for Writing Better Code (閱讀理解)

存在 int 範圍 ide ready 有一個 不清晰 and app 出發點 http://www.tuicool.com/articles/A7VrE33 閱讀中文版本《編寫質優代碼的十個技巧》,對於我編碼十年的經驗,也有相同感受, 太多的坑趟過,太多的經歷走過,

Lessons learned: Surviving in the cryptocurrency market(經驗教訓:如何在加密貨幣市場中生存)

經驗教訓:如何在加密貨幣市場中生存。 Lessons learned: Surviving in the cryptocurrency market. 原文作者:Sajwal 原文地址:https://hackernoon.com/lessons-learned-surviving-

Netsuite : 非盈利公司的實施案例------Dress forSuccess

Dress for Success® Singapore不是一家以牟利為目的的公司,業績平平。Image Mission Ltd卻想好好經營這家公司,達到這家公司的意義和目的。 Image Mission Ltd部署NetSuite來轉變業務營運,讓該機構能夠

Necessary Tips for Fiber Optic Cable Installation

FTTH, the concept that has been hotly debated by people in recent years, drives the demand for fiber optic cables and its related products. However,&n

Lessons Learned in Software Development

Here is my list of heuristics and rules of thumb for software development that I have found useful over the years: Development 1. Start small, then

7 Practical Tips for Cheating at Design

When you need to create separation between two elements, try to resist immediately reaching for a border.While borders are a great way to distinguish two e

Lessons learned on writing web applications completely in Rust

Lessons learned on writing web applications completely in RustThis blog post is an update to the preceeding article “A web application completely written i

Long-term React & Redux SPA — Lessons learned

Long-term React & Redux SPA — Lessons learnedIn the last couple of years I was involved in several React & Redux projects. During this challenging

Searching for Success? Elastic Found It

Searching for Success? Elastic Found ItLast Friday, Elastic, which commercializes open-source search and log management software, went public. Elastic clos

Ask HN: Tips for First Developer at company

So technically I am a junior developer at my company but I am the first one so I am deciding a lot of the architecture of the platform. They contracted alo

Top skills for Alexa: 6 tips for your Amazon Echo that will simplify your life

Here are 21 commands that even seasoned Echo users may not know. Many of them are useful, some are fun, and others give the illusion that Alexa is as cogni

šŸ’„ Training Neural Nets on Larger Batches: Practical Tips for 1

During step 4 of the Forward pass (top-right), the results of all the parallel computations are gathered on GPU-1. This is fine for a lot of classification

Lessons Learned Squatting ENS Domains

Enter ENS NiftyThus was born a new and free service called ENS Nifty. Similar to how Wrapped Ether (W-ETH) provides Ether with all of the benefits of an ER

Tips for Breaking Into User Research

Tips for Breaking Into User ResearchStill in school? Want to change course? Microsoft leaders offer their advice for beginning a career in user research.My

Best Tips for Speeding up your Android Phone

Best Tips for Speeding up your Android PhoneThe age of large-scale application environments where the choice of application for mobile devices is huge, sti

Top 7 Node.js/TypeScript Tips for scalable back end development

1) Start with `strict: true` from the get-go. Looseness should be the exception, strong null checking is one of the great TS value.2) Be function first, OO

Bleeping Aliens and Boom Ops: Lessons learned producing my first course

If it generates vibrations, your mic will pick it up.For me, I discovered that the ideal time to record was before dawn — There was little to no street tra

Ask HN: Tips for a prospective Ph.D student

I am a 25 year old guy who is going to be a PhD student in Europe. I have a bachelors in a pure engineering field (Ciivil), masters in operations Research