Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014...

42
1 May 12, 2015 Embedding Privacy by Design Metric Stream Customer Conference TRUSTe Data Privacy Management Solutions

Transcript of Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014...

Page 1: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

1

May 12, 2015

Embedding Privacy by Design

Metric Stream Customer Conference

TRUSTe Data Privacy Management Solutions

Page 2: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

2

Today’s Agenda

• Privacy in the Context of GRC

• Data Privacy Management and Top Privacy

Priorities

• TRUSTe Assessments Benchmark Data

• Key DPM Use Cases

– Global Data Transfer Management

– Global Data Transfer Interoperability

– Integrating Privacy Into Product Lifecycle

– Data Discovery and Mapping

Page 3: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

3

Privacy in the Context of GRC

Page 4: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

4

http://www.oceg.org/resources/illustration-privacy-risk-management-compliance-2015/

Page 5: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

5

Page 6: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

6

Page 7: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

7

Page 8: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

8

Page 9: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

9

Privacy Management

Functions

Page 10: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

10

Audit Data Management

Practices

Build Policy and Compliance

Requirements

Conduct

Compliance

Reviews

Identify

Gaps / Risks

Implement

Program

Changes

Ongoing Monitoring

Enable

Controls

Privacy Compliance

Marketing Product

Data Privacy Management Process

Page 11: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

12

Privacy Program Evolution

Page 12: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

13

Privacy Program Evolution

Page 13: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

14

Privacy Program Evolution

Page 14: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

15

Privacy Assessment

Benchmarking Study

Page 15: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

16

• Online survey conducted December

9 - 15, 2014

• External sample used (not TRUSTe

database)

• Participants blind to TRUSTe being

the survey sponsor

• External consultant used to

administer and analyze

• 203 respondents from large

organizations (>1,000 employees)

Survey Background Respondent Background

• Participants screened to ensure part

of company’s privacy function

• Companies ranging in size from

1,000 to 75,000+ (approximately

equal distribution)

• US multi-nationals, across wide range

of industries

Privacy Assessment Study Overview

Page 16: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

17

What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external resources, and external software and tools?

Under $100K 3%

$100K - $250K

9%

$250 - $500K 13%

$500K - $1M 18%

$1M - $5M 21%

Over $5M 15%

$0 4%

Do not know 17%

n=203

Nearly Half (45%) of Privacy Budgets over $1M Annually

Average = $3.3M

Median = $1.0M

Company Size is a Key Driver

• 1K to 5K Employees, Ave =

$1.8M

• Over 75K Employees, Ave =

$3.3M

Mature companies 2.5x more

likely to have > $1M budget

Calculations exclude “Do Not Know”

Page 17: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

18

How many individuals are involved in your organization's privacy initiatives as their primary responsibility over the course of this year (internal employees and external contractors)?

0 3%

1 4%

2 to 5 19%

6 to 20 31%

21 to 50 24%

51 or more 19%

n=203

Wide Range of Privacy Team Sizes

Average = 28 people

Median = 18 people

Company Size is a Key Driver

• 1K to 5K Employees, Ave = 18

• Over 75K Employees, Ave = 50

Page 18: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

19

How would you rate the maturity of your company's privacy program?

2%

6%

33%

45%

14%

0%

5%

10%

15%

20%

25%

30%

35%

40%

45%

50%

1 (VeryImmature)

2 3 4 5 (Very Mature)

n=203

Company Privacy Maturity

Page 19: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

20

What are your organization’s 3 highest priority privacy projects for 2015?

77

75

53

53

51

48

42

35

31

27

25

19

5

9

0 10 20 30 40 50 60 70 80 90 100

Internal privacy audit and assurance

Internal Privacy training

Regulatory compliance for cross-border data transfers

Vendor Risk Management

Document and maintain data inventories / flows

Managing an HR data privacy program

Develop and manage a comprehensive PIA process

Developing a program for vendor risk management

Centralizing global privacy policies

Third-party Privacy certifications

Compliance with self-regulatory ad frameworks

Compliance with EU Cookie Directive

Compliance with CASL

Othern=203

Assessment Practices

Page 20: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

21

47 65

52

111

50 30

-

20

40

60

80

100

120

Technology Finance /Insurance

Biotech/Pharma/Health

Manufacturing Retail / CPG Other

Privacy Impact Assessment (PIA) Volume Analysis

• Company Average = 59 per year

• Median = 12 per year

• Privacy Maturity Key Driver of Volume – Very Mature = 2x Average

• Company Size Not a Key Driver of Volume

Page 21: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

22

Assessment Benchmarking Summary

1. Conducting Privacy Assessments top priority for many companies

2. Average company conducts 59 PIAs per year

3. 1/3 across offline online and employee data

4. Assessments take a long time – 28 days, 285 hours on average

5. Managing respondents and analysis are top drivers to length

6. Assessments are labor intensive – 56 employees company-wide

7. Budget and team’s time top inhibitors to doing more assessments

8. Internal systems, email, and spreadsheets most common tools

9. Individual assessments cost $17K - $71K (length & rate)

10. Annual costs from $210K to $4.2M (volume, length, & rate)

Page 22: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

23

Key Privacy Use Cases

TRUSTe Data Privacy Management Solutions

Page 23: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

24

Company Type Use Case

Tech: Computer Integrated privacy impact assessments

into product lifecycle process

Medical Services Discovering and building business

process data flows for privacy risk

analysis

Energy and

Petroleum

Evaluating data transfers across global

enterprise

Data Privacy Management Use Cases

Page 24: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

25

Use Case:

Automating Privacy Impact Assessments

TRUSTe Data Privacy Management Solutions

Page 25: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

26

Privacy

assessment

initiated by

project owner

Respondent

answers PIA

System

analysis of

input

Issues

found?

Auto

approval

No

Privacy Impact Assessment (PIA) Automation

Reviewer

Resolve issues

and approve

report

Detailed

PIA

needed?

No

Preliminary

Risk Triggers

Analyzed

Yes

Yes

Page 26: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

27

Privacy Threshold Assessment

Page 27: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

28

Auto approval if no issues

System

approved

assessments

are available if

needed

Answers to preliminary

questions may result in

platform approval – no

need for privacy review

Page 28: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

29

Presence of Risks Triggers Deeper PIA

Answers to preliminary questions may result in user being presented a more detailed

PIA review

Page 29: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

30

Privacy Impact Assessment (PIA)

Page 30: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

31

Privacy Analyst Risk Administration

Page 31: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

32

Use Case:

Data Flow Analysis

TRUSTe Data Privacy Management Solutions

Page 32: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

33

• Describe business processes for full data lifecycle

– Source (collection)

– Intermediaries (hosting and processing)

– Destinations (data transfers, vendors)

• Describe a policy for risk analysis

– Global data transfer

– Data sensitivity (PII)

– Data protection strategy (security)

Objectives

Page 33: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

34

Data Flow Management

Page 34: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

35

Data Flow Policy Analysis

Page 35: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

36

Aggregate Analysis

Page 36: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

37

Use Case:

Evaluating Global Data Transfers

TRUSTe Data Privacy Management Solutions

Page 37: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

38

• Large global energy company

• Located in 80 countries

• 1,000 project managers requesting 5,000 data transfer

requests per year

• Goals:

– Use system to automate decision and remove ‘routine use cases’

– Inform users of when requested data is high risk

– Operationalize legal data transfer layers

– Involve privacy analyst on high risk areas for manual intervention

Data Transfer Management

Page 38: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

39

Data Transfer Analysis

Page 39: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

40

Data Transfer Analysis

Shows policy

violation when

data element

is selected

Highlights

where

proper

agreements

do not exist

Page 40: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

41

Thank You

Page 41: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

42

Assessments • EU Safe Harbor

• Privacy Impact Assessments

• Custom Engagements

Certifications • Apps, Cloud, Websites

• APEC, COPPA, EDAA

DPM Platform DPM Services

TRUSTe Data Privacy Management (DPM) Solutions

Extensive Expertise - Proven Methodology - Leading Technology

Page 42: Embedding Privacy by Design - MetricStream GRC Summit 2018 · 17 What is the approximate total 2014 privacy budget for your company, including employee salary / benefits, external

43

Enterprise Privacy Automation Privacy Assessments, Compliance Controls, and Monitoring Tools

Proven SaaS Technology

Self Service & Managed Service Options

DAA / EDAA OBA Compliance

EU Cookie Directive Compliance Website Analysis

Safe Harbor Dispute

Handling

Compliance Reviews, Gap Analysis,

Change Management

TRUSTe Data Privacy Management Platform

Data Flow Mapping

Mobile App

Analysis