Tag: data privacy

  • The Nightmare Letter

    I’m not sure if this imaginary GDPR letter is a nightmare, but I do know that in most of the organizations where I’ve worked, this type of request would result in a crash project for me. I’d be working long hours, contacting lots of people and trying to manage a complex spreadsheet of information about an individual. I’d like to think that I’d compile this information in a general sense to understand our data better and anticipate future requests, building a process that I could repeat, but I know that under pressure that might not always happen. I’m sure I’d grab some data without capturing and saving the metadata or query. I’d probably have to perform duplicate work when the next request came in.

    GDPR enforcement begins in a couple months, and organizations receiving this type of letter will have 30 days to respond. Companies can also charge a reasonable fee based on administrative costs for information requested. The fee that’s reasonable for getting a few of these letters a month might not be sufficient if hundreds or thousands of individuals start requesting this information, and I’m sure companies and authorities will be arguing about the rates.

    With the focus on privacy in the media, and the mishandling of data regularly by companies, I wouldn’t be surprised if there are going to be large numbers of requests by individuals. In fact, I’m wouldn’t be surprised if there are scripts or applications being built now to facilitate the ability for lots of individuals to ask for this information from companies about their data processing.

    Really all of this information should be documented and any decisions made about securing sensitive data should always be followed. Any organization should know how they handle data, where it’s stored, and how it’s secured. This is just practical and good administrative practice. The items about how data is processed and used are good business knowledge points. After all, should we be processing data without some justification for the resources involved? I think too often a company decides to implement some process without evaluating if it makes sense in the context of their mission. If it does, we should know why it does and be able to measure that. If it doesn’t, we ought to stop.

    If you do business in the EU or with EU citizens, you might wish to start ensuring you have a way to export the information requested in this letter. Being prepared for some of these items might make it much easier to respond to any or all of these requests.

    Whether you think this might happen to your organization or not, you might want to just save a copy of this letter. I know I will, with the idea that I might send this off to companies that store my data. Knowledge can help me protect myself by being aware of what’s being done with information related to me. If there are issues, having this information might help ensure my rights are protected. I’ll also be sure that I have a form letter to ask for removal of information. I’ve felt this wasn’t possible in the past, but at least in the EU, where I regularly travel, I can exert some control over my data.

    Steve Jones

    The Voice of the DBA Podcast

    Listen to the MP3 Audio ( 3.9MB) podcast or subscribe to the feed at iTunes and Libsyn.

  • The GDPR Sky is Falling

    David Poole wrote a nice summary of the GDPR regulations that come into force this spring in Europe. He covers a number of the sections, trying to provide a simple explanation of the potential issues from the perspective of a data engineer. That’s likely the role most of us fill , and I think David does a good job of trying to note the items that he (and maybe you) need to be concerned about.

    If you want to read the full text, and you should, it’s here. To me, this is a more sensible, easier to understand type of regulation. It’s way better than SOX and most other regulations I’ve had to deal with, with a better view of balancing the idea that companies won’t have all the answers, and might not choose the best technology but do need to make an effort. I don’t think this will excuse just continuing to do business as you have, but it does read as though courts and authorities will have flexibility in their interpretation.

    One of the main things that should be pointed out is that the 10 million Euro fine is a max, not a minimum. The same things goes for the potential 2% of global turnover (revenue for the US folks). These are the highest potential penalties, though if you have made some effort to protect data and comply, I doubt you’d see fines at this level unless you’re negligent.

    The keys parts of this regulation are that companies should be paying more than lip service to data privacy and protection. They should be designing and building software and infrastructure that protects data, and also considers the point of view of the individual or organization that is the subject of the data. That’s a good move, in my opinion, having us actually think about the data and the ramifications of its use, sale, transfer, and release, rather than just focusing on our own goals. Most data professionals I know keep this in mind, so GDPR is a step in the right direction to push management to care.

    We’ve got information at the Redgate site, which will help guide you. We are building features into existing and new products, and we’d love to sell you software if you can use it, but we’re also learning and trying to share what we know. This goes along with the core values at Redgate of being a part of the community and giving back, through SQLServerCentral, Simple Talk, blogs, and more.

    Ultimately no one knows what GDPR will bring, and its application can present a risk to any of us that gather data from EU residents. I know Brent Ozar as already decided to stop EU business for the time being to avoid taking on this risk, and I’m sure other small companies may do the same thing. In one way that’s a shame, though a reasonable decision for a company. In another way, this opens opportunities for other businesses. People in Europe still need goods and services, and there are plenty of ways to comply with GDPR that I don’t think will be too hard, especially for those businesses based in Europe that won’t have a choice. There will be other companies that can fill any void left by companies that cease working in the EU.

    GDPR isn’t the end of the world. I think it’s a good move in the right direction to balancing data value and protections. I’d like to see a better framework in the US that also ensures individuals have rights to exercise some control over all the data being gathered about them, as well as something that forces companies to actually consider data protection in their systems. There may be some bad results from GDPR, but most of us will adapt and continue to do business as we have in the past, albeit with better data controls.

    Steve Jones

    The Voice of the DBA Podcast

    Listen to the MP3 Audio ( 5.4MB) podcast or subscribe to the feed at iTunes and Libsyn.

  • A Data ID

    It sounds good. A universal ID that can be used for your identifiable data, in case you happen to lose your paperwork. Paperwork? When will that term become lost to history? These days, less and less of anything is available as a physical media, and if it is, it’s often because someone generates a copy from a printer. How secure or valid is that? After all, with Photoshop and other tools, we can reproduce almost anything that’s indistinguishable from the original.

    The UN wants a universal ID for humanitarian reasons. In case you can’t get your personal documents because you’re a refugees. They’re lost, they’re stolen, or just still in the desk drawer because you had to flee your residence. Digital representations of these papers might be the only way for many people to prove anything about their lives. Certainly a concern in today’s world.

    As we should know by now, anything that can be built in the digital world can be stolen. In fact, I’m fairly convinced that the vast majority of people that come up with good ideas don’t know how to evaluate them in terms of the horrible ways that others will abuse the system. Creators are optimistic and look to solve problems. They’re not nearly devious enough to think of the various permutations that a hacker mind might envision.

    A universal way to track and verify identity information would be great. I already worry about losing track of digital assets, and some way to query a number of systems to verify I own them would be great. However, the security aspects worry me. Even having governments or the UN provide digital lockers that entail backups of records is problematic. Any centralized system can be abused, and certainly this data would be abused. Or leaked. We see data breaches from government all the time. Can you imagine losing control of passport verification at a large scale?

    Each individual needs to come up with their own backup of precious documents, in a way that ensures they are encrypted and protected. However, we do need ways to authenticate and verify these digital assets. Maybe free signing certificates should be used when assets are provided to individuals, with public keys being disclosed by the government and escrowed by the UN, or maybe every other government. We ought to be able to verify a digital document in an open, transparent way, while leaving the storage to the individual. That would allow us to develop ways to protect our own assets, but ensure multiple entities can verify authenticity.

    Steve Jones

    The Voice of the DBA Podcast

    Listen to the MP3 Audio ( 3.7MB) podcast or subscribe to the feed at iTunes and Libsyn.