Tag: GDPR

  • Webinar: 6 Principles of the GDPR and SQL Provision

    On April 24, I’ll be hosting a webinar that talks about the GDPR and how you can help ensure compliance in your development environments. I’ll talk about some of the issues and show how SQL Provision can help.

    6-principals-of-gdpr-webinar

    The GDPR is complex, but it certainly does ask us to protect and prevent issues with data from development environments. There are many ways you can try and ensure you don’t have any issues, and I’ll show one with Redgate tools.

    Register today and I look forward to talking with you next week.

  • The Nightmare Letter

    I’m not sure if this imaginary GDPR letter is a nightmare, but I do know that in most of the organizations where I’ve worked, this type of request would result in a crash project for me. I’d be working long hours, contacting lots of people and trying to manage a complex spreadsheet of information about an individual. I’d like to think that I’d compile this information in a general sense to understand our data better and anticipate future requests, building a process that I could repeat, but I know that under pressure that might not always happen. I’m sure I’d grab some data without capturing and saving the metadata or query. I’d probably have to perform duplicate work when the next request came in.

    GDPR enforcement begins in a couple months, and organizations receiving this type of letter will have 30 days to respond. Companies can also charge a reasonable fee based on administrative costs for information requested. The fee that’s reasonable for getting a few of these letters a month might not be sufficient if hundreds or thousands of individuals start requesting this information, and I’m sure companies and authorities will be arguing about the rates.

    With the focus on privacy in the media, and the mishandling of data regularly by companies, I wouldn’t be surprised if there are going to be large numbers of requests by individuals. In fact, I’m wouldn’t be surprised if there are scripts or applications being built now to facilitate the ability for lots of individuals to ask for this information from companies about their data processing.

    Really all of this information should be documented and any decisions made about securing sensitive data should always be followed. Any organization should know how they handle data, where it’s stored, and how it’s secured. This is just practical and good administrative practice. The items about how data is processed and used are good business knowledge points. After all, should we be processing data without some justification for the resources involved? I think too often a company decides to implement some process without evaluating if it makes sense in the context of their mission. If it does, we should know why it does and be able to measure that. If it doesn’t, we ought to stop.

    If you do business in the EU or with EU citizens, you might wish to start ensuring you have a way to export the information requested in this letter. Being prepared for some of these items might make it much easier to respond to any or all of these requests.

    Whether you think this might happen to your organization or not, you might want to just save a copy of this letter. I know I will, with the idea that I might send this off to companies that store my data. Knowledge can help me protect myself by being aware of what’s being done with information related to me. If there are issues, having this information might help ensure my rights are protected. I’ll also be sure that I have a form letter to ask for removal of information. I’ve felt this wasn’t possible in the past, but at least in the EU, where I regularly travel, I can exert some control over my data.

    Steve Jones

    The Voice of the DBA Podcast

    Listen to the MP3 Audio ( 3.9MB) podcast or subscribe to the feed at iTunes and Libsyn.

  • If only the US would follow …

    I saw this blog from Allan Hirt and I wish the US would adopt something strong like this. I’d actually like this to apply to all organizations, but certainly critical services need to be secure. If you follow the link, you’ll see that the UK government has warned their critical industries that if they do not have effective measures or safeguards against cyber attacks, they can be fined up to £17 million. That might not seem like a lot in some industries, but it should get some attention from executives. I’m not sure how many CxOs would keep their jobs if they incur that level of fine because they didn’t implement strong security measures.

    For now the requirements apply to the energy, transport, water, and health industries. These are deemed essential by the UK government. The UK government is expecting that along with data privacy changes to ensure GDPR compliance, that these industries need to implement better cyber security to prevent or limit attacks. This is part of guidance from the European Parliment, and it’s overdue. I just wish the US were as focused on pushing organizations to adopt security as a priority rather than an afterthought.

    Not that I want government to dictate specifics, but I do think that having a government authority that can stay up to date and evolve their view of what constitutes good security is a good idea. This could be similar to some sort of review and feedback situation that we have for auditing. Ultimately, I’d like there to be some group that can weigh in on good security practices for platforms and systems, probably with research and industry feedback, on what constitutes valid patch levels for systems and software. It would be valuable to know that your version of Windows or Debian or PHP or the database platform is insecure. Not that I want to create more of an upgrade treadmill, but using software means patching it.

    Perhaps this would drive more organizations to move to open source software, or perhaps more vendors to issue patches rapidly and lower their prices to compete. Maybe more importantly, it would press vendors of third party software to ensure they continue to develop security patches, perhaps even spelling out support lengths in contracts. The pressure to perform better would be useful in raising quality in the security area. One thing to note is that the intent isn’t to fine companies, but ask them to make valid risk assessments and take appropriate measures (with input from regulators).

    For now, I’d say that most UK organizations ought to start taking security more seriously. Making changes in platforms to prevent attacks and limit downtime will require some planning and foresight. You might not be in an industry affected today, but in two or three years that could change.

    Steve Jones

    The Voice of the DBA Podcast

    Listen to the MP3 Audio ( 3.9MB) podcast or subscribe to the feed at iTunes and Libsyn.

  • The SQL Privacy Summit

    This May 18th, Redgate is putting on a SQL Privacy Summit for people that are looking for solutions to help them comply with the GDPR regulations.  I’ll be heading over to participate, and I’m looking forward to hearing from customers and attendees about the challenges they’re facing.

    sps

    The Details

    Friday May 18th 2018

    The Grange Tower Bridge Hotel, 45 Prescot Street, London E1 8GP

    8:15am – 5:30pm (GMT – convert)

    The schedule is out and I’ll be doing a variation of a talk I’ve delivered before on how the GDPR is really asking for solid data practices that we’d all like to implement. There are some panel sessions and lots of networking time built in.

    Registration

    This is an all day conference, though early bird rates continue through this week. You can purchase a ticket for the event from the event announcement. If you’re a customer, contact sales, and you may be able to get a set of discounted tickets.

    Hopefully I’ll see you there and we’ll get the chance to talk about how we can all do a better job securing and protecting our sensitive data.