1
00:00:06,570 --> 00:00:08,670
- In lesson 26.2

2
00:00:08,670 --> 00:00:11,100
we're gonna be talking
about privacy principles

3
00:00:11,100 --> 00:00:14,043
and compliance with privacy regulations.

4
00:00:14,970 --> 00:00:16,950
Now, privacy is the right of an individual

5
00:00:16,950 --> 00:00:20,640
to control the use of
their personal information.

6
00:00:20,640 --> 00:00:24,570
And we talked about this way
back in our early, early lesson

7
00:00:24,570 --> 00:00:26,190
where I said it's really important

8
00:00:26,190 --> 00:00:28,710
that every cybersecurity practitioner

9
00:00:28,710 --> 00:00:31,080
has a good understanding of privacy

10
00:00:31,080 --> 00:00:33,240
and doesn't think about privacy issues

11
00:00:33,240 --> 00:00:35,370
as somebody else's responsibility.

12
00:00:35,370 --> 00:00:36,930
Right, it's our responsibility.

13
00:00:36,930 --> 00:00:38,520
When we think about confidentiality,

14
00:00:38,520 --> 00:00:42,360
integrity and availability
as the fundamental principles

15
00:00:42,360 --> 00:00:44,280
of information or cybersecurity,

16
00:00:44,280 --> 00:00:46,650
I always want you to tack on privacy.

17
00:00:46,650 --> 00:00:47,883
It's that important.

18
00:00:49,170 --> 00:00:52,140
Now, individuals expect
their privacy to be respected

19
00:00:52,140 --> 00:00:54,060
and their personal
information to be protected

20
00:00:54,060 --> 00:00:56,553
by the organizations which
they do business with.

21
00:00:58,080 --> 00:01:00,540
Now, a strategy that's
really good to adopt

22
00:01:00,540 --> 00:01:02,670
is known as data minimization.

23
00:01:02,670 --> 00:01:06,360
Data minimization approach
limits our data collection

24
00:01:06,360 --> 00:01:10,140
to only what's required to
fulfill a specific purpose.

25
00:01:10,140 --> 00:01:13,350
If we don't need something,
don't collect it.

26
00:01:13,350 --> 00:01:14,670
It's that simple, right?

27
00:01:14,670 --> 00:01:15,570
Then we don't have to think

28
00:01:15,570 --> 00:01:18,390
about how we're going to protect it.

29
00:01:18,390 --> 00:01:20,880
The consequences of privacy breaches

30
00:01:20,880 --> 00:01:24,780
include reputational damage,
loss of stakeholder trust,

31
00:01:24,780 --> 00:01:27,000
fines, could be extraordinary fines,

32
00:01:27,000 --> 00:01:29,220
we've seen some really big fines

33
00:01:29,220 --> 00:01:32,553
coming out of the European
Union, and litigation.

34
00:01:34,950 --> 00:01:37,260
So way early on a number of lessons ago

35
00:01:37,260 --> 00:01:39,600
we talked about the
OECD privacy principles,

36
00:01:39,600 --> 00:01:41,640
and I wanna go through
them as a refresher.

37
00:01:41,640 --> 00:01:44,220
Remember, there are eight
OECD privacy principles,

38
00:01:44,220 --> 00:01:46,260
let's just look at the first five.

39
00:01:46,260 --> 00:01:50,490
Collection limitation, data
quality, purpose specification,

40
00:01:50,490 --> 00:01:53,970
use limitation, and security safeguard.

41
00:01:53,970 --> 00:01:56,550
The collection limitation
privacy principle

42
00:01:56,550 --> 00:01:58,440
is that collection of personal data

43
00:01:58,440 --> 00:02:01,020
should be obtained by
lawful and fair means,

44
00:02:01,020 --> 00:02:04,350
and were appropriate with the
knowledge and with the consent

45
00:02:04,350 --> 00:02:06,300
of the data subject.

46
00:02:06,300 --> 00:02:09,270
Data quality is that personal
data should be relevant

47
00:02:09,270 --> 00:02:12,870
for the purpose collected and
should be accurate, complete,

48
00:02:12,870 --> 00:02:16,140
and we have a responsibility
to keep it up to date.

49
00:02:16,140 --> 00:02:17,880
Purpose specification is the purpose

50
00:02:17,880 --> 00:02:21,300
for which personal data is
collected should be specified

51
00:02:21,300 --> 00:02:23,387
no later than at the
time of data collection.

52
00:02:23,387 --> 00:02:25,230
Again, we don't just get to collect stuff

53
00:02:25,230 --> 00:02:27,513
'cause we think it might
be useful later on.

54
00:02:28,500 --> 00:02:30,450
Use limitation is that the personal data

55
00:02:30,450 --> 00:02:32,700
should not be disclosed, made available,

56
00:02:32,700 --> 00:02:36,990
or otherwise used for purposes
other than what was specified

57
00:02:36,990 --> 00:02:40,050
except with the consent
of the data subject

58
00:02:40,050 --> 00:02:42,120
or by the authority of law.

59
00:02:42,120 --> 00:02:44,730
And then number five is
the security safeguard

60
00:02:44,730 --> 00:02:47,160
which is that personal
data should be protected

61
00:02:47,160 --> 00:02:49,560
by reasonable security safeguards.

62
00:02:49,560 --> 00:02:51,690
And here we're talking
about confidentiality,

63
00:02:51,690 --> 00:02:54,363
integrity and availability.

64
00:02:55,950 --> 00:02:57,660
So an interesting component

65
00:02:57,660 --> 00:03:01,200
of both current and some
emerging privacy regulations

66
00:03:01,200 --> 00:03:03,450
is the right to be forgotten.

67
00:03:03,450 --> 00:03:04,680
Now, the right to be forgotten

68
00:03:04,680 --> 00:03:06,900
pertains to an individual's right

69
00:03:06,900 --> 00:03:09,270
to have their personal information removed

70
00:03:09,270 --> 00:03:11,970
or deleted from online platforms,

71
00:03:11,970 --> 00:03:16,143
search engine results, or other
publicly accessible sources.

72
00:03:17,280 --> 00:03:20,610
Now, the right to be forgotten
is not an absolute right,

73
00:03:20,610 --> 00:03:23,370
and it really needs to be
balanced against other rights

74
00:03:23,370 --> 00:03:25,290
such as freedom of expression,

75
00:03:25,290 --> 00:03:28,680
public interest, and or legal obligations.

76
00:03:28,680 --> 00:03:30,870
So the scope and the interpretation

77
00:03:30,870 --> 00:03:32,760
of the right to be forgotten

78
00:03:32,760 --> 00:03:37,203
really does vary across
jurisdictions and legal frameworks.

79
00:03:41,010 --> 00:03:45,510
Now, there are numerous
privacy specific regulations

80
00:03:45,510 --> 00:03:47,460
in the European Union, in Canada,

81
00:03:47,460 --> 00:03:50,283
in Mexico, in Brazil, in Japan.

82
00:03:51,510 --> 00:03:55,410
Sort of the foundational
regulation, right?

83
00:03:55,410 --> 00:03:57,750
The one that really started it all

84
00:03:57,750 --> 00:04:01,050
and one that so many other
regulations are modeled after

85
00:04:01,050 --> 00:04:02,941
is GDPR.

86
00:04:02,941 --> 00:04:05,280
And we're gonna talk
about GDPR in just a sec.

87
00:04:05,280 --> 00:04:07,200
And then here in the US,

88
00:04:07,200 --> 00:04:12,060
we don't have any one
overarching privacy regulation,

89
00:04:12,060 --> 00:04:14,520
but California was first out

90
00:04:14,520 --> 00:04:16,860
with a state level privacy regulation.

91
00:04:16,860 --> 00:04:20,490
So I wanna review the
California regulation as well.

92
00:04:20,490 --> 00:04:22,230
Now, I know we talked about
both of these earlier,

93
00:04:22,230 --> 00:04:23,160
but they're really important

94
00:04:23,160 --> 00:04:24,960
so we're gonna talk about 'em again.

95
00:04:25,860 --> 00:04:29,010
GDPR, the General Data
Protection Regulation,

96
00:04:29,010 --> 00:04:32,070
the objective is to protect
people in the European Union

97
00:04:32,070 --> 00:04:34,950
and the European Economic Area, the EEA,

98
00:04:34,950 --> 00:04:38,700
from unlawful data
collection or processing,

99
00:04:38,700 --> 00:04:41,970
and it also works to
increase consent requirements

100
00:04:41,970 --> 00:04:44,670
and to provide enhanced user rights.

101
00:04:44,670 --> 00:04:48,513
Now, GDPR is based on those
OECD privacy principles.

102
00:04:49,740 --> 00:04:53,190
CCPA is the California
Consumer Privacy Act

103
00:04:53,190 --> 00:04:57,030
and its objective is to
protect California residents.

104
00:04:57,030 --> 00:04:59,430
Now, the CCPA draws the scope

105
00:04:59,430 --> 00:05:02,430
of personal information really broadly,

106
00:05:02,430 --> 00:05:04,200
and that's one of the
things that's so interesting

107
00:05:04,200 --> 00:05:06,960
about this particular regulation,

108
00:05:06,960 --> 00:05:07,957
where it doesn't just say,

109
00:05:07,957 --> 00:05:11,190
"Okay, we're looking at discrete personal

110
00:05:11,190 --> 00:05:13,830
or personally identifiable information

111
00:05:13,830 --> 00:05:17,730
like a social security
number or date of birth."

112
00:05:17,730 --> 00:05:19,080
But instead we're looking

113
00:05:19,080 --> 00:05:22,680
at this really broad scope
of personal information

114
00:05:22,680 --> 00:05:27,450
which could include
information that identifies,

115
00:05:27,450 --> 00:05:29,640
relates to, describes,

116
00:05:29,640 --> 00:05:32,610
or is capable of being associated with

117
00:05:32,610 --> 00:05:37,170
or could reasonably be
linked directly or indirectly

118
00:05:37,170 --> 00:05:39,900
with a particular consumer or household.

119
00:05:39,900 --> 00:05:42,570
So it just like blew up
what we think about privacy.

120
00:05:42,570 --> 00:05:45,570
It's not just these
identity theft based things,

121
00:05:45,570 --> 00:05:49,230
it's like everything almost
they could gather about you.

122
00:05:49,230 --> 00:05:51,720
But California is the
first state in the US

123
00:05:51,720 --> 00:05:53,250
to have a privacy regulation.

124
00:05:53,250 --> 00:05:55,680
There are other states that
are starting to follow suit,

125
00:05:55,680 --> 00:05:58,230
and California's really
considered a a bellwether state

126
00:05:58,230 --> 00:05:59,490
for regulations.

127
00:05:59,490 --> 00:06:00,510
They were the first state

128
00:06:00,510 --> 00:06:03,360
that had a Security
Breach Notification Act.

129
00:06:03,360 --> 00:06:06,120
And here we are, well,
a number of years later,

130
00:06:06,120 --> 00:06:08,700
and every US state and jurisdiction

131
00:06:08,700 --> 00:06:11,340
has breach notification regulation.

132
00:06:11,340 --> 00:06:13,860
Now, what's crazy about those,
and I mentioned this earlier,

133
00:06:13,860 --> 00:06:15,720
is that they all vary from each other

134
00:06:15,720 --> 00:06:16,830
and some of them conflict.

135
00:06:16,830 --> 00:06:18,810
It'd be really nice here in the US

136
00:06:18,810 --> 00:06:21,060
if we had one overarching
security regulation

137
00:06:21,060 --> 00:06:22,860
and one privacy regulation.

138
00:06:22,860 --> 00:06:24,780
But the bottom line is we don't

139
00:06:24,780 --> 00:06:26,313
so it's left to the states.

140
00:06:28,230 --> 00:06:31,320
Now, GDPR actually has some very defined

141
00:06:31,320 --> 00:06:33,600
privacy roles and responsibilities

142
00:06:33,600 --> 00:06:34,980
that I want you to be aware of,

143
00:06:34,980 --> 00:06:37,080
a data controller, a data processor

144
00:06:37,080 --> 00:06:39,540
and a data protection officer.

145
00:06:39,540 --> 00:06:42,720
A data controller determines
the purposes for which

146
00:06:42,720 --> 00:06:45,993
and the means by which personal
data is gonna be protected.

147
00:06:46,890 --> 00:06:49,380
The data processor processes personal data

148
00:06:49,380 --> 00:06:51,360
on behalf of a data controller.

149
00:06:51,360 --> 00:06:53,310
Now, it's possible that
the same organization.

150
00:06:53,310 --> 00:06:56,790
You can be both the data
controller and the data processor,

151
00:06:56,790 --> 00:06:59,370
or those two roles can be split.

152
00:06:59,370 --> 00:07:02,340
And then we have a DPO, a
data protection officer.

153
00:07:02,340 --> 00:07:05,760
And a data protection officer
ensures that an organization

154
00:07:05,760 --> 00:07:09,330
is in compliance with privacy regulations

155
00:07:09,330 --> 00:07:11,580
as defined in GDPR,

156
00:07:11,580 --> 00:07:13,653
and independence is required.

157
00:07:15,150 --> 00:07:19,140
So let's talk about some
privacy enhancing technologies.

158
00:07:19,140 --> 00:07:20,730
We talked about two of these already

159
00:07:20,730 --> 00:07:22,860
so it'll be a refresher, but two new ones.

160
00:07:22,860 --> 00:07:26,640
Data masking, tokenization, anonymization

161
00:07:26,640 --> 00:07:29,370
and pseudo anonymization.

162
00:07:29,370 --> 00:07:31,110
The data masking is a technique used

163
00:07:31,110 --> 00:07:32,460
to protect sensitive data

164
00:07:32,460 --> 00:07:35,747
by replacing it with fictional
or de-identified data.

165
00:07:35,747 --> 00:07:38,910
Right, and we talked
about this one early on

166
00:07:38,910 --> 00:07:40,560
as well as tokenization.

167
00:07:40,560 --> 00:07:42,660
Tokenization being the technique

168
00:07:42,660 --> 00:07:44,940
to secure and desensitized data

169
00:07:44,940 --> 00:07:46,920
by replacing the original data

170
00:07:46,920 --> 00:07:50,400
with an unrelated value of
the same length and format.

171
00:07:50,400 --> 00:07:52,000
That's referred to as the token.

172
00:07:53,130 --> 00:07:54,780
But here's two new ones for you,

173
00:07:54,780 --> 00:07:58,140
anonymization and pseudo anonymization.

174
00:07:58,140 --> 00:07:59,700
Anonymization is the process

175
00:07:59,700 --> 00:08:02,370
in which individually identifiable data

176
00:08:02,370 --> 00:08:05,550
is altered in such a way
that it can no longer,

177
00:08:05,550 --> 00:08:09,333
never, ever, ever be related
back to a given individual.

178
00:08:10,800 --> 00:08:13,560
And then we have pseudo anonymization.

179
00:08:13,560 --> 00:08:15,600
The pseudo anonymization is a method

180
00:08:15,600 --> 00:08:18,540
to substitute identifiable data

181
00:08:18,540 --> 00:08:21,210
but it has a reversible consistent value.

182
00:08:21,210 --> 00:08:25,602
So we could swap it back
to the original individual.

183
00:08:25,602 --> 00:08:28,383
So anonymization and pseudo anonymization.

184
00:08:30,180 --> 00:08:33,900
Organizations that are
in jurisdictions, right,

185
00:08:33,900 --> 00:08:37,110
that have privacy regulations on them

186
00:08:37,110 --> 00:08:39,810
need to have a privacy management program.

187
00:08:39,810 --> 00:08:41,520
And there are three components

188
00:08:41,520 --> 00:08:43,440
of a privacy management program.

189
00:08:43,440 --> 00:08:46,080
The privacy program itself,

190
00:08:46,080 --> 00:08:49,170
operations or operationally
how do we deal with the data,

191
00:08:49,170 --> 00:08:51,603
and then incident and breach response.

192
00:08:52,530 --> 00:08:54,630
So what are some of the
components of a privacy program?

193
00:08:54,630 --> 00:08:57,510
Well, first of all, we wanna
have executive sponsorship.

194
00:08:57,510 --> 00:09:00,030
We're going to be doing
privacy impact assessments.

195
00:09:00,030 --> 00:09:01,980
I'll show you one of those in just a sec.

196
00:09:01,980 --> 00:09:04,020
We want tools for data mapping,

197
00:09:04,020 --> 00:09:07,680
meaning we need to find out
where all of our data is

198
00:09:07,680 --> 00:09:09,330
that would be considered you know,

199
00:09:09,330 --> 00:09:13,440
that falls under a privacy regulation.

200
00:09:13,440 --> 00:09:15,570
We need to identify our compliance

201
00:09:15,570 --> 00:09:18,030
and our contractual regulations.

202
00:09:18,030 --> 00:09:21,270
We'll wanna implement privacy by design,

203
00:09:21,270 --> 00:09:24,870
which is privacy by design,
automation and checklists.

204
00:09:24,870 --> 00:09:27,603
And we'll wanna have a
published privacy statement.

205
00:09:29,070 --> 00:09:30,840
Then from an operations perspective,

206
00:09:30,840 --> 00:09:33,240
while we wanna have cookie compliance,

207
00:09:33,240 --> 00:09:35,100
now you've seen cookie compliance a lot,

208
00:09:35,100 --> 00:09:36,807
right, every time you go to a website,

209
00:09:36,807 --> 00:09:37,980
and you haven't been there before,

210
00:09:37,980 --> 00:09:40,260
it says, "How do you want
your cookies to be handled?"

211
00:09:40,260 --> 00:09:42,600
That's really our cookie compliance.

212
00:09:42,600 --> 00:09:43,950
We need consent mechanisms.

213
00:09:43,950 --> 00:09:45,780
That's part of what you're being asked

214
00:09:45,780 --> 00:09:47,370
when you go to the website.

215
00:09:47,370 --> 00:09:50,400
But consent for whenever
you're collecting information.

216
00:09:50,400 --> 00:09:51,870
Communications mechanisms

217
00:09:51,870 --> 00:09:53,880
for how you're going to
communicate with the individuals

218
00:09:53,880 --> 00:09:55,920
for who you have information about.

219
00:09:55,920 --> 00:09:58,620
Compliance mechanisms
for collection, uses,

220
00:09:58,620 --> 00:10:00,300
sales and sharing.

221
00:10:00,300 --> 00:10:02,190
So we wanna have mechanisms to ensure

222
00:10:02,190 --> 00:10:05,280
that what we collect is what
we said we were gonna collect,

223
00:10:05,280 --> 00:10:08,160
that we're using it in the way
we said we were gonna use it,

224
00:10:08,160 --> 00:10:11,490
and that we are keeping it
up to date and accurate.

225
00:10:11,490 --> 00:10:14,640
And that if we are going to
sell it or share it, right,

226
00:10:14,640 --> 00:10:17,943
that we are doing that with
consent and full disclosure.

227
00:10:18,930 --> 00:10:22,350
Then we may wanna adopt some
privacy enhancing technologies

228
00:10:22,350 --> 00:10:26,880
like anonymization or pseudo
anonymization or tokenization,

229
00:10:26,880 --> 00:10:29,580
and then ways that we can report out

230
00:10:29,580 --> 00:10:32,700
and knowing how we can
assess our own operations

231
00:10:32,700 --> 00:10:35,220
to make sure that we are
doing the right things.

232
00:10:35,220 --> 00:10:38,610
And then lastly, we have
incident and breach response.

233
00:10:38,610 --> 00:10:42,120
That's incident prevention,
detection, management,

234
00:10:42,120 --> 00:10:45,483
notification triggers,
and reporting obligations.

235
00:10:47,250 --> 00:10:49,290
So I mentioned as part
of our privacy program

236
00:10:49,290 --> 00:10:51,660
we need to do privacy impact assessments.

237
00:10:51,660 --> 00:10:54,613
Let's go through the steps or
the components of doing a PIA,

238
00:10:54,613 --> 00:10:56,673
a privacy impact assessment.

239
00:10:58,470 --> 00:11:01,530
So we're going to focus
on a particular system.

240
00:11:01,530 --> 00:11:03,780
So the first question we're gonna ask is,

241
00:11:03,780 --> 00:11:06,600
what information is being collected?

242
00:11:06,600 --> 00:11:07,500
What are we collecting?

243
00:11:07,500 --> 00:11:08,703
What do we have?

244
00:11:09,660 --> 00:11:13,050
Then we're gonna say, "Okay,
well why do we have it?"

245
00:11:13,050 --> 00:11:14,610
This is what we have,

246
00:11:14,610 --> 00:11:15,570
why do we have it?

247
00:11:15,570 --> 00:11:18,210
Which is really another way
of saying, do we need it?

248
00:11:18,210 --> 00:11:19,200
Is there a reason?

249
00:11:19,200 --> 00:11:21,930
So let's figure out why
we have this information.

250
00:11:21,930 --> 00:11:24,680
Let's figure out why we're
collecting this information.

251
00:11:25,740 --> 00:11:28,050
Then how will the information be used?

252
00:11:28,050 --> 00:11:30,693
Let's understand how we're
using the information.

253
00:11:31,530 --> 00:11:33,720
How will the information be maintained?

254
00:11:33,720 --> 00:11:36,150
Meaning how will it be updated, right?

255
00:11:36,150 --> 00:11:40,500
How will it be modified if
it needs to be modified?

256
00:11:40,500 --> 00:11:41,910
You know, how will it be deleted

257
00:11:41,910 --> 00:11:45,483
if we get a request for it to be deleted?

258
00:11:46,860 --> 00:11:49,950
Then will the information remain internal?

259
00:11:49,950 --> 00:11:52,533
And if not, is it being shared or sold?

260
00:11:53,970 --> 00:11:57,120
Now, what are our compliance,
our regulatory, contractual

261
00:11:57,120 --> 00:11:59,790
or just ethical
requirements and obligations

262
00:11:59,790 --> 00:12:01,383
on that information?

263
00:12:02,310 --> 00:12:05,190
And then how will that
information be protected?

264
00:12:05,190 --> 00:12:06,930
How will we be in compliance?

265
00:12:06,930 --> 00:12:08,910
And how will we protect that information?

266
00:12:08,910 --> 00:12:12,060
And those are the primary
questions in that order

267
00:12:12,060 --> 00:12:15,423
that we would ask in a
privacy impact assessment.

268
00:12:17,730 --> 00:12:21,300
Now, once we've adopted
a privacy posture saying,

269
00:12:21,300 --> 00:12:23,400
yep, we are committed to privacy,

270
00:12:23,400 --> 00:12:25,020
or maybe we have to do this

271
00:12:25,020 --> 00:12:28,230
because we have a regulatory requirement,

272
00:12:28,230 --> 00:12:30,600
we issue a privacy statement.

273
00:12:30,600 --> 00:12:32,670
Now a privacy statement will describe

274
00:12:32,670 --> 00:12:35,460
how an organization collects, uses, shares

275
00:12:35,460 --> 00:12:37,200
and protects personal information

276
00:12:37,200 --> 00:12:39,360
collected from individuals.

277
00:12:39,360 --> 00:12:40,500
Now, best practices

278
00:12:40,500 --> 00:12:44,010
and in some cases are legal
and regulatory requirements

279
00:12:44,010 --> 00:12:45,990
dictate that whenever personal information

280
00:12:45,990 --> 00:12:46,950
is being collected

281
00:12:46,950 --> 00:12:49,530
there should be a corresponding
privacy statement.

282
00:12:49,530 --> 00:12:53,730
And the statement should indicate
a mechanism for opting out

283
00:12:53,730 --> 00:12:55,950
as well as for reporting real

284
00:12:55,950 --> 00:12:58,770
or perceived breach of privacy.

285
00:12:58,770 --> 00:13:01,710
That my friends, brings us
to a three second challenge.

286
00:13:01,710 --> 00:13:03,540
Five challenge questions,
three seconds each.

287
00:13:03,540 --> 00:13:04,373
Let's do it.

288
00:13:06,150 --> 00:13:07,560
The role charge with ensuring

289
00:13:07,560 --> 00:13:11,460
that an organization is
following privacy regulations.

290
00:13:11,460 --> 00:13:12,843
1, 2, 3.

291
00:13:14,370 --> 00:13:16,833
That's a DPO, a data protection officer.

292
00:13:18,420 --> 00:13:21,180
Number two, decision making tool

293
00:13:21,180 --> 00:13:24,210
used to identify and
mitigate privacy risks

294
00:13:24,210 --> 00:13:26,340
at the beginning of and
throughout the lifecycle

295
00:13:26,340 --> 00:13:28,083
of a program or system.

296
00:13:29,370 --> 00:13:31,200
Those are those questions that we asked.

297
00:13:31,200 --> 00:13:33,270
1, 2, 3.

298
00:13:33,270 --> 00:13:35,760
That's a privacy impact assessment,

299
00:13:35,760 --> 00:13:37,710
we can use at the beginning of

300
00:13:37,710 --> 00:13:40,803
or throughout the lifecycle
of a program or a system.

301
00:13:41,760 --> 00:13:43,740
Number three, limiting data collection

302
00:13:43,740 --> 00:13:47,400
to only what's required to
fulfill a specific purpose.

303
00:13:47,400 --> 00:13:48,813
1, 2, 3.

304
00:13:50,070 --> 00:13:52,530
That's gonna be data minimization.

305
00:13:52,530 --> 00:13:55,230
Number four, replacing the original data

306
00:13:55,230 --> 00:13:59,160
with an unrelated value of
the same length and format.

307
00:13:59,160 --> 00:14:02,310
That's one of our data
protection techniques.

308
00:14:02,310 --> 00:14:03,540
It is what?

309
00:14:03,540 --> 00:14:05,070
1, 2, 3.

310
00:14:05,070 --> 00:14:06,123
Tokenization.

311
00:14:07,140 --> 00:14:10,500
And lastly, number five,
public notice that describes

312
00:14:10,500 --> 00:14:14,430
what information may be
collected and how it'll be used.

313
00:14:14,430 --> 00:14:16,410
1, 2, 3.

314
00:14:16,410 --> 00:14:17,670
That's a privacy statement,

315
00:14:17,670 --> 00:14:19,770
sometimes referred to as a privacy notice.

316
00:14:21,180 --> 00:14:24,300
All right, let's talk
about privacy collection

317
00:14:24,300 --> 00:14:26,733
and processing in our Security-in-Action.

318
00:14:27,930 --> 00:14:30,240
Your employer, Space Rockets,

319
00:14:30,240 --> 00:14:32,490
has signed a contract with an HR company

320
00:14:32,490 --> 00:14:35,910
to maintain payroll, benefits, tax filing,

321
00:14:35,910 --> 00:14:38,100
and employee drug testing.

322
00:14:38,100 --> 00:14:40,920
And outside lab provides
the drug test results

323
00:14:40,920 --> 00:14:44,190
and is required to keep
the results confidential.

324
00:14:44,190 --> 00:14:45,870
The employees enter their time

325
00:14:45,870 --> 00:14:49,080
onto an online portal
provided by the HR company,

326
00:14:49,080 --> 00:14:53,310
and the HR company processes
and stores the employee data.

327
00:14:53,310 --> 00:14:55,200
For compliance purposes,

328
00:14:55,200 --> 00:14:59,970
you have been asked to identify,
okay, who's the data owner?

329
00:14:59,970 --> 00:15:02,670
Who's the data controller or controllers?

330
00:15:02,670 --> 00:15:05,940
And who is the data
processor or processors?

331
00:15:05,940 --> 00:15:08,340
So tell me about the privacy roles.

332
00:15:08,340 --> 00:15:11,640
So we've got our company,
which is Space Rockets, right?

333
00:15:11,640 --> 00:15:14,190
Signed a contract with an HR company.

334
00:15:14,190 --> 00:15:18,480
And that HR company is going
to manage payroll, benefits,

335
00:15:18,480 --> 00:15:22,350
tax filing, and employee drug testing.

336
00:15:22,350 --> 00:15:25,800
Now, an outside lab provides
the drug test results

337
00:15:25,800 --> 00:15:28,920
and is required to keep
the results confidential.

338
00:15:28,920 --> 00:15:31,500
Our employees are entering
the time into the portal

339
00:15:31,500 --> 00:15:33,180
that's provided by HR.

340
00:15:33,180 --> 00:15:38,180
The HR company processes and
stores the employee's data.

341
00:15:40,320 --> 00:15:41,970
And I have a lot going on here.

342
00:15:41,970 --> 00:15:44,760
Put me on pause and figure
out who are the data owners,

343
00:15:44,760 --> 00:15:47,763
who's the data controller,
and who is the data processor?

344
00:15:50,520 --> 00:15:54,810
Space Rockets is the data
owner and the data controller.

345
00:15:54,810 --> 00:15:57,750
Ultimately, they are responsible
for that information,

346
00:15:57,750 --> 00:15:59,940
and they are making the decisions

347
00:15:59,940 --> 00:16:01,920
on how that data is gonna be used

348
00:16:01,920 --> 00:16:04,620
and who else might work on that data.

349
00:16:04,620 --> 00:16:07,080
The data owner is responsible
for protecting the data

350
00:16:07,080 --> 00:16:09,630
in compliance with all
applicable regulations.

351
00:16:09,630 --> 00:16:12,870
And the data controller
determines the purposes for which

352
00:16:12,870 --> 00:16:16,473
and the means by which personal
data is gonna be processed.

353
00:16:17,640 --> 00:16:20,460
So what about the HR
company and the outside lab?

354
00:16:20,460 --> 00:16:22,560
Those are both data processors.

355
00:16:22,560 --> 00:16:26,040
The data processor is going
to process that personal data

356
00:16:26,040 --> 00:16:28,380
on behalf of the controller.

357
00:16:28,380 --> 00:16:31,530
So Space Rockets was our data
owner and data controller,

358
00:16:31,530 --> 00:16:34,800
the HR company and the outside lab

359
00:16:34,800 --> 00:16:37,920
will be considered data processors.

360
00:16:37,920 --> 00:16:39,990
So understanding privacy roles,

361
00:16:39,990 --> 00:16:42,243
that my friends is Security-in-Action.

362
00:16:43,440 --> 00:16:44,490
There's your word cloud.

363
00:16:44,490 --> 00:16:46,110
There's a lot here.

364
00:16:46,110 --> 00:16:47,940
Again, make sure you understand

365
00:16:47,940 --> 00:16:49,440
that you know all about it, right?

366
00:16:49,440 --> 00:16:53,130
You can speak to all of these
confidently and comfortably.

367
00:16:53,130 --> 00:16:54,660
If not, go back into the lesson.

368
00:16:54,660 --> 00:16:55,530
It was a long lesson.

369
00:16:55,530 --> 00:16:57,030
There was a lot there.

370
00:16:57,030 --> 00:16:59,190
And when you're ready, come on over

371
00:16:59,190 --> 00:17:00,640
I got a quiz waiting for you.
