Petronella Technology Group Podcast 01-14-21
Recorded January 2021. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.
What this episode covers
Craig Petronella of Petronella Technology Group welcomes Lisa Shastine, co-founder of the Shastine and Percy Law Firm in Tampa, Florida, a practice focused entirely on data security and privacy. Lisa explains that the General Data Protection Regulation took effect in May 2018 and grew out of Europe's long-standing treatment of privacy as a fundamental right.
She recalls a client data breach days later that triggered what she describes as a 72-hour reporting deadline at the time of recording. The conversation covers the distinction between data controllers and data processors, the broad definition of personal data, and the lawful bases for processing, such as consent and contract performance. Lisa explains when United States businesses may fall under GDPR, including targeted marketing in European languages or currencies, and notes that GDPR covers nonprofits while, at the time of recording, California's CCPA does not. She recommends starting with a data map, performing data privacy impact assessments, and using encryption. She also describes how, at the time of recording, the Schrems Two decision had invalidated the Privacy Shield, leading companies toward standard contractual clauses for transatlantic data transfers.
Worth rememberingKey takeaways
- Lisa advises first determining whether people in EEA countries regularly access your services, because knowingly doing business with them creates a duty to examine GDPR requirements.
“Do you know that people in these countries are accessing, you know, your your services or your products?”
- Lisa recalls a client breach just after GDPR took effect that triggered what she describes as a 72-hour reporting deadline at the time of recording.
“they had the obligation of reporting their data breach within 72 hours of discovery of that breach.”
- Lisa explains that processing is lawful only if at least one basis applies, such as consent, contract performance, a legal obligation, or legitimate interest.
“the data subject has given consent to the processing of his or her personal data for one or more specific purposes. So there's your consent, right?”
- Lisa notes that GDPR protects a much broader range of information than United States law, including opinion data, which is not protected in the United States.
“Opinion data under the GDPR is a protected category of information.”
- Lisa warns that translating pricing into GDPR country currencies or marketing in local languages could be seen as doing business in Europe.
“So you're translating your pricing into into GDPR country currencies. You are translating it into their languages or the languages most used in in those countries.”
- Lisa suggests starting with a data map of your own business processes, then analyzing it through the lens of GDPR and performing a data privacy impact assessment.
“That's why I'm suggesting you start with your data map and just your own business processes.”
- Lisa calls encryption a fabulous tool and a get-out-of-jail-free card in most every jurisdiction, provided the implementation, such as hashing, is strong enough.
“encryption is a fabulous tool; it's a get-out-of-jail-free card in most every jurisdiction.”
The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.
From the show notesAbout this episode
Petronella Technology Group Podcast 01-14-21 with Craig Petronella of Petronella Cybersecurity and Digital Forensics and Expert GDPR Attorney Lisa Shasteen discuss what GDPR is and steps you can take to make your website and business compliant.
Episode transcript
Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.
This is Encrypted Ambition, a podcast about the builders rewriting the rules. Join Petronella Technology Group as we decode the ideas, challenges, and momentum behind tomorrow's business, technology, and leadership breakthroughs. You're listening to Cybersecurity and Compliance with Craig Petronella. Visit us online at petronellatech.com.
Well, hi, Lisa. Welcome. Hey, Craig. Are you excited to talk about GDPR today? Oh, I'm excited about GDPR every single day. Sure. So, so give us. So, introduce yourself, please, so the audience knows who you are.
Okay, sure. My name is Lisa Shastine, and I am a co-founder of the Shastine and Percy Law Firm here in Tampa, Florida. And we pretty much focus on data security and privacy 100%. That's that's what we do, and we represent quite a few tech companies.
As well as people who are having some issues with privacy and security of information, and we do things with social media influencers and the like. So we're all digital all the time. Awesome. So.
Tell us, from your perspective, I bet a lot of people have heard GDPR that name. So, what what is it really? What what does it mean? What what do people give us like your version? The short the short one, of course. Well, well, I don't know if you want my real version or the official version, but the what GDPR is is the General Data Protection Regulation.
And it was - it actually went into effect in the spring of 2018, I believe it was May 25th. And in any event, I just - I remember that year very well because about seven days later, we got a call.
From a a client who's a very wonderful group, and they had had a data breach, and unfortunately, they were doing business all over the world from a location here in the United States. They didn't even have any offices in the EEA, the European Economic Area countries. So it's not just the EU; it's it's a few more.
That didn't join the European Union, and so they needed some help. And under the General Data Protection Regulation that had just gone into effect, or the GDPR, they had the obligation of reporting their data breach within 72 hours of discovery of that breach.
Because that is the GDPR standard, and they called us thirty six hours in, so I said, "Yay!" I wow, they give you a lot of time. Yeah, I'm glad we weren't rushed. It's basically my my response. I was signing an engagement letter with them at their offices at seven p.m. and saying we we really have to get started now. Yesterday.
With the forensics team, who was already on the scene, thank goodness. And you know, so so the the thing about GDPR and the whole philosophy behind it, I think it's important to understand it. Europe, since the 1100s, has had this concept.
Which was incorporated into the laws of the state of Hesse in Germany, that European citizens have a inalienable right.
Of privacy, so just like we have, you know, you know, the right to, you know, the pursuit of happiness, they have this right to privacy. It's a fundamental right to them, and so sharing of information is a big deal for Europeans. And I don't know if any of the listeners.
Are financial professionals, or somebody who has come into contact with maybe a European citizen who's trying to set up some sort of business or residence over here, that they are generally shocked and dismayed that we share so much information.
With our credit reporting agencies and other creditors, and we tell them our incomes, and we tell them our jobs, and we tell them all sorts of things, and they just they can't even believe it. I mean, it's it's just something. So the GDPR grew out of that philosophy, and it it basically took over from a couple of.
Regulations, or a couple of, I should say, laws that were in effect that were not quite as far-reaching. So, what they wanted to do is create an EEA-wide standard that would sort of direct the, you know, the the protection of information throughout the.
Area. So that's that's a lot. I'm sorry. And and by the way, each of the EEA countries, or I'll call them states, because they are they are nation states. They each have the opportunity, also, just like our states in the United States, when there's a federal law, the states can.
Enact regulations or requirements that are even more restrictive for their for the benefit of their citizens. They have some of that going on too. And for instance, in Germany, there I believe five five regions or states within Germany. Each of them has its own.
You know requirements and methodologies, and so delving into this kind of thing, it's it's just like in the United States. You certainly don't want to be caught, you know, non-compliant with GDPR, and not know which way you're going to turn because it's very complex. Wow! So it sounds like a lot to keep up with. So.
Bringing it back or simmering it back down to websites and GDPR. I know I've seen like the little banners on the websites and things like that. What's your take on that? Like some people are confused by that or don't know where to start. What are you referring to? You know, people marketing GDPR.
Yeah, well, yeah. So, like, um, company United States companies that are in the United States, small businesses, for example, they may have a website, um, and they may put on they may do marketing on their website for you know maybe retargeting or various types of marketing, uh.
The visitors of their website, right? So, in that context, should shouldn't they have something in their privacy policy, terms of use, and or some type of notification banner if they're going to use cookies or things like that? Well, yeah, actually, very similar to well.
Similar in level of difficulty of compliance. That is, that is where the similarity between California and GDPR countries diverge. They're both similarly difficult. There are a few touchpoints that are the the same, where you know, where you have to know what your
Under under the GDPR, you have to have a reason to collect the information you are collecting or processing. So there's data controllers who are people who are okay. So let me just explain this very very basic function under GDPR. There's a there's a distinction between a data.
Controller and a data processor. So, a data controller is someone like Petronella. Okay, so Petronella will collect information on its customers, and let's say Petronella hires an accounting firm to process financial information on.
For those those customers, so the the financial firm would be a data processor because they're doing something on behalf of a of a data controller. The controller is telling what needs to be done or directing traffic, you know, sort of like a company director. They're setting policy and and saying what needs to be done. But they may outsource some of their functions.
To these data processors who work in conjunction with or on behalf of the data controller, so similar. You know, there are similar concepts throughout throughout the world, which we'll get to in a minute. But let me get back to your question. So, you know.
Data processors and controllers have to have. Well, the the controller has to have a reason for collecting the information. There has to be a contractual basis, or there has to be a law enforcement basis, or there has to be something like the, you know, to fulfill, you know, some sort of order.
From the customer, or something like that. You have to have a reason why you're collecting this information from from the what they call the data subject. I actually like that term. Data subject is so descriptive that I use it even here when I talk about the United States because people understand what I mean. So the the data subject also has right to be forgotten.
So you have to get rid of all your information on the data subject, which can be challenging in backups and things like that. There are they have the right to correct their information and to review it. So it's in that regard, it's very similar to what.
California requires, but who's covered is is different, and that's where I'm going to go with this this explanation. I had to kind of give you that background, so not every company is going to be subject to GDPR. If you have a website,
You know, there's been some guidance from the European Data Authority over there about the interpretation of the GDPR. Thank you so much. You know, after after all. And so, at this point, they're saying, "Well, if you're."
If you're a data subject, and let's say you're a German citizen and you come here and you go to the hospital, well, you're here and you're giving your information here for healthcare. You're not necessarily subject to GDPR. There may be circumstances and under which you would be, but you're here doing business here, getting services here, and.
Indeed, the GDPR says the data subjects who have rights under GDPR are data subjects within the EEA, within the the governed territory, right? And so, what does it mean to be in there? I mean, so does that mean I have the same rights as an American citizen if I'm if I'm just like traveling over to Italy for a couple of weeks?
Probably not. Of course, like any legal system, the data the data authority over there is not 100% clear, and they haven't sorted out. Now, if you if you had put the Germans in charge, they would slice it and dice it, and everything would be laid out.
Like minute detail, but you know, you've got the French in there who use a very elegant approach, kind of like our Constitution. Well, it should just, you know, the laws should apply to every situation, and we'll interpret them based upon the facts at hand. So a lot of times, you know, people are asking very definitive questions like, "What is the rule?"
Well, that's where the lawyer answers come in. It depends what is the situation. Also, if you're if now, I will tell you how you can get into the GDPR crosshairs. You can be marketing. You can put marketing on your website that.
Basically, is targeted toward people that speak a certain language. So you're translating your pricing into into GDPR country currencies. You are translating it into their languages or the languages most used in in those countries. So that could be seen as doing business over there.
the The term "doing business" is not defined, of course, in the regulation. And regulations usually define way more, but but this one doesn't. So it's still a little bit vague. But I'm just saying, there's there's been some guidance lately that, you know, if you're an American company, you're you're.
You know, marketing in English. You're you're not necessarily. I mean, you you're not knowingly. You know, marketing to people all over the world. Unfortunately, our clients. What they were an association, and they had members.
From all over the world, that was their that was their thing. They were they were trying to get the global thought process in a certain industry, and so they knew. I mean, they they knew that that's what they were doing, even though they weren't marketing with specific, you know, translations or conversions of currency, or or they didn't even use any foreign languages on their on their website. But they.
By by the nature of their business, they were within that purview. You see what I'm saying? So it's fact specific. So, if I've got a client that's in the nonprofit space, and they are they have a strong mission to change the world, and they attract folks that are in the European Union, right? Um.
Shouldn't they then have some notifications on their website in regards to a banner or updating their policies? Yes, there there would be there there would definitely be a reason because they know they're attracting people all over the world and they're encouraging it, right? So I would say, in an abundance of caution.
I would definitely do that. Now, see, there's where, like, for example, I keep picking on California. I'm sorry, California, but you know, and California is really progressive in this area. But, but the thing is, they in California, their CCPA does not apply to nonprofits. So that's not the case.
With the GDPR applies to for-profit and nonprofit organizations. In fact, our our client was a not-for-profit, but it was a rather large one. Wow. Okay. So then, I guess the question is: so something should be done. So then, then it seems like there's just so much variance in what to do. But I but I assume that.
If you do something, it's better than nothing. So, I guess what should be their next step? Should they, obviously, do the basics with the banner on the website, and you know, tell folks what they're doing in regards to marketing and what data they're collecting.
And why, you know, like you explained, you know, you always have to have a purpose, right? So, why they're collecting this information, and how, you know, what they're doing with it, should that be kind of the the minimum? Yes, and they're they're. I mean, if you go onto a website, I mean, you can you can take one that you know has a GDPR, you know, privacy obligation, such as, I mean, let's pick on somebody who.
Who's like mad like Facebook or or or HubSpot right like HubSpot dot com? They have a GPR. Yeah, I mean, and and you've got some others. You know, I mean, Microsoft, Google. I mean, go go to their GPR disclosure and just and just take a look at how they do it. You're going to have to have.
You know your cookie policies. You're going to have to have your your you know your reason for collecting the data. You're going to have to have a statement of of you know EEA citizen right. You know people in EEA. I say citizen doesn't have to be a citizen. Um, you know could be somebody from Africa who's who's over there working, or could be an American who's over there staying for an extended period of time.
What that period is, you know, only only those people know. Only the regulators know, and they'll tell you. Fine. So to be clear, in the in this basic example of a website, so if I'm a German citizen, for example, and I find this nonprofit website that's in the United States, in this case, you know, let's say the East Coast.
And there's some type of event, like I said, the mission is to pretty much change the world. That I need to be advised of what data is being collected from me and why, right? And what if I say no? Like, what if I don't want any of that data collected? Am I no longer allowed to view that website? What's the extreme?
Well, you have - I mean - you have the right to be told what is done with your with your information if you participate in that website. And if you disagree with it, then you do not have to visit that website, right? It's like if you don't like the the movie that's on Channel Four, change the channel.
Right, but yeah, okay, that makes sense. But but I guess do you write in the policy, you know, gracefully leave, or do you have to put a technical control that if they click the no button, then something happens? Well, I think if I think if you you know if if somebody clicks that they don't agree with your policies, then yes, I mean it would be wise to.
Implement a technical control to say, "Thank you for visiting the website. We understand you don't agree with our policies." You know, have a nice day, and then send them back to Google or somewhere else. There you go. I mean, because at the end of the day, if you allow that person in and they say they don't agree, then.
We, I mean, then you're basically putting putting yourself as the business owner or business operator at risk. Okay, all right. Another question around this: What if you, you know, a lot of folks would do what's called geo fencing on their firewall, where, you know, like let's say you're a small insurance company.
Or you're a mom and pop business, and your business footprint is only maybe two or three miles from your geographic presence, right? Your storefront. What if you put in place IP address and firewall rules to basically deny any traffic outside of your your area? Maybe it's your your little area, or maybe it's just your state.
That you want to accept, and then for everybody else, your website's not accessible. Is that something that could be an example of a control, even though it might be extreme? Well, I'm going to throw this one kind of back into you, your Ben, because technically, I know that you're you're very aware.
That you know, an IP address can be tracked from a location, but that's not necessarily where that person is. And for many reasons, that IP address may be hitting your website from a location where the person is is not. So, I mean, it's it's one control.
Right, I mean, it's one control. Say you, nothing, no IPs from this area, but that's not a hundred percent bulletproof policy. And maybe you can. I understand. That's like one layer of the onion, right? That I always talk about the onion concept. I guess what I'm saying is, you know, if we say in the in the policy, or you know, Mr. Customer, the mom and pop example that I gave.
Says, you know, we only serve customers that are within a three mile radius, you know, from us. Blah blah blah. In the policy, right? And then we have our banner that, you know, if you're if you don't agree with this, you know, we.
Gracefully redirect you back somewhere else to like Google, and then you know maybe we add this other layer with IP address verification. And yes, you're absolutely right. You could spoof an IP address, and people use VPNs and things like that. I guess my point is that how far, in your opinion, does the small business need to show effort and steps towards?
Policing this. Well, I think you know. I think you go back to: Do you know that people in these countries are accessing, you know, your your services or your products? Do you know that you're doing business with people like that? If you know that.
Then you probably, you know, and it and it happens on a regular basis. It's not, you know, I mean, even though one is enough, but but you know, if if that's the type of business you have, then you're gonna have, you know, you're gonna have a a duty to look at the requirements of the GDPR. And one one of the requirements at a certain level.
You know they have they have, you know, sensitive information that they've identified in the GDPR. There, there's you know like certain information information that's protected by the GDPR is way broader than what what we normally see in the United States too. So you if you're if you're saying well I'm an opinion based company and I just
Get you know people's opinions on different things. Well, guess what? Opinion data under the GDPR is a protected category of information. That's not the case here in the United States. So, you know, here we're focused on social security numbers, which they don't have over there.
You know, they don't they don't use things the way we use them. They have identifiers, but they don't they don't necessarily use them the way we use them. You know, there's still you know things like you know email plus passwords and things like that. But over there, you've got a lot a much broader definition of information that is personally identifiable information, basically.
Sure. So that's what I mean. That's where people get a little, you know. Let me let me see if I can read this to you. So, personal data. This is for purposes of this regulation. Personal data means any information relating to an identified or identifiable natural person, data subject.
An identifiable natural person is one who can be identified directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental.
Economic, cultural, or social identity of that natural person. Wow, that's a lot. Yeah, think about it. And so here's what here's what processing means. Okay, so if you're processing data.
And by the way, you can be a processor and a controller at the same time. So you you're not just thrown into one bin. But you know, like in the United States, if you're the controller, you got to notify the data subjects right away. If if you are notified of a breach, if you're a processor in that particular incident.
Then you have to notify the controller. So yes, really the same kind of third-party structure that we have here under HIPAA and other other places. But processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization.
Structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure or destruction. So, just about everybody is a data processor, right? Right.
So, I mean, see what I'm saying is it's just really, really a lot. I mean, it's really. So, is it safe to say that when in doubt, force the user to accept your your policy, or otherwise gracefully redirect them? Well.
Yeah, I mean, for for many reasons, and even people you know working in the United States and only working with with clients in the United States, you're you're going to need to make sure that people are okay with your your privacy policies, because if they're not, you do need to redirect them, and and most sites will do it. Go go to any site.
And see if you can quote. No, I don't agree. See what they do to you. Make sure your cookies are. But you know, but really, just make sure that you know. See what they do. But you have to agree with their with their way of treating you if you're going to be in their house. If you don't, if you don't want to have what they're cooking up for dinner.
Then you need to go somewhere else for dinner. Sure. Well said. Unless you were important, like you know, the Queen of England or something, and somebody's going to do it just for you, you know. Right. Doubt it, though. I mean, and here, let me see if I can send you. Okay, lawfulness of processing.
I just I want to I want to cover this. It's very important. Processing shall be lawful only if, and to the extent that at least one of the following applies: a, the data subject has given consent to the processing of his or her personal data for one or more specific purposes. So there's your consent, right? And then number then b.
Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into the contract. C. Processing is necessary for compliance with a legal obligation to which the controller is subject. D.
Processing is necessary in order to protect the vital interests of the data subject or of another natural person, like providing somebody's medical details to emergency personnel. You know, in other words, e. Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
And then, as processing is necessary for the purposes of the legitimate interest pursued by the controller or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject, which require protection of personal data, in particular where the data subject is a child.
Now, what I will say is this: whole thing about the interests of the control being overridden by the fundamental rights and freedoms of the data subject. One of those fundamental rights and freedoms is the right of privacy. So you have to balance that, and that's where.
Companies in in Europe, depending on what level of processing you're doing and what types of things you're collecting, you may have an obligation. I mean, it's always a good idea, but you may have an obligation to perform a data privacy impact assessment, which is a DPIA, and.
So it's sort of like a security risk assessment, but this one covers privacy, and it talks about. I mean, it basically takes a data map. Okay, so you you got your data map, right? Like, what are my pro my business processes? Where do I take the data? When I get it, what do I do with it? Do I store it? Where I store it?
Then I use it. How do I use it? Where do I use it? How do I get it there? You know, what are all my protections? You know, along the way, and when I'm doing each of these processes, like I'm, I'm providing the information to my credit card processor so that I can build this person, right? Right. So that's a legitimate.
Right, I'm doing that in order to fulfill a contract with the data subject. So that's a legit interest. But what I have to do is go through and list all of my processes and figure out why I'm doing each of those processes and what's a really good reason under the GDPR why I need to do those processes and what sort of protections I have on them.
So is that process that I think you said DPIA, right? Yeah, data. Yeah, data privacy impact. So is that something that you would do for somebody, or is that something that they would self-assess or on their own? Well, it it doesn't have to be done with a third party. So companies can or or people can do that for themselves. Generally.
They would like to know, you know, at least the first time. They would like to know whether they are doing it right or not, and interpreting the law correctly. So we we can get involved with that and sort of set up the framework for them. And then as they're, you know, let's say you add a some sort of a business line or.
You decide to do something differently in your business, and you're processing data differently, or you're marketing to new places, and you're sharing information with new companies, like an AI company, or you know, a blockchain company, or something. Then you've got to you've got to redo your DPIA to make sure these new new things or changes.
Are still, you know, that you can, you have some basis for it, right? And that the things that you're doing are not overridden by the interests and fundamental rights and freedoms of the data subject. Wow! And you literally have to write this out in the DPIA. You literally have to say, you know, this is because of this. I, this is, you know, our interests in doing this are overridden by their.
You know, I mean, whatever you have to say. You know, we we have this as a basis, and you know, basically the the best thing to say is the data subject is agreeing to all this because we're doing it in order to do the business that we're doing with the data subject. Okay, so it sounds like most businesses that.
Would work with somebody from the EU and be subject to GDPR. Should definitely follow that process and go through that DPIA. It it would be very interesting to do, yes, and and very very good to do as a you know it's like it's like do you have to put? Are you required by law to put?
Anti malware on your on your endpoint, no, is a good idea. Yeah, yeah, and that's getting in that in that equation or that example, that's becoming you know more of of a political issue as well. I mean, especially around the CMMC, where yeah, you're going to have to put that. I mean, they don't tell you which brand maker manufacturer you have to put on there, but you have to show supporting evidence that it is on there.
Terrible example, probably because even some states are talking about reasonable security measures, you know, required in their privacy laws. So, you know, obviously that's going to be required. But, you know, it's like it's a good idea to, you know, lock your deadbolt as well as your little, you know, you know, doorknob lock. So it's it's just, you know, it's it's it's.
It's a defensive measure on your part against, you know, overzealous regulators. And if anybody has been following any of the the litigation with, you know, Facebook and and the Schrem cases, Schrem's is a guy from Austria that disagreed with Facebook's, you know.
Policies and their processing of his information under GDPR. There was Schrems One and Schrems Two, and as a result of Schrems Two, the entire basis for transferring data of European data subjects to the United States was absolutely decimated. The European Court of Justice decided that.
The the systems whereby we were doing that, the Privacy Shield was was not sufficient, and basically it was it was based on our our Section Seven O Two collection of intelligence data, just doing these big scoops of data and sorting out the things we actually wanted.
And Congress over here keeps passing that thing, and the Europeans are like freaking out because when we go looking for bad guys, we just scoop up older people's information. They don't like that. I mean, I totally see it, but it sure makes it difficult. So now you're you're kind of looking at putting in place.
You know these what they call standard contractual clauses. So if you're going to have, you know, cross transatlantic, you know, transfers like that, you're going to have contractual clauses in your data processing and controlling agreements, so that you are are deemed to be to have adequate protections for European.
Citizens, and that's a whole nother. That's the standard contractual clauses, a whole nother story. But just for the basics for GDPR, I would say, yeah, it's a good idea to do a privacy impact assessment, data privacy impact assessment. Great idea. Well, it sounds like it would give at least some.
Some clarity around how GDPR could affect your organization, and you know what what jobs to be done. You know, need to be addressed. One thing that came to mind, you know, going back to the IP address, and obviously spoofing of IP address is easy to do. VPNs, you know, IP address, and you know the the very nature of the internet was not built around security, so.
I'm wondering if you know if if if it's so easy to spoof an IP address and use a VPN and things like that, how do you really know who's visiting your website and where they're coming from anyway? You know what I mean. So it sounds it sounds like that would be you know an exercise that's hard to prove, but it it it also sounds like.
You, as a website owner, if I keep going back to websites, but I mean using that as an example, it sounds like you should definitely have the GDPR information in the policies, the privacy policy, the banner, etc., and pretty much ask every time somebody comes to your website if you agree or not, and then.
Gracefully redirect them away if they don't, and then I think once they raise their hand and fill out like a contact form, and you do know where they are and where they live, providing they give you factual information, then you probably have more obligations to to obviously safeguard that information.
Yeah, I think I think, and and you gotta you gotta be real careful about what you're what you're collecting and what you're keeping. If somebody, you know, disagrees, right? So that's that's the other thing. You know, get it off, get it off. It's like, you know, hurry up, it's a spider. It's kind of it's kind of like that.
I was gonna, I was gonna share with you one other thing. Okay, so the lawfulness of processing is addressed in the GDPR generally. Okay, there's been guidance on this, but you know we can't get in the weeds. I'm just trying to give you the top level kind of perspective. It says processing shall be lawful only if, and to the extent that, at least one of the following applies.
A. The data subject has given consent to the processing of his or her personal data for one or more specific purposes. So basically, you're disclosing to the data subject on your site, you know, with your GDPR notice that, you know, here's what we do with your data, right? Then they agree or don't.
B processing is necessary for the performance of a contract to which the data subject is a party in order to take steps at the request of the data subject prior to entering into the contract, right? And then you've got, you know.
All these other things that we went through. So, so again, with respect to the the notices and the agreement, first you have to tell them what you're doing. That's why I'm suggesting you start with your data map and just your own business processes. You know, probably most businesses, you know, unless you're gigantic enterprise, you probably have.
A succinct number of business processes that you engage in. You know, you probably have things that you do. You might have, you know, several things that you do, like we do. But we do a lot of the same thing. I mean, we take in people's information through our email programs or telephone calls. We write down notes, you know, on our computer. We store them. Where do we store them?
How are we protecting them at all these different points? You know, what what are we doing? And then, of course, that comes into the you know the fundamental triad of security, confidentiality, integrity, and availability. You know, you got to make sure you're protecting that in your in your data, and you have to pay attention to the technical, physical, and also the administrative, where your policy and procedure aspect of security of the data. Because if it's not secure, it won't be private.
Somebody's going to dock you and put out your information on the internet, a la Capital One breach. Yuck! You know? Yeah. Wow. So that's you get, and and then one person calls their data protection authority in their country, and you are just tearing your hair out.
Jeez. So, do you have any tips or suggestions for? I mean, it sounds like the assessment process is a good place to start. Is that accurate, or any other insights? Yeah, I think I think even before you get there, I think it's, you know, I think I think it's important to understand what business you're in with respect to people in the EEA countries.
Right? Are you even governed by this? For example, a very large hospital system here decided they weren't. They're like, we're not. And the reason they decided that, the basis for their reason didn't matter how big they were or small they were. It was just, it was just that they treat people who are in the United States and they're here.
Getting information, we're not transferring information across the Atlantic, you know, and we're not having to prove the adequacy of our controls. We're collecting information here in the United States. That was their take on it. Now, if somebody is sending over information from their
From their, you know, doctors or whatever, in the EU, there may be an argument. But I mean, it would be factually based, right? So you may not really be marketing to European people. You might get them every once in a while. You're just, you're just marketing. You're, you're thinking you, you know, you're mainly dealing with Americans or whatever. But that is something.
That I would say, talk to somebody who knows something about the GDPR and has a little bit of knowledge about the different cases that have arisen since it has been enacted in 2018, because that will.
You know, guided by that perspective, you'll be able to make an analysis. And nothing is going to be perfect. I'm going to try to emphasize this. You know, until a regulator pronounces whether you're good or not, nothing is black and white. You know, are you are you needing to comply? Are you not needing to comply?
You know, most U.S. businesses that are doing business business locally, they don't have an obligation. But most, but but if you know that you regularly do business with people outside the country, you may have that obligation. And that at that point, I would definitely go to your data mapping and your business process mapping, which you should have at all times anyway.
Even for your United States risk assessments, that Petronella can help you with, and at that at that point, you know, analyze it through the lens of GDPR, because you probably already analyzed it for the United States compliance, but you need to now look at it from a European perspective, because as you could see.
The types of information that are protected are is is much it's a much broader group of information. Absolutely, so it you know further emphasizes the need and importance of annual security risk assessments, and then branching that out into GDPR.
And other regulations that you might be subject to, but it sounds like when in doubt, at least make some effort instead of assuming or doing nothing. Yeah, and I and here's here's my here's my you know symbol full of advice for anybody that asks, you know, a cocktail party or otherwise. I I usually tell people just absolutely no.
What kind of data you're collecting, and where your data is, and how you're protecting it. You know, encryption is a fabulous tool; it's a get-out-of-jail-free card in most every jurisdiction. However, you know that depends on whether your your hashing is strong enough, et cetera, blah blah blah. But
You know, and you. You're not saving the public keys on your hard drive or somewhere else. Ah, yeah, or putting your passwords on a post-it note, you know, on your desk, and then leaving for, you know, Europe. So, no, I. What I would say is just know, know your business. You know, in it's it's become a function, a business function to know.
Your data types, know where where your data is and how it how you deal with it. So that's a business function, just like you know how much money you have in the bank and how much income you can expect, and you know you know what your your budgeting requirements are going to be for the year. You you just kind of need to do that with your data. Also, it it is it is an asset.
And it's valuable, and it's valuable when it's stolen too, because it's going to hurt you. It will hurt you to the extent of its value and more. Awesome. Well, this has been awesome. I appreciate all your insights and discussion on GDPR. So, how do folks reach you? Should they want to do the assessment process with you?
Yeah, if somebody wants to speak more, and more particularly about their particular situation, you can feel free to call me directly at eight one three two two zero three thousand. And also, we have a website which is S H A S P E E N.
P is in Paul Percy dot com, so that Shastin Percy dot com. Awesome, thank you, Lisa. I appreciate all the insights and the the the shedding of light on this wonderful topic. I don't know if I created confusion or shed light, but yeah. Well, thank you again. I appreciate it.
You're welcome, friend. All right, you too. Bye. Bye. Thanks for listening to yet another episode of Cybersecurity and Compliance with Craig Petronella. Listen to all of our podcasts on Apple, Google, and Spotify. Visit us online at petronellatech.com to book a meeting with Craig about your business. That's a wrap on this episode of Encrypted Ambition.
Subscribe wherever you listen, and if today's guest inspired you, leave us a review or share the show with someone in your circle. To learn more about how we support innovators with AI, cybersecurity, and compliance, head to petronella.tech.com. Thanks for listening, and remember, the future favors the bold.
Never miss an episode
New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.