Passed by the National Congress of Brazil on Aug 14, 2018, the Brazilian General Data Protection Law, or LGPD (“Lei Geral de Proteção de Dados”), is set to take effect in August 2020. The LGPD grants data subjects a bevy of privileges, including access to their data, deletion of this data, data anonymization, and the disclosure of any third parties who may have their personally identifiable information (PII). For small and medium-sized businesses, the potential LGPD fines can be devastating; in fact, violations can be as high as 2% of annual revenue — up to 50 million Brazilian reais (roughly USD $30 million) per infraction. If your organization is currently working to address this new legislation, the following points can help you in your endeavor.

Assess whether your organization needs to be compliant

Before you assign a data protection officer (DPO), be sure to receive advice from lawyers to better understand the law. Determine whether your company is a controller, a processor, or both, as this will dictate what your liability looks like. If you do not collect, store, or sell data subjects’ PII, odds are you don’t even need to worry about the LGPD.

Also, certain data collection is exempt. As an example, anonymous data generally doesn’t apply to the LGPD. As long as anonymized data is not reversible or used for behavioral profiling, this data doesn’t fall under the LGPD’s purview. Additionally, data used for academic or artistic purposes, data used for criminal investigations or public safety issues, and data not being used for business purposes all fall outside the scope of the LGPD.

Also, per the LGPD, there are different deadlines and procedures for start-up companies and small businesses. The Autoridade Nacional de Proteção de Dados (ANDP), the government entity responsible for enforcing data protection laws, is ultimately responsible for determining which companies are required to adhere to the LGPD and appoint a DPO.

Much like the GDPR, the LGPD requires any company that processes personal data of Brazilian customers to comply with the law. So, even if your headquarters are in another country, you very well may have to adhere to LGPD regulations.

If you do have to comply with LGPD, locate where the data is stored 

Whether your personal data is stored in databases, file servers, Word documents, or Excel sheets, it’s important to separate this data from non-confidential information. By isolating personal data, you can set up special security configurations and provide an extra layer of security.

Also, by isolating this sensitive data, you’ll focus more on the data flow, making it easier to answer the following questions: “What data is being collected?”, “Where is it coming from?”, “How long is it being stored?”, and “What processes are being performed upon it?” Be sure to back up this data as well, so you can access it quickly in the event of an incident.

One person in every department should be responsible for their department’s sensitive PII

If your company is indeed a data controller or processor, you should appoint a DPO (“encarregado”) to conduct a data protection impact assessment (DPIA). Be on the lookout for large-scale data processing, as well as data on vulnerable subjects, and any data that is of a personal nature. You should consider assigning one employee in every department to work closely with the DPO as the DPO performs a DPIA, as this can prevent a great deal of headaches down the road.

Also, according to the LGPD, the DPO can be located outside of Brazil. In fact, the DPO doesn’t even have to be an individual person per se; it could technically be a third-party group or committee. However, SMBs shouldn’t have to break the bank as they work to comply with the LGPD. In all likelihood, you won’t need to hire a third-party consultancy to fulfill your DPO responsibilities.

Issues unique to the LGPD

As a final caveat, there are still a few outstanding issues in regard to the LGPD roll out. Although it was originally supposed to take effect in February 2020, the LGPD has been pushed back until August 2020. We may see another delay in the coming months. Additionally, as of December 2019, the government entity responsible for enforcing the LGPD has not been formally created. And lastly, as the law stands now, it requires DPOs to provide evidence of a data breach “within a reasonable time frame,” which is a rather vague clause.

Disclosure: This article was originally published in IT Forum 365. 

After the California Consumer Privacy Act (CCPA) passed, lobbyists from both sides of the aisle descended on Capitol Hill. The Information Technology Industry Council (ITI), a DC-based lobbying group, has called for a federally mandated consumer data privacy law, as have some of the biggest players in tech, including Google, Facebook, Intel, Microsoft, and Apple.

Industry players believe they’ll have to deal with a patchwork of state regulation if Congress doesn’t intervene and issue a federal law. Pro-business groups, such as the Council on Foreign Relations, have been particularly vocal in their assertion that it’s up to Congress to protect consumer privacy.

Pro-business concerns: It will stifle innovation and force out smaller players

As Mercatus Center research fellow Jennifer Huddleston argues in a policy brief, “With states like California now enacting their own data privacy policies, federal action may be necessary to prevent an individual state from unfairly disrupting markets and the framework initially established for the internet.” Huddleston suggests that the absence of federal action will cause more states to place overly stringent legislation into practice, which could stifle innovation.

The Mercatus Center is a center-right think tank, so it’s no surprise that Huddleston is an advocate of soft laws and industry self-governance; however, she does make a rather convincing argument when she suggests that laws like the CCPA and GDPR have the potential to prevent new, innovative companies from going to market. It’s Huddleston’s contention that the hefty fines imposed by the CCPA will allow the bigger players to increase their market share, while smaller tech companies will be forced to exit the market due to burdensome compliance costs.

Privacy advocates: In states we trust

Pro-regulatory analysts fear that the tech industry doesn’t have consumers’ best interests at heart. As an example, Neema Singh Guliani, senior legislative counsel at the ACLU, is skeptical of any law that would wipe out consumer data protections at the state level. In an op-ed piece, Guliani posits that preemptive legislation from Congress would likely be a boon to the tech industry at the expense of consumers. Although Congress could certainly pass legislation that effectively protects consumers, Guiliani notes that consumer privacy protections have historically originated at the state level.

Requisite features: Consumer control, transparency, and accountability

Regardless of whether consumer data privacy is handled at the state or federal level, it’s clear that any laws need to contain the following three elements: (1) Consumers should be able to control what data is collected from them, either via opt-in or opt-out mechanisms. With an opt-in rule, companies can’t collect user data unless the users have granted them permission. With an opt-out policy, users must figure out how to opt-out of data collection, either through the app’s preferences or elsewhere. (2) Companies must be transparent about exactly what they’re collecting. (3) There must be adequate enforcement of the rules by the FTC to ensure companies are held accountable.

What does the future hold?

It’s quite interesting to see consumer data privacy protection at the forefront of public policy considerations. Former Democratic presidential candidate Pete Buttigieg made “right to be forgotten” a key part of his campaign. Similarly, Apple CEO Tim Cook has called for a “data-broker clearinghouse,” which would not only require all data brokers to join a registry, but would also allow consumers to track and delete their data.

Although many believe it’s only a matter of time before the US sees a federal data privacy law, it may be difficult for Congress to preempt the CCPA in the short term, especially given that California has 53 members of Congress. Nevertheless, the fact remains that Big Tech lobbyists are extremely active on the Hill these days, and federal consumer data privacy bills have already been drafted. As a recent example, Intel has met with several congressmen and written several drafts of a bill tentatively titled “Ethical Data Use Act of 2019.”

“As leery as I am about government regulation in general, it is now clear that we have reached a tipping point, where companies controlling a large portion of the world’s personal information have failed to protect it. In fact, we have a fox in the henhouse situation in that many of these companies’ business models are predicated on exploiting personal information,” said Raj Sabhlok, president of Zoho Corp. “As such, there is a need for regulation that would protect consumers’ personal data. Such regulations should not be overly burdensome on business or constraining free enterprise, which suggests that one overarching federal data privacy regulation should be enacted—as opposed to fifty state regulations.”

If a federal law does emerge, let’s hope it benefits businesses, innovation, and consumers’ privacy.

As Chairman of the House Intelligence Committee Adam Schiff recently declared at a congressional hearing, “Advances in AI and machine learning have led to the emergence of advanced, doctored types of media—so called ‘deepfakes’–that enable malicious actors to foment chaos, division, or crises. And they have the capacity to disrupt entire campaigns, including that of the Presidency.” According to the BBC, there have already been several instances of criminals employing deepfake audio to impersonate CEOs and facilitate wire transfers.

Despite its real potential for harm, deepfake technology is merely an advanced version of existing technologies, such as Adobe Photoshop and video editing software. With every new technology, comes a host of detractors who emphasize the potential effects. It’s important to remember that the technology itself is agnostic; it can be used to help or to harm. David Doermann, director of the AI Institute at the University of Buffalo, says, “There’s nothing fundamentally wrong, or evil, about the underlying technology; like basic image and desktop editors, deepfakes [are] only a tool. And there are a lot more positive aspects of generative networks than there are negative ones.” That said, deepfake audio and video do create cause for concern, especially when they are combined with social media platforms. 

When deepfake video is shared on social media, the files are shrunk down and compressed, making it exponentially more difficult to decipher that the file isn’t real. Attributions and trace evidence are destroyed while the synthetic media is spreading like wildfire. This can have serious side effects. Considering the possibility of a deepfake video going viral the night before an IPO, BU Law Professor Danielle Citron laments, “The market will respond far faster than we can debunk it.” Also, the proliferation of deepfake media will lead to what Citron calls “the liar’s dividend,” which is the idea that people will begin to doubt whether or not content is real, allowing liars to proclaim things they actually said were not said. Addressing this trust decay, Citron says, “We’ve already seen the ‘liar’s dividend’ happen in practice from the highest of the bully pulpits. So, I think we’ve got a real problem on our hands.” 

Software companies are leading the fight

In December 2019, Facebook, along with Microsoft, the Partnership for AI, and a group of academics, launched a “Deepfake Detection Challenge,” offering $10m in prizes to contributors who can help develop deepfake detection software. This contest wraps in 2020. There are a handful of software companies focusing on media manipulation detection as well, including Deeptrace Labs in Amsterdam, ZeroFox in Baltimore, TruePic in San Diego, and of course, the Department of Defense’s Defense Advanced Research Projects Agency (DARPA)’s MediFor (Media Forensics) team is also working vigilantly in the space.

Enterprises can protect themselves from the imminent threat of deepfake audio and video

Part of the solution will be to provide comprehensive AI education. Although legislators may require search engines and social media companies to identify and provide watermarks on synthetic media, we need to educate our own employees about deepfake technologies as well. Deepfake audio, in particular, is getting increasingly prolific; so it’s important for employees to be wary of any phone calls that don’t sound quite right. These calls could be social engineering attempts. As far as deepfake videos are concerned, they can be can identified by blurriness and changes in skin tone around the perimeter of the facial region. Also, be on the look for unnatural movements and lighting as well.

After Jerry Brown signed the California Consumer Privacy Act (CCPA) paperwork in June 2018, shock waves reverberated throughout Silicon Valley. Lobbyists at the Information Technology Industry Council, a Google-backed think tank, quickly went to work drafting proposals for a federal law that would supersede the stringent California bill.

Twelve states subsequently followed California’s lead and passed similar legislation, causing some of the largest tech companies, including Google, Facebook, Apple, Intel, and Microsoft, to clamor for federally-mandated consumer data privacy regulation. Although 15 bills have been proposed in the last year alone, as of September 2019, none have yet to pass. However, it’s only a matter of time before a federal data privacy bill passes. Businesses need to be prepared to make drastic changes to their data gathering and privacy processes, and determine if outside help is needed.

Looking to the future: a law on the horizon

The bills that have been proposed and turned down to-date have common threads running through them, so we can accurately deduce what a future federal data privacy law might look like. Below are the common themes that have appeared in the bills that were proposed but did not pass.

It will give citizens control of their data or the ability to opt out

Consumers want access to and control over their own data. The Data Broker Accountability and Transparency Act was put together in the wake of the Cambridge Analytica uproar, and it directly targeted data brokers – companies that collect consumer data and sell it to third parties. Additionally, this bill would allow US citizens to remove their data from corporate servers.

Another bill, the Consumer Data Protection Act (CDPA) called for the creation of a national “do not track” registry.

It will keep large corporations in check

The American Data Dissemination Act was introduced by Marco Rubio in January 2019 as another opportunity to supplant the current patchwork of state laws. In an effort to keep large, incumbent companies from dominating the space, Rubio’s bill called for the FTC to create exemptions for smaller companies. Creating more opportunity among competition should ultimately benefit consumers.

It will create severe punishments for data breaches

Aside from calling for the creation of a “do not track” registry, the CDPA also proposed data breach fines as high as four percent of offending businesses’ annual revenue, as well as 10 to 20 years of jail time for negligent executives. The bill also proposed hiring 175 more FTC employees to monitor the sale of private data.

The Corporate Executive Accountability Act, issued in April 2019 by Elizabeth Warren, would affect companies with over $1 billion in annual revenue. Like the CDPA, the bill calls for jail time for senior executives; however, the threshold for incarceration is quite high. According to the proposed bill, senior execs are only liable if a data breach is the result of illegal activity, and prosecutors must prove that these executives were negligent.

Companies need to be prepared for consumers to have more control over their data; they should expect more balanced competition, and to be held accountable if consumer data is left unsecured.

An opportunity for managed service providers

If the United States enacts a federal data privacy law, this change will provide an opportunity for managed service providers (MSPs). As we’ve already seen in Europe, many MSPs have taken advantage of the GDPR, opting to position themselves as experts in data privacy compliance. These MSPs essentially offer consultancy services, which can include providing clients with data protection officers (DPOs), technicians, and internal auditors. By encrypting data, patching software, and providing auditor checklists, these MSPs help businesses address their GDPR compliance issues.

When MSPs provide their clients with external DPOs, it helps to prevent business conflicts of interest from arising; for example, if a business were to have a sys admin or someone else doing double duty as a DPO, he or she might not want to change their everyday activities—even if it were required for compliance. Hence, it can be more beneficial for a business to use a DPO provided by an MSP than to use an employee from inside their own organization. However, it’s important to keep in mind that paying an MSP for DPOaaS (data protection officer as a service) doesn’t provide businesses with immunity from data breach fines.

Who is liable?

MSPs can open themselves up to fines, lawsuits, and reputational damage should a breach happen while they’re hosting a client’s data. However, if an MSP is solely providing their client with software or tips, the responsibility then likely lies with that client. Answers to questions around liability continue to be vague, with the industry paying attention to new precedents as they are set.

Ultimately, we are going to see a shift in two directions: 1.) companies using third-party advisors; 2.) companies owning and taking on liability. Companies and advisors will both be highly dependent on technology solutions to provide the necessary transparency and data security to keep up with future federal regulations. In addition, the solutions relied upon will need the right mix of intelligence and automation to course correct individuals and companies in the moment in response to regulatory changes. Picking the right technology vendor that can keep up with the rapid change ahead will be key.

Companies must start determining their technology stack, as well as their strategy for complying with the impending changes that federal regulation poses, including whether or not to utilize an MSP that specializes in data protection. While there will be a certain level of risk for MSPs, there clearly is a lucrative opportunity ahead for those who are willing to fill this gap. The question is whether utilizing MSPs’ services will become companies’ preferred strategy for dealing with the federal regulations that are on the horizon.

Disclosure: This article was originally published in SC Magazine

With strict data protection laws in place around the world (including GDPR and CCPA), it’s vital that the data protection officer (DPO) and CISO work closely together. Although part of the DPO’s job is to audit the CISO’s security policies, it is essential that the DPO and CISO have a good rapport. Essentially, CISOs are concerned with security and confidential data, and DPOs are focused on privacy and personal data.

The CISO examines security issues from a business and operations’ standpoint. While bolstering an organization’s cybersecurity posture, the CISO strives to ensure that all company information is securely processed. The DPO is primarily concerned with how the organization handles personal data. This can include data minimization, communication with data subjects, rights management, storage minimization, data collection, and data processing.

Data Minimization


One of the DPO’s main goals is to ensure that no unnecessary customer data is processed. If any personal data is processed, it should not be kept beyond a certain date (as per the commitment mentioned in the privacy policy), and customers must be informed about the nature of the data processing.

Data minimization involves storing less personal data, which shrinks the overall attack surface. This is important when it comes to the collaboration between the DPO and CISO. With the DPO helping to minimize the amount of collected data, the CISO is able to maintain a higher level of security.

For example, perhaps your organization issues a sign-up form that asks for an email address, phone number, and Social Security number. The CISO will mostly be concerned with how the data is protected. Conversely, the DPO will likely ask questions such as, “Why are we even collecting this information?” and “Do we need to process (store, use, or transfer) this data?” By asking questions like these, the DPO helps the CISO’s security team effectively — and proactively — protect data.

Create an Activity Register


In modern digital organizations, there are many data flows coming from a variety of different sources. By creating a register, the DPO can help the CISO monitor the various data flows. An effective activity register will answer questions such as “Where exactly is this information being used?,” “Who is using it?,” and “To whom is this data being transferred?” Again, the CISO is interested in this information from a security standpoint, and the DPO has privacy concerns.

During the creation of an activity register, assess whether the data is personal in nature. Sometimes, whether the data is personal depends on the context. For example, perhaps a customer only provides a company with her home address. If this home address can be traced back to the individual, then it’s personal data. Due to nuances like these, it’s helpful to have a DPO with a legal background.

Data Protection by Design


Another way that the DPO and CISO can effectively work together is during product inception. By working closely with an organization’s developers, the DPO and CISO can proactively build data protection into the company’s products.

For example, during the creation of essential and nonessential cookies, the CISO will have concerns related to security vulnerabilities, and the DPO will have privacy concerns. From a security perspective, the CISO wants to ensure that the essential cookies — those used for tracking logged-in sessions and providing user-related functionality — are protected. This way, no impersonation can occur.

And from a privacy perspective, the DPO will be concerned about nonessential cookies, such as advertising cookies used to display ads. The DPO must ensure that the list of cookies is displayed to the website users, and that users can opt out of some cookies without significantly degrading website performance.

Thus, close collaboration between the CISO and the DPO during the cookie creation process can be effective from both a privacy and a security standpoint.

Handling Breaches and Privacy Violations


Another instance in which DPOs and CISOs should work closely together is in the event of a data breach or privacy violation. Incidentally, these are often disparate events. For example, perhaps a customer is given a contact form, and the phone number is used later to sell him or her a product. If there was not a link to the privacy policy on the contact form, this would be a privacy violation, but not a breach. Alternatively, perhaps there was a data breach; however, only source code was stolen. This would be a data breach but not a privacy violation.

Nevertheless, to assess the situation, the DPO and the CISO should closely collaborate. This is especially important during a breach, as fines can incur if the company doesn’t alert authorities about an incident in time.

Impact Assessments


After a breach, organizations should conduct a risk assessment during which the DPO functions in an advisory role. In addition to auditing the CISO’s existing security infrastructure, the DPO should offer advice for the future. With the help of the CISO, the DPO can answer questions such as “Can an incident like this happen elsewhere?,” “How can we protect against this moving forward?,” and most importantly, “Should we be collecting this personal data at all?”

Conclusion


By working closely, the DPO can help the CISO secure data more efficiently by collecting only the most necessary data and keeping customers well-informed about the transfer and usage of data. With the DPO and CISO working together, the transfer of data from one place to another can be transmitted securely and legally, greatly reducing the chance of a security breach occurring and ultimately helping the organization save time and money.

Disclosure: This article was originally published in Dark Reading

Over the past few decades, AI has gone from science fiction to an integral part of everyday business operations. According to a recent report, “62% of organisations in India have implemented AI in some form, a figure which is not so far from the global figure (65%).”

Looking out a bit further on the horizon, a report predicts that by 2023, 40% of infrastructure and operations teams will use AI-augmented automation in enterprises, resulting in higher IT productivity. As companies proceed from narrow AI to general AI — and begin automating not only processes, but also decisions — it’s vital that AI tools explain their behaviour.

The importance of explainable artificial intelligence cannot be overstated; it is absolutely vital that AI tools justify their decisions by offering detailed explanations. If an AI tool fails to offer an explanation as to how it reached a given decision, users may lose faith in the tool altogether.

While implementing AI tools into your business, it is important to retrofit AI into your existing workflows. After processes are successfully automated, you can begin to automate decisions as well. Even if you have a 100-member team specializing in anomaly detection, computer vision, natural language processing (NLP), and other AI techniques, all AI decisions should require approval from a human—at least until you have fully honed the process. Ideally, one’s AI tools should be accurate at least 80% of the time, and for every single automated decision, your tools should offer an explanation, as well as confidence intervals.

Why is explainable AI so important?

In a recent report, Forrester notes that “45% of AI decision-makers say trusting the AI system is either challenging or very challenging.” Thus, there’s a need for transparent and easily understandable AI models. For all decisions made by AI, there needs to be readily available explanation.

Acknowledging this, you should offer pre-built explanations for all of your AI decisions. For example, perhaps you’re utilising NLP and chatbots to streamline processes for technicians; if a particular request is frequently raised and directed to the same sysadmin every week at the same time, the AI recognises this pattern, automates the process, and explains why it did so.

Through “explanation-ready” AI features, you will be able to effectively assist IT teams with a host of security concerns, including log management, insider threat analysis, user behaviour analysis, and alert fatigue management. And through AI monitoring tools, it’s easier than ever to predict anomalies, outages, combinatorial anomalies, and the root causes of outages. During all of these automated discoveries and decisions, an explanation for the course of action must be provided, along with confidence intervals.

Your robust solutions for DevOps and IT Operations can effectively use AI tools to assess past user behaviour and then ascertain whether an action is anomalous. While accounting for seasonality, changes in schedules and processes, and time of day, these AI tools effectively predict anomalies and outages, ultimately saving your IT teams copious amounts of time and energy.

As an example, perhaps your website monitoring tool notes that a web page loads slowly at the same time each week when it is accessed from a certain location. AI tools will acknowledge this pattern and automatically send a ticket to the web manager via your service desk software. By integrating with multiple tools, AI automates processes, saves time, and improves productivity.

Again, the important point to drive home is that the AI must be explainable. AI tools can suggest certain decisions; however, if these decisions don’t come with pre-built explanations, people will lose faith in the tools.

Disclosure: This article was originally published in Analytics India Magazine

Unsure about AI? Take our two-minute quiz for a clear readiness score Arrow X
x