SecurityMetrics Podcast | 15
Data Privacy Compliance: A Critical Moving Target
“A lot of people in the security world want to talk about security, not compliance. But you can’t help secure things if you don’t know what you’re supposed to be securing,” says host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA).
In this episode, NuSkin Data Governance Analyst, Gabrielle Harris (CIPP/E, CIPM, MSML) explains how security and compliance are permanently entwined, “Even though ‘compliance’ has a negative connotation and ‘security’ has a positive one, the truth is that compliance builds brand reputation and trust with customers. Protecting data is an ethical thing, and we would all hope that whoever is protecting ours is taking it seriously.”
With experience in over 50 markets, Harris brings a big-picture understanding, a positive attitude, and a tireless work ethic to privacy programs.
Gabrielle Harris sits down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) to discuss:
- Pervasive attitudes and pitfalls that can hinder GDPR, HIPAA, and CCPA compliance
- Critical points in your step-by-step compliance process that build rapport and respect, including whom to involve and when
- What you need to understand about the differences between security standards and privacy laws
Resources:
Download our Guide to PCI Compliance! - https://www.securitymetrics.com/lp/pci/pci-guide
Download our Guide to HIPAA Compliance! - https://www.securitymetrics.com/lp/hipaa/hipaa-guide
[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.
Data Privacy Compliance: A Critical Moving Target Transcript
Hello, and welcome back to the Security Metrics podcast. I'm Jen Stone. I'm a principal security analyst for Security Metrics, and I'm, super excited here today to talk to you about, data privacy.
I have, Gabrielle Harris with me today. She's from Nu Skin. Gabrielle, would you please, tell us a little bit about yourself and and, your relationship to to data privacy, how you know what you know, that type of thing?
Yeah. I'm excited to be here. I'm a certified information privacy manager through the IAPP.
I also have a CIPP e certification, which is certified information privacy professional in Europe.
I've been working in data privacy, data protection, and data governance for the last three years, working on GDPR compliance, CCPA compliance.
We're in about fifty markets that we have to work on privacy laws and regulations and focus on how to encrypt, protect data, work on data flows, data mapping. So we have kind of a robust, outline of all these different regulations and laws that we try and focus on how to be compliant, how to protect the really prized asset of individual's personal information. So that's a little bit about my background in data privacy.
That's awesome. And I love that that you are in so many markets because then you can speak to more than than just one, privacy regulation. And a lot of the privacy that we talk about, these are laws and regulations that that dictate the privacy.
And, one of the reasons that I wanted to have you talk to us today is that a lot of times we focus on the security because I'm a security analyst, and so we talk about security. But, it you can't secure things if you don't know what it is that you're supposed to be securing a lot of times, especially in, like you said, GDPR, the the Canadian or the the California, CCPA, the, HIPAA. These things start with privacy. And so sometimes I'll go into work with, people on their security, and they they haven't even identified their information yet. They haven't even identified what they're protecting.
And so I'm super excited that you're here to talk to us about privacy because that helps people focus in on what is the important thing that we're even putting the security on.
Yeah. From my end, I think I often think of data governance. You really wanna build that foundation of knowing where all your data is, where it all lies, but then you really have to focus on how to protect that data, that data protection aspect, and know what's sensitive, what needs to be confidential, what needs to be restricted, and how to really secure it. But then you have to know all of the different laws and regulations and how to comply to all of those. And so in my mind, those three functional areas, tied with information security obviously, have to really all go hand in hand. Otherwise, you're going to really have a lot of gaps that are gonna introduce a lot of risk that you're gonna have to mitigate down the line.
Excellent point. So let's say that somebody is new to protecting their information. Say that they suddenly realize, hey. GDPR applies to us or, the California protection or HIPAA.
What's the first step in in, moving towards compliance? And and before we talk about about that so we're going to talk about, privacy and GDPR compliance, privacy protection law compliance. And a lot of times, especially in the security world, people say, I don't wanna hear about compliance. I wanna hear about security.
Because I think that there's a disconnect. I think that people don't understand. Compliance is the mechanism by which security is, enforced.
So so when we talk about compliance, really, we're talking about do you have the things in place to protect your data? And so I don't think compliance is a bad word. It it, but but it sure does make a lot of people upset. So from your perspective, do do you do you run into that as well from your position?
Yes. Unfortunately, I think that compliance is is a curse word in many functional areas. I do think that, just like you said, security and compliance have to go hand in hand, and I think sometimes security can have a positive connotation. We're keeping things secure, and compliance unfortunately has a negative connotation a lot of the time.
But I think that complying to a law or regulation doesn't have to be seen as a negative thing, it really is just another way of protecting and securing your assets, which a lot of the time in privacy is personal data, personal information, but the idea that we're building brand reputation, we're building trust and loyalty with our consumers because we're doing the ethical and responsible thing of protecting and securing their data, to me there's ways to view it in a more positive light, but definitely I've encountered that, oh, here comes compliance, here comes privacy compliance, the same as here comes internal audit, these things kind of the adverse services side of the industry, it's definitely something we encounter and have to kind of work to, you know, change that image because it's an important thing that isn't going away.
If anything, it's just constantly increasing.
Yeah. Yeah. And and especially from the mentality of a lot of the IT and security people and myself. You know, I was so I was at the gym yesterday and, went to go pick up something, and my coach said to me, oh, don't bump your head.
And I was like, don't tell me what to do. But so compliance feels like that. Like, here we have a law telling us, hey. You need to protect these things for good reasons.
And and our some of us, our knee jerk reaction is quit telling me what to do. But Yeah. It's important. Get behind it.
And then suddenly, it's you driving it and not an outside source driving it. So if you have, a new journey ahead of you to to achieve GPR, to achieve one of these, privacy compliance, HIPAA is right in there with it. What's your first step that you recommend?
So my first step that I recommend is assembling your sponsors, your champions, the leads of the project, kind of a task force. This can include members of legal, security, or if you have actual privacy experts or people that are willing to become that, whoever is really going to be the subject matter expert of that current regulation, whether it's GDPR, CCPA, or HIPAA, like you mentioned, Thailand's PDPA, whatever regulation you're trying to currently become compliant towards, really assemble that task force together, and start that at the very, very beginning and decide who's gonna dedicate time and effort and resources to really focusing on that regulation.
So you've got a task force, and, typically, you'll have somebody who's, kind of leading that or who is the the executor bringing all of the things together for that task force. What if they are super new to data privacy? What's what should they be doing?
Yeah. That's a great question. I think that starting with talking to other privacy professionals is really great next step. See what works for them, what didn't work for them.
As a general rule, I think privacy professionals are really friendly. They like to network, they like to find other people in the industry that they can bounce ideas off of. So joining up with them, don't be afraid to ask dumb questions, because they're friendly, because a lot of regulations are new, uncharted territory, don't be hesitant to just ask dumb questions, ask them again and again, and ask different people, get different perspectives. There's also the IAPP, which is the International Association of Privacy Professionals, joining that is a great resource.
There's white papers they put out, webinars, tons of documentation about the different regulations, about the continual interpretations of those regulations, which is always really helpful.
As well, through the IAPP, there's knowledge net chapter, so you can find your local knowledge net chapter of more privacy professionals to network with, which I think is a great asset.
And along those same lines, on LinkedIn there's so many different privacy professional groups. Once again, going into those groups, throwing out your questions, you'll also find a slew of opinions on what vendors are beneficial, what vendors aren't, you'll just get a ton of information, and you can start to get those patterns of, okay, I'm hearing the same information again and again, and it's building that foundation to help you, especially if you're starting from scratch. If you're new to privacy in general, you wanna start to build that kind of network, that group of people that you can constantly throw ideas around, discuss with, collaborate with, and I think that makes a huge difference in helping you have success down the road.
And and you also mentioned that you had a couple of certifications. Did you find those helpful to you personally to to get certified?
Yeah. So I those certifications are through the IAPP, the International Association of Privacy Professionals, once again, and I think that those make a huge difference. So the CIPM specifically, the certified information privacy manager, helps you build a foundation in building up a privacy program in general. So it helps you cover a wide array of different privacy knowledge, how to mature a privacy program and how to understand, okay, HIPAA covers health information, GLBA covers financial information, you know, these different aspects across the board.
APEC is in these markets, in these countries, and this is how I need to apply different regulations and different ways and how I can mature my organization's privacy program in a way to take it from really ad hoc to optimized.
And I think for me that was really beneficial, especially when I joined our department, we were just really starting out and we had to really build it from the ground up. And then the CIPP is focused on Europe and GDPR specifically and how to really, implement those specific laws and regulations and having a really deep understanding of GDPR for us where we're in the EU specifically is really beneficial.
But even if you're not in the EU, the CIPPE helps you understand so many aspects that are still applicable to CCPA, are still applicable to Thailand PDPA because GDPR in the privacy realm is kind of the gold standard that so many states or countries are trying to replicate.
So I think having those certifications really helps you kind of determine, okay, this is what privacy is all about. This is what matters in privacy. This is what matters to the individual. This is what external organizations are advocating for in those privacy discussions. And so then you're able to go to your board, go to your executive committee, and advocate for resources because you can speak the language of privacy in a much more effective way.
Excellent. So you've put your your team together. You've got the the training. And then what's the next steps in this, in this journey?
So what I think is really important is after you have this team with this established baseline knowledge, is to really sit down and establish your mission or vision of that project and what it's really going to be. So what I think often happens is you have this task force, you have everyone come in with their knowledge, with their opinions, but someone in the group's gonna think, oh, we hire an external vendor and we roll with it and we put it in their hands. They're gonna know what to do better than we do. Someone else is gonna think, no, we have a great DevOps team, we have a great legal team, we're gonna do it all in house.
Or someone's gonna think, well, based on budget constraints, we should we should handle things differently. So sitting down as a task force and really getting aligned on how you're going to execute compliance and what your mission and vision is going to be is really strategically necessary, in my opinion. Understanding the gaps of what your organization has, whether it's budget, resources, timeline, if you're up against a really significant deadline, for example, GDPR has been in effect for a couple years, and if you feel we're really behind in our compliance, that's different conversation than if you're looking towards a future, regulation coming down. So I think that looking at what the authority of your task force is gonna be, if you can actually influence, the scope and the sprints of certain teams, or if you don't have that degree of influence, doing kind of that in-depth analysis so that task force is really aligned is really important.
I think something that, our organization has come up against and I've heard of other organizations encountering is walking away from that that kind of group conversations and not everyone being aligned. And then you go to larger group conversations or you go to the management committee and everyone kind of giving different expectations.
We'll be compliant in two months. We'll be compliant in two years. You know, it's gonna cost us x amount of dollars. If if you don't have that alignment from that smaller group, it's gonna be really disastrous once you get to that larger group.
That makes a lot of sense. So you've assembled the group. You have a clear mission. You're aligned on how you're going to approach the the project of of data privacy.
Then what do you do?
So then I recommend assembling the complete team. So data lies in every corner of your organization, whether it's finance, HR, technology, throughout everywhere. So I think it's really important to make sure that everyone has a voice at the table and every functional area is represented.
So I recommend after you have that clearly defined, you have your smaller group of really the kind of authority leads, then you assemble the full team.
It's really important to have that, those first two steps already done because too many chefs in the kitchen can be pretty problematic, but then assemble the full larger team so everyone can feel like they're represented and they can really be the subject subject matter experts in, their their specific data areas.
I and I love that idea. Sometimes I'll work with groups that say, oh, it's it's just too time consuming to involve everyone. We don't wanna have, you know, all of these voices at the table, and yet they don't have enough information on their own to gather the information. So sometimes, from a security perspective, I get only to talk to the IT and security team.
So when I start out, usually, I'll say, okay. Tell me about your data flows. What is the and depending on which type of data they're trying to protect, where where does it live? How does it flow through your systems?
But they don't know that because they don't know the business processes. And so the the only way to get that is to actually speak to everyone who has something to do with the processes of how that information is taken in and how it's processed. Once you have it, where it's stored, whether people keep it on their laptops or whether it all goes into a centralized system on a on a server somewhere.
All of these things, not one person know or one person doesn't know all of these things at the same time unless it's, like, a an extremely small organization.
Yeah. Definitely agree. I think that so often assumptions are made about the data that, well, I tease over the database, so they know all the ins and outs, but I mean, really, there's hard copy data, there's unstructured structured, and all of that comes into the regulations of GDPR, CCPA, etcetera. So, I mean, I agree. You really have to have those conversations in order to have meaningful quality data maps and data flows.
So so what are some of the the techniques that you can use in those, in those conversations with the team?
How do you share that information in a in a successful way? Or or is there more than one way to to share, information?
Yeah. So one thing that we kind of found through lessons learned is that one great approach is to kind of have an initial meeting where you invite representation of those different functional areas, but it's really important to recognize who you meet with initially might not be who you're actually going to continue to work with. So some teams will know right away, this is the data steward who always works on this type of project, who knows the data inside and out, who's familiar with the data flows, and we're gonna send them from the get go. Other teams, they have a VP or a director who wants to know, I wanna know what this is all about. And so they wanna go from the initial onset, but they're gonna hand off that project.
And then other teams, they have a project manager or product owner who facilitates kind of the management of the work, but they're not gonna really be the hands on person either. And so we kind of made the mistake with GDPR that initially we just kind of sent out this call and we thought we did such a great job, and we're gonna teach everyone about GDPR, and we're gonna explain everything.
And so we have this great, you know, robust meeting. We go into all this in-depth information only to have half the people drop off, get replaced with another half of people, and let's start over and explain it again. And there's, you know, the handful of people that have been there from the beginning that, you know, by the time you go through your kind of your fifth iteration of what GDPR is, they just think, if you tell me one more time what this is, I'm gonna go crazy. And so a couple things that we realized is the initial meeting really should be more explaining the scope of the work.
Having everyone come, this is, you know, what we're asking. This is the bandwidth that we think will be required, the scope of the work. So who on your team do you think is best for that?
And then once you get those appropriate counterparts and stakeholders, then one thing that I would recommend is kind of documenting those context trainings in ways that are recorded or through PowerPoint because you're still going to have handoffs. You're still gonna have turnover. You're still gonna have things that come up that you're gonna typically compliance is a long haul project, right?
So you're gonna have people that are gonna come six months into the project and they're gonna be asking questions that it's great for them to ask, but you don't wanna be starting at square one, that you start to lose other people's attention and have them check out. So if you have all of this context training recorded or aligned in a way that you can just hand it over to them and then follow-up, it's gonna be much more efficient. And those were some great lessons learned for us that when CCPA comes around, it was much easier to, okay, this is how we'll go about it, right? To reiterate that kind of more effective, handing off of information.
So my recommendation would be have initial meeting and recognize most people in that meeting might not actually be the pill that do the work, and then context training meetings, definitely record those to disseminate them in a more effective way.
That seems super effective. I'm glad you went through this twice so you can here's what works.
So then I think the next step is to figure out where the the data actually lies.
Yeah.
And one big recommendation I would suggest with that is to perform those initial data inventories, data mapping in one on one sessions, if at all possible, with those key stakeholders at the beginning.
It definitely is a greater time investment to meet with them one on one and to go through that, but I feel like that brings great gains down the road.
I found that taking the time to meet one on one really helps to develop that rapport with those data stewards, those key stakeholders, and that significantly will change that relationship, which is a key relationship for any type of privacy operation.
I think in most organizations, privacy work, compliance work is an add on. I think it's really rare for there to be dedicated privacy analysts or technical privacy related compliance work that just this is fifty percent of my job that I helped get compliant. I just think that's a great wishlist, but I don't think that's very realistic. And so I think usually privacy asks are on top of already scheduled work. And so I think it requires, using a lot of diplomacy and persuasion to get that work prioritized.
And I think if you take the time to really invest in that relationship and meeting one on one, when you originally do those data flows and those data maps, you're able to convey the importance of privacy. You're able to answer questions that maybe they weren't comfortable asking in that larger group setting, and you're able to build that mutual respect and to understand there are other projects going on, so how you can develop realistic expectations of timelines and prioritization.
And I think it just really develops a greater resource because, for us at least, these are the same people that we depend on for data subject right requests to be executed. So the right to be forgotten, the right for portability, as well as these are the people that know their data inside and out. So when there's new data coming in, that we also need to document for article city reports, for new business processes that we want to embed privacy by design. These are the people that we have to rely on to be our ear to the ground, to be our frontline, to help us and really be our privacy champions throughout the organization.
So taking that time to meet with them one on one to really get their buy in from the get go brings about such a great reward down the road. So I think that I'd really recommend, even though it might be thirty different meetings, thirty different people, I really think that it's really important to take that one on one time with them at that beginning if at all possible.
So these people who who it's almost an add on to their job, and and and it kinda feels like, oh, this is one more thing you want me to do. You're talking about making their champ the privacy champions. Does it affect how they do their work after they understand it? Do they ever does it ever become more embedded into the work? So instead of being an add on, it's just part of their workflow after after this work that you do with them?
Yeah. So we found that as these data stewards, really become privacy champions for a lot of them, it becomes really second nature for them to notice, hey. There's there's privacy impacts to this process I'm working on, or some team has requested this data source to fulfill this project, and there's privacy principles that that impacts. So there's use and purpose limitation principles where if we collected this data for this purpose, we can't necessarily add on this other point for these different implementation implications of legal basis.
Right? Right. And so these data stewards increasing their understanding, it really becomes kind of second nature for them to raise those red flags or for them to ask those questions, not even having to loop us in every time, which, number one, in our experience, I think lost time gives them greater fulfillment. Most people wanna be constantly learning in their jobs is at least my experience.
Sure.
Yeah.
They also, I think most people are mindful of what would I want someone to do with my personal data? How would I feel if someone was asking for more, doing more, not protecting it? So I think most people can empathize or relate very naturally.
So I think that most people like to know that as an organization, we're mindful of that and like to contribute to that effort. So I do think that it really, even though it can be an add on to their current job, it becomes natural the more educated they are in the realm of privacy.
So, doing the work with them and and driving towards compliance, do you ever become a hundred percent compliant? Is it is that ever is there ever, like, oh, we made it.
Or So that's something that we, so we love to joke about that because we've gone to numerous privacy conferences, and we'll, you know, sit at a table networking, and there'll be, you know, some people that will very adamantly kind of boast to brag, we're one hundred percent GDPR compliant.
And we always kinda chuckle because, in my mind, data is a living organism, and compliance is just a moving target. And so, yes, one hundred percent compliance is always always the target we're aiming for, but there's always new interpretations of the same regulation. There's always, at least in our realm, new data coming in. There's always new business processes, new technologies that require new article thirty reports, new, privacy impact assessments. There's just constantly work to be done that I never, in my mind, to think I'm one hundred percent compliant is to think I'm stagnant. And so in my mind, there's always a hustle to be done, always work to be done about improving and refining our compliance.
So that's kind of my other recommendations that you always should be refining, and you should always be, just constantly auditing and looking where can we improve even if it's just from an efficiency standpoint. Right?
As a business, we we could do things smoother. We could do things more easily. We could, improve our time spent on the project just to ease our lives.
I just think there's always ways that we can analyze, are there new data collection points? Are there new data stores? Is there a better way for us to document our data flows that just we would be able to access for greater data quality. I just think that there's ways to be data compliant and there's ways to just constantly be improving the impact your privacy notice, the impact, the need to notify individuals.
So in my mind, a living organism, can it ever really be done? No.
Yeah. And I think that that where where some people kind of get confused about, how to be compliant against a privacy law or regulation is they're comparing it to a security standard usually. So a lot of people are are familiar with PCI certifications.
So PCI is set up as a standard, by a certifying body. You go and check your list against what they have in place, and you can certify against that standard. So, yes, you can say, here's my signature. You are certified PCI compliant.
Yeah.
But laws aren't like that. Laws give you a set of things that are worded really weird to begin with.
Right. Yeah.
But and even where it is clear, you have some guidance. But every time the the law every time it's tested under the law so every time somebody is perhaps not compliant and has to go and either work with, the the governing body for it or, go to the court about it.
Whatever the judge eventually says and signs off in in their in their summary becomes part of that body of law. It it adds nuance to what's already there. And so you can get a degree of assurance that you're compliant against, a regulation, or that you are performing in a in a GDPR compliant manner.
But to say we are compliant, there's first of all, there's no certifying body that says that. Yeah. And and second, the the the nature of law is that it is constantly under scrutiny and constantly being modified by the way we live and test the law. Right?
So I think this is one of the reasons why having a privacy officer is actually critical for organizations that have to deal with privacy laws, because they are changing. They are you have to actually be on all of these, you know, lists of, hey. Guess what happened today? And guess what what this, settlement came out and said or what these new guidelines said.
Right? So they're the way we look at it is slightly different than looking at a certification that gives us a checklist.
Yeah. Exactly. I mean, there's the DPAs, the data protection authorities in Europe are constantly reinterpreting. If there's a data breach that results in a fine, then everything's reinterpreted.
I mean, couldn't agree more with what you said. It's just it's constantly the nuances of interpretation change what you need to do with the regulation. So you just have to be on your toes, and you can never rest on your laurels that we're done. We've checked the box.
We're good.
For sure.
Alright. So in that effort to continually improve, are there any other suggestions that you can give people about how to make sure they are constantly reiterating to stay current with the the privacy regulations?
Yeah. So I think that it's great to plan on a regular cadence to go through your data flows, to go through the privacy impact assessments that you've done, and to just kind of reevaluate to take one thing that's been great for us is that using GDPR as kind of a gold standard, but then reiterating the same process when we go through CCPA compliant helps you realize, okay. Here's here's some things that we can improve on because now we're reintering with CCPA. Same thing when we go through Thailand PDPA.
As we reiterate for that, we realize, okay. Here's some ways we can improve. So as you reiterate with different regulations, you realize some ways to improve and to, increase your gains. I also think there's so many, privacy blogs out there by different law firms, different organizations, different vendors.
Subscribing to blogs are just a great resource to help you stay up to date on those interpretations like we were talking about to help you realize, okay, this is this is what just happened with this company, so let's make sure we're strong in that area. Let's fortify, let's do everything we can to not fall prey to that same weakness and that same vulnerability.
And I think that doing this exercise, whether it's once again, assembling the same team, meeting one on one with those key stakeholders, going through that same those same few steps, meeting together the tax task force, aligning again, even though you feel like, no. We we already did that with GDPR. Do it again with GDPR, and going through the same steps helps you make sure, okay, a year later, do we still feel confident in our approach? Would we still go about things the same way, or would we change everything? And that gives you a really good make sure that you feel confident that if a regulator was to come knock on your door, you would be confident in what you offered them.
Right. That's the last thing that you wanna have happen, but you definitely want to be in a good position if it does happen. And I know that Nu Skin, doesn't fall under HIPAA, but HIPAA is the same way where if a settlement is reached, they will publicize it. They they they put the information on the HHS website.
We're not supposed to call it the wall of shame, but if you go and type in HHS wall of shame, you'll find out, the details on on things that are affecting an interpretation of the law, given additional guidelines to people who have that particular privacy law on their plate. So, lots of great places to find the information.
Well, Gabrielle, it has been so great to have you join us here today. I really appreciate, your education on privacy and and hope to talk to you again in the near future.
Yeah. This has been great. I really appreciate it. Thank you for the opportunity.
Alright. You take care.
Thanks.
Thank you for joining us at the Security Metrics podcast. I hope to see you again. Thanks for watching. To watch more episodes of Security Metrics podcast, click on the box on the right. If you prefer to listen to this podcast, it's available on all your favorite podcast platforms. See you on the slopes.
