cmacc gdpr server en - 20170606

14
CMACC SERVER – A CONTRACT SERVER FOR GDPR

Upload: marc-dangeard

Post on 22-Jan-2018

59 views

Category:

Technology


3 download

TRANSCRIPT

Page 1: Cmacc   gdpr server en - 20170606

CMACC SERVER – A CONTRACT SERVER FOR GDPR

Page 2: Cmacc   gdpr server en - 20170606

Cmacc Transact  MarcDangeard◦ Engineering(Supaéro)andBusiness(HEC)background◦ Entrepreneur(25yearsinSiliconValley)◦ Oracle,Sony,manystartups

 CmaccTransact◦ Createdin2016todoaPOCwithCaissedesDépôts◦ Cmacclanguage/server,basedonCommonAccord

CMACCSERVER-MAY2017 2

Page 3: Cmacc   gdpr server en - 20170606

Personal data from the very first interacCon

CMACCSERVER-MAY2017 3

Whathappensnext?Whatdataiscollected?How?Whereisitstored?

Howlongisitkept?Whohasaccess?

PaulvisitsMyCorpwebsite PaulagreetoTermsofUse(withoutreading)

Page 4: Cmacc   gdpr server en - 20170606

Data in the enterprise: many silos

CMACCSERVER-MAY2017 4

?Manysilos,coordinatedaroundlinearprocesses

Noeasydataprivacymanagement

DPO

LouispreparesaTermsofUsedocument

Bernarduploadsthedocumentonthewebsite

Jeannesendsmarke\ngemails

Marieshipsproducts Pierrecollectspayments

MSWorddocumentinafolder

Cookies Emailcampaigns+CRM ERP+Shippingso^ware FinancialsystemLEGAL IT MARKETING BACKOFFICE COMPTA

Page 5: Cmacc   gdpr server en - 20170606

GDPR – May 25th, 2018 Informedconsent

Accesstodata,righttobeforgoaenPortability

◦  Structuredformat,datatransferreddirectlyfromoneprocessortotheotherifpossible

◦  Tomakeiteasytoswitchserviceproviders

Privacybydesign/bydefaultCulture,process,butalsotoolsto:

◦  Informusersoftheirrights

◦  Managetheserights(access,changes,righttobeforgoaen)

◦  Renewconsentsasneeded

CMACCSERVER-MAY2017 5

Page 6: Cmacc   gdpr server en - 20170606

What is GDPR was an opportunity to re-focus the enterprise around data?

CMACCSERVER-MAY2017 6

Page 7: Cmacc   gdpr server en - 20170606

What if the DPO could manage all enterprise data with a simple tool?

CMACCSERVER-MAY2017 7

Page 8: Cmacc   gdpr server en - 20170606

Contract server

CMACCSERVER-MAY2017 8

VSCodeplugin

Opensourceproseobjects

AIcapture

Databinding

Proseobjects

Contractserver

Webpagegenera\on

•  APIforcustomUI•  APIforContractLifecyclemanagement

•  APIforSmartContracts

PDFgenera\onPrivateproseobjects

Page 9: Cmacc   gdpr server en - 20170606

Benefits (GDPR)  ManageTermsofUsetemplates

 Mul\-juridic\ons

 Mul\-lingual

 ManageUserInforma\onno\ces

 ManageallcontractsthatareimpactedbyGDPR(BCR,sub-contractors,etc.)

 Managerelatedvisualinterfaces

CMACCSERVER-MAY2017 9

Page 10: Cmacc   gdpr server en - 20170606

An improved user experience

CMACCSERVER-MAY2017 10

PaulvisitsMyCorpwebsite Hegivesaninformedconsent,thankstothevisualcluesprovided

ontopoftheconsentform

Paulobject

MyCorpobject

TermsofUse

source:DisconnectPrivacyIconsserverviaLegaltechdesign.com

Page 11: Cmacc   gdpr server en - 20170606

CMACCSERVER-MAY201711

DPOLEGAL

Paulobject

MyCorpobject

TermsofUseobject

Usersobjectsdatabase

DataStore

Managementofconsentsandothercontracts

Groupobjects

Partnersobjects

Salescontractobject

ProseObjectsdatabase

An architecture for GDPR

Page 12: Cmacc   gdpr server en - 20170606

A “data store” to manage all data

CMACCSERVER-MAY2017 12

Consentsarecapturedfromthewebsiteanddue

processcanbedocumented

Manageeasilyupdatesresul\ngfromchangesininternalpolicy

orchangesinthelaw

Userscaneasilychangetheirchoices,updatetheirconsentorthe

relateddata)

Salescontractswithpaymentandshipping

informa\on

Deliveryreceipts,no\cesofclaim,

etc…

Invoices,Statements

Asystemtomanagealldata,includingUIfortheuserstoaccesstheirdata,andfortheDPOtohave

aviewofhowdataiscollectedandmanaged

LouispreparesaTermsofUsedocument

Bernarduploadsthedocumentonthewebsite

Jeannesendsmarke\ngemails

Marieshipsproducts Pierrecollectspayments

Cmaccproseobjects Cookies Emailmarke\ng+CRM ERP+Shippingso^ware FinancialsystemLEGAL IT MARKETING BACKOFFICE COMPTA

1 2 3 4 5 6

DPOContractsserver+DataStore

Page 13: Cmacc   gdpr server en - 20170606

From compliance to business opportunity

CMACCSERVER-MAY2017 13

Asystemtomanagedataprivacy,including:•  Manageusersrela\onships

•  Build tools to collected an informed consent, withvisualcluesandabilitytomanagedataprivacyrights

•  Buildtoolstocollectconsentforminors

•  ManageallcontractsimpactedbyGDPR

•  Adatastoreastheonesourceoftruthforuserdatawithintheenterprise

•  ThisdatastoreusedinternallycanbeopenedwithanAPItobecomeadatastoreforendusers

•  API and autoriza\on management so that the next\meauserwantstopurchasefromAmazon.com,shecan provide a link to the data store rather thanhavingtoprovidepersonalinforma\ondirectly.

COMPLIANCE OPPORTUNITY

Page 14: Cmacc   gdpr server en - 20170606

Cmacc server – a contract server for GDPR

 ManageTermsofUsetemplates

 ManageUserInforma\onno\ces

 ManageallcontractsthatareimpactedbyGDPR

 Managerelatedvisualinterfaces

Cmacc Transact � HEC Paris � Supaéro

[email protected]+33(7)68112325

Databinding

Proseobjects

Contractserver

CMACCSERVER-MAY2017 14