40th Annual Data Protection Conference

40th International Conference of Data Protection and Privacy Commissioners

Reflections on the 40th Annual International Conference of Data Protection and Privacy Commissioners

Guest Post by Abby Moscatel

It’s been about a week since Rafael and I returned from Europe, where we attended the 40th International Conference of Data Protection and Privacy Commissioners at the European Parliment’s Hemicycle in Brussels, Belgium.

The thought leaders posed the single most important question facing us today: What kind of world do we want to live in? You see, we are at the tipping point where the internet will know more about us than we know about each other, or even ourselves. And yet there is no recognized universal ethical and moral code for how we deal with all of the data that is being collected about us. How do we handle it? Right now, Data Kings hold the cards. Companies provide free services to gather our information.

Apple CEO Tim Cook was correct when he said that we are now in a time where our data is being weaponized. We see it in our news feeds. No matter what you believe, you get socials and content that affirms your position, and makes the opposite position something you must resist.

Tim Cook at the 40th Annual Conference of Data Protection Comissioners

Hong Kong artificial intelligence researcher Pascale Fung was also right when she said that unless we get all of the world leaders together, it won’t matter.

Now, we have the GDPR. And, here in the US, we are starting to get patchwork legislation, like the California Consumer Privacy Act, heavily resisted by Big Tech in favor of a federal privacy law.

I want to live in a world where I own my data, control access to my data, and where I can delete my information. If a company or individual breaks a law, then I want a private right of action. Most importantly, I want to live in a world where we have a universal agreement on digital ethics.

What kind of world do you want to live in?

The Olympics of Privacy in Brussels!

Debating Ethics: Dignity and Respect in Data Driven Life, the 40th Annual Conference of Data Protection and Privacy Commissioners

Two Americans walk into a EU Privacy Conference…

Just a few weeks ago, a colleague reached out and reminded me “the Olympics of Privacy” were being held at the EU Parliament in Brussels in late October, and also if I’d like to attend. Well, how the heck am I supposed to turn down an invitation like that? After all, this is the year of GDPR, the NYDFS, the new California Privacy legislation and the ICDPPC has leaders like Mark ZuckerbergSundar Pichai, Tim-Berners Lee, Jagdish Singh Khehar and even the King of Spain all lining up to share their thoughts.

We want to stimulate an honest and informed discussion about what digital technology has done and is doing to do to us as individuals and as societies, and to consider future scenarios. We want to better understand the impact of technology on people of all generations, in all parts of the world, including the way people think, interact with others, develop their opinions, create art and write, how they buy and sell and how they participate in civic life.  – Privacy Conference Statement

Mark and Sundar are likely showing up because they realize the stiff penalties now associated with data security and privacy violations and the rest of the speakers realize that we are on the cusp of a digital and ethical revolution of sorts, one which will affect generations to come. In fact, Debating Ethics: Dignity and Respect in Data Driven Life is probably the most important privacy conference of the 21st century. My wife Abby Moscatel, an attorney and ethicist heard about this lineup and quickly said, yeah… I’m coming with you to this one!

So let’s have a look at the incredible schedule they’ve put together this year…

First, the conference is going to be opened up by Giovanni Buttarelli, the European Data Protection Supervisor. Below is his speech on the state of privacy from last year. According to the program, “the Supervisor will welcome participants to the conference and set out the strategic importance of defining a truly global digital ethics to the future of data protection, privacy and respect for individuals and groups in the decades to come.”

Next, the public conference is going to be split into 3 parts: Our Common Digital Future, Right Versus Wrong and The Digital Dividend. In Our Common Digital Future, Maria Farrell will help us explore at how digital technology has brought us to where we are and gives some insights on our future, including takes on augmented reality and deep fakes. Can’t wait to explore these trends.

Maria’s discussion is followed by a keynote address by one of the pioneers and creators of the internet as we know it, Sir Tim Berners-Lee, who plans to address ethics and the internet. What a great way to move onto the next discussion which will address the role of ethics in human society, directed by Anita Allen, a notable Professor of Philosophy from UPenn. I love how the EU has selected an American to make this contribution to the conference and set the stage.

OPENING PRESENTATION: WHAT IS ETHICS? European Parliament Hemicycle
Anita Allen, Professor of Law and Professor of Philosophy, University of Pennsylvania
What is the role of ethics in human society? How has it evolved over time?  What are the origins of autonomy, dignity and respect in different cultures? Who defines ethics and whose interests does it serve? What is the relationship between ethics and law?

The next segment, Right Versus Wrong, opens with a panel of renowned ethicists and scholars who will discuss human dignity, economic interests, healthcare and interactions between humans and machines.

RIGHT VERSUS WRONG: DISCUSSIONEuropean Parliament Hemicycle
A panel of renowned ethicists and scholars will expand the topic of ethics in regards to the notions of human dignity, economic interests, work relations, scientific progress, healthcare as well as the interaction between humans and machines.

And finally, the conference will wrap up with discussions around what organizers are calling The Digital Dividend, with a message from His Majesty, The King of Spain Felipe VI. Following that we’ll have the pleasure of hearing from Jagdish Singh Khehar, the former Chief Justice of India! Can’t wait to see this guy. The conference then will have a message from Sundar Pichai, Mark Zuckerberg and Erin Egan, followed by a second group of experts discussing technology and behavior. One of the last keynotes will be from Guido Raimondi, President of the European Court of Human Rights.

The conference is then followed by a gala at Autoworld and the next day conference attendees are treated to a special session of the EU Parliament and a lunch. If you’re attending the conference, please reach out to us because we would love to get together to discuss and share ideas and thoughts about what this brave new world might bring!

Last date to register is October 15th!

Navigating The Global Digital Economy – An Interview with April Dmytrenko, CRM, FAI

Seventh in a series of in-depth interviews with innovators and leaders in the fields of Risk, Compliance and Information Governance across the globe.


April Dmytrenko - Information Governance Perspectives

April Dmytrenko, CRM, FAI is a recognized thought leader in the field of information management, governance, compliance, and protection. As both a practioner and consultant, she works with global organizations on key initiatives and best practice approaches for the enterprise; developing sustainable solutions; integrating legally compliant programs focused on information/digital assets; motivating and facilitating multi-disciplined groups to collaborate on achievable goals; and building strategic partnerships with internal and external teams. She serves on industry action committees and governing and editorial boards, and is an active industry speaker, trainer, and author. I had the pleasure of sitting down with April this September to discuss privacy, the role of industry associations and key concerns for leaders navigating the global digital economy.

April, almost five years ago I asked what the next big frontier would be for those of us managing data, and more importantly where the jobs would be. You wisely predicted that privacy would be on the horizon. Well we now have a number of legislatures drafting regulations and CPO positions can’t seem to be filled quickly enough. Do you believe there is still time to enter this emerging field and make an impact?

Right now we are experiencing an amazing transformation of the business environment based on many things but particularly the evolution of technology and the global digital economy. It is indeed an exciting time but we are acutely “headline news” aware of the impacts of compromised data security and privacy, including financial impact on brand and reputation, litigation, and the overall burden and distraction on the business. The exponential growth rate of incidents of data theft, damage, loss or inadvertent disclosure continues to expand not only in frequency but scope, and complexity. While privacy concerns gained attention over 100 years ago, and became topical about 15 years ago, it is still truly in an infancy state. Privacy offers IG professionals a rich and important opportunity to expand their leadership or advisory role in maturing a unified approach to protection, compliance with laws and regulations, and incident response and recovery.

April Dmytrenko - Governance - Not Taking Risks
Courtesy ARMA International

In your role as a fellow of ARMA International, you’ve helped to connect organizations with practitioners who truly understand the discipline and benefits of Information Governance. How has this evolved over the years and what steps do you think organizations like ARMA and the ICRM need to keep taking to remain relevant?

This is a great question as the core IG professional organizations have been dealing with an identity crisis for some time, and still struggle to have a clear and concise “elevator speech” on mission and value. IG, while it has a wide breath, has many in the industry confused, and still is a term that does not universally resonate with senior management. These associations have tremendous value and passionate support but numbers speak volumes and membership and conference attendance have been decreasing for years. We are seeing the technology vendor market taking over a leadership role and may serve as the new defining force in setting direction and guiding the industry – self-serving yes but it could be what is needed going forward. I am not concerned about relevance as it will continue to be all about information and technology, and the management, protection and leveraging of information asset. While the role of a traditional Records Manager may not continue to be relevant, I don’t find it concerning – the relevance is in the work and it evolves.

Read More

GDPR - General Data Protection Requirement - Information Governance Perspectives

Emerging From The Dense, Digital Fog – An Interview with Dr. Ulrich Kampffmeyer

Third in a series of interviews with leaders in the fields of Risk, Compliance and Information Governance across the globe.


IMG_992_kff_400x400

Dr. Ulrich Kampffmeyer is the Managing Director of Project Consult in Hamburg, Germany and a renowned expert on digital transformations, business intelligence and enterprise content management. I had the opportunity to sit down with him in May and discuss the GDPR, artificial intelligence and social issues emerging from the dense, digital fog we all find ourselves in.

Ulrich, you write and teach extensively about the cultural and social changes in work environments that are a direct result of the emergence of digital transformations. Now that data is at the fingertips of everyone…

What changes should society expect that the business world may have already?

The pace of digital transformation accelerates day by day. Cloud technologies, artificial intelligence, IoT and other developments are happening so fast that there is a danger they’ll get out of control. The mightier AI becomes the larger the danger that it gets uncontrollable.

Consider Soshana Zuboff (one of the first tenured women at Harvard Business School) and her three laws:

  1. Everything that can be automated will be automated.
  2. Everything that can be informated will be informated.
  3. Every digital application that can be used for surveillance and control will be used for surveillance and control.

Read More

The Future of Compliance – An Interview with Professor of Financial Law Miguel Mairlot

First in a series of interviews with leaders in the fields of Risk, Compliance and Information Governance across the globe.


Miguel MairlotMiguel Mairlot is the Risk and Compliance Officer for Lombard International Assurance and a Professor of Financial Law.  I sat down with him at the beginning of the year to learn a little more about his experience in the field of Risk and Compliance and pick his brain on issues like GDPR, the future of privacy rules, the role of A.I. in “fintech” and any advice he can offer millennials looking to get started in the business.

What is it about the business discipline of Risk and Compliance that originally attracted you to the field and keeps you interested?

I spent the first 10 years of my career working in litigation, specializing in banking and finance laws. My expertise and knowledge of the MiFID regulation (Markets in Financial Instruments Directive) led me to work on its implementation for various financial institutions. At that time, legal and compliance tasks were usually performed by the same department. Although I’m interested and continue working on several aspects of the MiFID regulation, I devote most of my time on issues related to money laundering and the detection of serious tax fraud in the event of repatriation of assets.

How do you think companies should approach implementing GDPR and what do you think will be the greatest challenges here?

Any company subject to GDPR should take great care when implementing the requirements set out by this new regulation. Before its entry into force, data protection was not a top priority for many European companies. Now, the paradigm is about to change, due mainly to the hefty fines which can be imposed and the potential reputation damages which may result from a violation of the GDPR provisions.

Among all these tasks, raising awareness among employees about the risks related to the infringement of the rules set out by GDPR might constitute the biggest challenge since this new piece of legislation is considered as a important cultural change in Europe.

The implementation of GDPR will require the revision of internal procedures, the appointment of a Data Protection Officer in some cases and a mapping and assessment of all the data processes, as well as contractual changes. Among all these tasks, raising awareness among employees about the risks related to the infringement of the rules set out by GDPR might constitute the biggest challenge since this new piece of legislation is considered as a important cultural change in Europe. Read More