YouSaid · the spoken record
Megan O'Neill
- lines on the record
- 68
- first
- 2018-04-12
- most recent
- 2018-04-12
- sittings or episodes
- 1
- sources
- podcast
Every line below is reproduced as it was said and linked to the record it came from. Nothing here is summarised or generated. Directory · Search · Corrections
“Well, thanks a lot. I just want to wrap up and remind everybody of sort of these core GDPR principles that I'm just going to read so that we end with these. But everything must be based on consent. You can only collect what's adequate, necessary, and not excessive in relation to a specific service. The right to transparency, as Lisa was saying, that seems to be where the main emphasis is. You have the right to be forgotten, you know, IP addresses, email addresses, genetic information, all of those are personally identifiable information. Thanks a lot, Lisa Hawk from Everlaw, for educating us about GDPR.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“I would recommend certainly the privacy by design, the foundational principles. It's a document. You can Google it. Dr. Anne Kavukian, she's the former Information and Privacy Commissioner from Canada. And that talks about in a very digestible format the things you can do to incorporate privacy by design into your engineering and design process, certainly.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Five steps ahead. You want the people who can triage issues, who can spot issues, who can think ahead to what the challenges might be and how you will solve them. I don't think it necessarily matters what function, but look for the people who have that detail-oriented nature and the ones that are just always thinking ahead.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Well, at Everlaw, it's a bit of all hands on deck because each of the teams, everyone does something with personal data. And so it's important for all the teams to be involved. But if you're at a smaller company and you need somebody to lead your GDPR compliance project, then you don't have a person in charge of compliance, then my advice is to look for what I think of as your risk sentinels. My life before the startup life was actually in the oil industry for about nine years. And I've had a bunch of different roles worn different hats around regulatory compliance from an energy trading perspective. And then after that, responding to Deep Water Horizon and leading environmental restoration for the company. So in my career in compliance, I've had colleagues that came from trading. They came from engineering. They came from risk. Not everybody in compliance is a lawyer. Some come from audit. But you want the people who are thinking.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“There's an action item for a podcast. This is really going to be it. And I think everybody's going to be shocked at just how much potential there is for risk that they weren't really thinking about. So just two things to wrap up. One, you obviously came with all of this experience and that focus when you joined the company. But an existing company might not have the opportunity to hire somebody like you or the budget or that's the priority. But who is the right person to focus on this in a company? Where do you When you talk to your peers that are doing this where are they in the company? Are they in product and ops and marketing? Who is doing this work?”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Exactly. You're just sitting down with your colleagues and you're saying, you know, what do you do with personal data? And going through, it will help you get all the information you need to figure out how much exposure you have.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Yeah, when it comes to privacy and personal data, we're just used to using information, putting it into productivity tools, and doing our jobs, right? We're not used to thinking of how do I rely on personal data to actually perform my business function. So if you take this sheet and you sit down with one of your marketing folks and you say, you know, what personal data do you actually use to do your job? The next minute they'll be talking about, okay, well, inbound lead generation, I need contact information for that. And then the next thing I'll say, well, what do you do with that? And then I guarantee you there's at least two software programs that they put lead contact information into to actually do their jobs to generate emails and do the things they do.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Have to go back and say, okay, where do we have a username? Like, where do we have an address? Where do we have an account history? Where do we have other? And you sort of just systematically have to go through and do that.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“There's a lot of free resources out there, but I couldn't find anything that was free and that put all of the information where I wanted it in one place. And yes, it's a spreadsheet. It's actually Google Doc. It's really easy for a lot of people to be in there working on it at once. And what it does is it lays out all of the things that you need to document to do your own risk assessment in terms of what data do you have, where is it, what are you doing with it, why do you have it? Do you really need it? How are you securing it? So it's a one-stop shop where startup can just document what they're doing with personal data that will then allow them to assess their risk and decide what they need to do.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“So you're now a product manager on the team trying to figure out what to do. Like, one of the things you did was pull together a tool. It's just a spreadsheet, not just, it is a spreadsheet, but it's the way that we started in security too. It's a checklist of what you have to do for a bunch of stuff.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Our controller and processor obligations which need to be clearly laid out in a contract. And if you transfer data, you will have to have probably, at least right now, people, a lot of companies are using the standard contractual clauses. So in a nutshell, yes.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Well, if you have money burning a hole in your wallet, I'm not going to tell you not to do that, but I take a little bit of a more practical approach in that I think that I think startups can do it themselves. I think they have a lot of smart people. There are tools out there that you can use. Eventually, you will need a lawyer to draft some contracts. But I do think there are practical things you can do without engaging a really expensive consultant.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“There is an alphabet soup of potential certifications around privacy and security, certainly. GDPR is a regulation, and right now there is no certification for it. The regulation does have language around certification in it, but nothing's actually been developed. It's referenced, but it's not developed. So there are a lot of advisors out there, consultants that may try to sell you on some kind of certification. But at the end of the day, it's a law. So it's your job as a company to figure out how does this law apply to me? How can I take a risk-based approach to meeting my obligations? And then how can I document my rationale and what I've done to comply if I'm ever asked, if my door is ever the one that gets knocked on.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“So, a good rule of thumb is if you can sign on to your product, then you're collecting private information because you have that key and then everything associated with it is private. So let's assume you want to be GDR compliant. Is it like getting like FedRamp certified or FISMA or HIPAA or any of these other acronyms that not everybody is clear on?”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Well, of course, I think cloud is special, but when it comes to GDPR, I don't think there's a huge difference because I just can't imagine how any company can run a business without collecting personal data. I mean, whether you are a B2B SaaS company, whether you're a social media company, whether you're selling on-premise software, you're still billing people. You're collecting names, you're collecting emails, phone numbers probably. You have user accounts.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“I would just encourage other people to think about it as a culture, not as compliance, as sort of feature design. So we talked about that this applies to sort of everybody. Is there anything unique or special about being cloud or being on-prem? Because, you know, sometimes people think that like if you're on-prem, then you sort of escape all of this stuff because it's all just stuck on a server somewhere. But I'm not sure where does that fit in with these regulations.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“And that was how security was. You know, when I started it in the software industry, nobody talked about security. It was sort of funny that there were viruses, not like, oh, the world is going to end. And then one day the world is going to end. And then all of a sudden, all the new hires learn, by the way, what you work on can cause the world to end if you don't do a good job. And they're like, cool, so how do I fix that? I don't want to be the person who makes the world end.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“That's one of the neat things about because Everlaw is in the regulatory space and the legal space, I can see it when I visit that they view compliance with things like GDPR not like a weird training exercise glued on the side that you have to worry about on one day a year, but it has, it is a thing that gets baked in to sort of how the company functions. And then when new hires show up, they don't see it as weird or the weird training thing they have to go to. They just see it as, oh, this company cares a lot about this topic.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Right, exactly. You know, culture is so important for a lot of reasons, but around a speak-up culture for everyone in the company feeling like, hey, something over here looks weird and having the ability to raise that and knowing that they will be supported when the issue is raised and that it will be responded to and that folks on the team take it seriously. I think from a compliance, security, privacy perspective, having a culture where it is common and is accepted and is encouraged to bring up issues is where you want to be because if something goes wrong and you don't have that, you're already going to be on the back foot. I've been on the receiving end of a deferred prosecution agreement largely relating to a cultural issue around not reporting things and sort of being scared to report things. And I can absolutely say without”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Well, and I think that part of this gets also to the kind of company culture that gets created around the information that the company has, like how many people have a password that enables them to see it. And just even these little things.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Yeah, absolutely. And I mean, and it could be something as simple as an employee hitting send on an email containing some personal data. So it doesn't have to necessarily be a hack, but absolutely you need to have a process in place with the knowledge that nothing is ever going to go as planned, but you still need to have laid out some plans, even if it's very basic. And then I also recommend testing those plans because Testing them and doing scenario planning and actually running scenarios is the best way to find out, okay, actually, I don't have Joe's phone number. And how do I get it? Without my computer.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“So, I think that for any startup, a key thing is there's probably a good chance that the company has a process around the service going down. And the reality is they need the same kind of checklist process, call list, pagers, alerts in case of being notified by a breach, which might actually not be a systems notification. It might actually just be, you know, it actually might show up on some Reddit forum somewhere, or it might show up by people sending threatening mail that they have the data, but they need to have like an action plan.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Well, there is some specificity there around timeframes for response and notification. So people kind of gravitate to the 72 hour language, which talks about the obligation of data controllers notifying the supervisory authorities, so the regulators within 72 hours of becoming aware of a breach. And a lot of the discussion has been around companies thinking, okay, 72 hours, not a lot of time. How do we respond in that timeframe?”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Okay, no one has read that except you. So tell us what it means. Don't just show up one day. Now, the reason that this all got started was the problem of breaches. And that what was happening was these giant data sets are being collected, and then they were leaking. So what is GDPR say about breaches?”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Reading European things Yeah, it's, and I think that scares a lot of people, and it scares smaller companies into thinking that it's just too much of a hot potato. But if you actually read Article 83, which is the part in GDPR where they're talking about you. So tell us what it means. Well, I have to say, I do recommend that folks take a look at it because working backwards from there, they actually tell you what they care about when they're going to potentially assess a fine, which is, you know, is there negligence?”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“And I think that is just the huge focus because the numbers are so large. And frankly, that's what the reporters are writing about. They're doing the whole thing. Look at these giant finds, you know, 4% of global turnover. Oh, overturn over.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“So people who don't know whatever law does, it happens to be software for lawyers, but that doesn't, the domain doesn't really change anything. They have a massive amount of very, very sensitive information and also identifying information about attorneys and what they're working on. And it's no different than any other product for collaboration. And so to me, it's been very interesting to watch this notion of GDPR get baked into the engineering cycle. But one area that is just fascinating to me is that as vague as the GDPR might appear to an engineer in some places, it got very specific very quickly on penalties.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Yeah, we've been talking about security for a long time, and certainly the concept of privacy, once you start talking about how it actually applies in practice with the engineers, it makes a lot of sense to them. And when we were talking about this, you know, the example I gave just a second ago, look, we're going to design this thing and we can either do it so that it's easier to delete data later or it's harder. privacy by design way is to make it easier and the light bulb goes off and they just get it. So certainly if you're working on implementing this with your engineering team, it may require a little bit of explanation up front, but it's common sense.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“It's not a user design thing necessarily or that obviously has implications. But this feels much different in terms of the overall engineering design process. So you've integrated that yourself into Everlaw.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Dr. Anne Kavukian wrote a paper back in the 90s called Privacy by Design. So the concept has been around for a while. The GDPR discusses it in the context of requiring data controllers to meet the principles of data protection by design and data protection by default, which is very similar to the privacy by design. And essentially just boils down to privacy being taken into account throughout the whole engineering development process. And it sounds kind of complicated, but it boils down to some really straightforward concepts, like, for example, privacy as a default setting, privacy embedded into the design. So if you have a choice to design a function where you can make it easier to delete data later down the road or harder to delete data down the road, you want to go down the road where it will make it easier for you to delete that personal data.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Wow. So the GDPR offers up a whole bunch of things to worry about. Like you have to support all these features in your product. You have to do all these things. But it doesn't really tell you what to do. One area that it does is it that I think is super interesting is that it tells you about privacy by design. That sounds familiar to me having lived through the security world of secure by design. But privacy by design, what does that really mean?”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Yes, now you've reminded me. And there's actually a really good, there's a few sort of dueling journal articles around the right to be forgotten and around the automated data processing. So what you're talking about, algorithms, how GDPR will affect data science, and the types of automated decisions, such as machine learning, that affect the outcome as it relates to an individual. So like a credit report, a loan, and so forth, and the right to have a human actually look at the output of that algorithm and say and explain how the decision was made so.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“I think, oh, the one you're talking about is this really interesting one where it's that if they make a decision based on your data in software, like you have, this is crazy. You actually have the right to make humans do the same, look at your data and make the same choice if I read it correctly. Is that what they meant? Yeah.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Have to be able to object to the use of your information for direct marketing, you have to be able to request that your data be erased when it's no longer needed. You can also request the portable version of your data, request that decisions based on algorithms made by humans.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Yes, but in fact, one of the top regulators from Europe was in the Bay Area just a month ago, Helen Dixon, who is the Irish Data Protection Authority. And she actually said that transparency and how companies respond to the data subject access rights when asked is going to be a big focus. So certainly how companies operationalize this will be in the...”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“And it's not really designed for consumers. And I think the European Union has learned from that because they've been iterating since 1995 on this. So I think they're going to look at the implementation of these as well as whether or not you have them.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“So then all of this actually to me sounds a lot like if you have ever gotten your own credit report. In the US law, they've actually done a very similar thing, but for this very narrow case for credit reports, and honestly, it's kind of adversarial.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Yes, so you have the right to request basic information about the nature of the processing, about what the company is actually doing with your data. You have that right to information. You also have the right to access it.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Sure. And like I said before, it definitely matters what role your company is as a how you respond to these rights, which is why it's really important that you start there and understand where you fit into GDPR, what information you have. Because like you pointed out, if you have to comply with these data subject rights, you have to be able to do it. And you may need to build that into the product that you're building.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“And so once you and your company have those personal data, you've identified it, one of the things that's that I found the most interesting in the GDPR is that, and it's in the very beginning in the recitals, is that citizens in the EU, they have very clear rights about their data. Like your product just has to do these things. So why don't we just walk through what these rights are?”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Yeah. The U.S. just chose not to make laws and regulations that are nearly as all-encompassing as these EU ones. But often what happens is it's just better to just pick that as the standard by which you do, because it's the higher bar.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“They're covered by. That's true. And so if you look at the scope, there's two different areas of coverage. One is offering goods and services to the EU, and there are things like even if you have a US website, do you offer a translation? Do you have a contact number in the EU? Do you have employees in the EU? And then there is another aspect, which is a little bit less clear, but around monitoring and profiling. So targeted ads are you collecting fitness data from people in the EU on a wearable device. So it's very, very broad.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Okay, this is personal information, so let's be careful. So the key is that these regulations cover European Union citizens no matter where they happen to be at a given time, regardless of where the product resides that they're covered by.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Well, you're probably using personal data from EU data subjects. They could live in the US. I'm married to one. Okay, this is personal information. So let's be careful. I was being a little bit facetious, but if you have a software product, you're probably marketing to people in the EU just because you have a US website, if you offer it to the folks in the EU, there's a good chance that you're collecting personal data. It's a big place.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“But I think your non legal advice is anonymization is good, but we should probably be aware that someone is going to find themselves having that tested in front of the regulators or in court as to whether or not it went far enough. And the state of the art isn't even clear yet if it's far enough”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“I think there's a stat out there that says that over 80 or 85% of the US population can be identified with three pieces of data. So it's certainly a challenge. The regulation also introduced another concept, pseudonymization. So pseudonymization is when information is obscured, but there is a key that can tie it back to an individual's. And the regulation talks about pseudonymized data as a way to meet data protection by default and by design.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Well, it is a big research topic over whether or not you can truly anonymize something because the ability for machine learning to triangulate and find patterns that you can't readily see is so extreme. And even when Apple announced that that's the kind of thing that they do, there was a lot of pushback saying, well, it's not really proven and six degrees of separation or whatever. In fact, that goes way, way back to a very famous case in the US over a product called Lotus Marketplace, which came out in the early 1990s. And it was anonymized census data. But the problem was it was so granular. At the city block and building level, but basically you knew how much a person made in salary just because they lived in a certain house.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“It's really important because there is one escape route from GDPR, which is the provision in the regulation, which is also the same as the 95 directive, which says that data that are fully anonymized, meaning that no individuals can be identified, are outside the scope of GDPR. So if a company, a startup, can truly anonymize data, then that data wouldn't be subject to the regulation. But I have to say, I think that the concept of anonymization will be tested, sort of what actually qualifies. And I know there's a lot of security enthusiasts and mathematics enthusiasts out there thinking about, you know, what this is going to look like when applied.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“People in startups want to look for okay, is there a scalable technology solution such that it can reduce my overall sort of surface area that I have to worry? And so one question is, what if a startup from the very beginning has a clear anonymized identifier mechanism and then encrypts and anonymizes somehow all of this other kinds of data? Where does encryption and anonymization fit into all of this?”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source
“Yeah, and I'm glad you pointed that out because, in addition to the things that are listed as examples, there is a statement in there that says different pieces of information which collected together can lead to the identification of a particular person counts. So certainly the triangulation of different information, which you might not think actually would identify a person, but taken together or taken in parts and pieces can, that certainly would qualify.”
2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source