YouSaid · the spoken record

Megan O'Neill

lines on the record
68
first
2018-04-12
most recent
2018-04-12
sittings or episodes
1
sources
podcast

Every line below is reproduced as it was said and linked to the record it came from. Nothing here is summarised or generated. Directory · Search · Corrections

  1. And I think that the key thing is that they're very aware of taking one piece of data, like your genetic information, like the equivalent of a social security number, a driver's license number, tax number, and then a whole bunch of other data that might be innocuous, but triangulating it into one giant thing. And so the list of like things that are other types of data that matter is very long. It just doesn't stop as far as I can tell.

    2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source

  2. Well, it is very broad, and there's a bit of a history lesson as to why it's so broad, which is that the European Convention on Human Rights talks about respect for private and family life as a human right. So the definition is broad, and the definition really hasn't changed that much from the 1995 directive. There's a few important updates. One of those important updates is the inclusion of an identifier, including online identifiers like location data. So the original definition says that personal data is any information that relates to an identified or an identifiable living individual. So add on to that things like the online identifier and genetic information. Those are the two key updates to the definition. It was meant to be very broad and it was meant to apply to a large swath of information.

    2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source

  3. And that's just another reason to go back to what is your role here? Are you a controller? Are you a processor? Because when it comes to responding to data subject rights, there are some differences and the controllers are likely going to be the entities that are receiving these complaints. So it is important to know where you fall in that spectrum and what your obligations are in terms of responding to those kind of complaints.

    2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source

  4. No, certainly not. And with the data protection principles under a GDPR, the one that I've heard the regulator is focusing on the most is transparency. So they are putting a huge amount of work into making sure individual citizens in Europe understand that they have the right to know what the data controllers and processors are doing with their information and who they're giving it to.

    2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source

  5. And I think that's a sort of a key theme about GDPR is difficult and as big as it all seems. They've done a lot of work to sort of make it hard to find loopholes or excuses and there's not like an easy out, so to speak.

    2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source

  6. No, in fact, if you do that, they are probably the third term, which is the subprocessor. So then you've brought a subprocessor into the mix, which is just another processor, but you'll have to ensure that they are meeting their requirements and sort of the chain of obligations and responsibilities.

    2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source

  7. And so, just to be clear, inserting a vendor or a third party in there doesn't change any of this. And that's something that sometimes in U.S. law you think, oh, there's a third party and liability is insulating, but you can't just hire a contractor in GDPR goes away.

    2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source

  8. So, the data controller is the company that decides how and why the personal data is going to be processed. And the processor is processing that data on behalf of the controller. And the reason I say that there is a good chance that you will actually fall into both of those categories is because let's say you're a company with a website in Europe and you have a contact form on that website. So folks are inputting their name, email, and phone number to go into a database at your company that you might use for marketing later. Then you may also have customers. So if you're collecting that data through the website, you're a controller of that data. And then you may have a product where you're processing other personal data on behalf of your clients, your customers. You may be a processor for that data, but a controller for the other information you collected.

    2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source

  9. And it is really important to figure out where you fall in that. And if you're processing personal data, there's also a really solid chance that you're both. So the terms controller and processor actually aren't any different from the 1995 directive, but the obligations of a controller and a processor have changed under GDPR. So there are definitely some things to be aware of in terms of what the obligations are.

    2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source

  10. Right, right. And so startups do have a real advantage. Okay, so let's dive into the main body of the GDPR. So the first thing is it comes out and it just defines two kinds of main roles in the company. And they're awesomely named that seem roughly synonymous. Controllers and processors. And I guess this is important because you sort of want to know which one am I or what do they mean? Because they define everything else relative to being a controller or a processor.

    2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source

  11. Well, you're paralyzed because you have to do the EU just spent four years pulling together 28 member states, but you're at a big company, you're going to spend two years pulling together the 400 different groups each with their own data sets and their own vendors and their own policies and their own ULAS project.

    2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source

  12. Yeah, I think so. And especially for startups, first of all, it is a big deal. I'm not saying it's easy to do all the work that you need to do to get into compliance, but startups tend to be more nimble. You may have fewer resources, but it's also easier to make changes to your infrastructure, your org structure. And if you're willing to put the work in and you can do it, I think it could open up a ton of opportunities.

    2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source

  13. Yeah, and I think whether or not it's harder to do business there depends a little bit on your perspective. Certainly the Europeans view it as a way to make it easier to do business in the digital single market, merging all the laws of the 28 member states into sort of one data protection regime, so to speak. I think for U.S. companies that are working towards compliance, there are two different ways to look at it. You can either adopt the stricter standard and look at it as an opportunity to do business across Europe, or you can look at it as a barrier.

    2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source

  14. So, the thing that is interesting for me is that the European Union, by virtue of the long arm, which it's hard to get the song out of my head right now, but I won't sing, I swear. One thing that's interesting is that they've sort of taken the global lead on privacy. And that's interesting because it puts the US companies oddly under this new regulatory oversight, even though they didn't elect the people who sort of are passing it. So does it sort of make it weird that Europe is almost harder to do business in in the US?

    2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source

  15. Which is going to sort of end up being everybody who's listening in one way or another. They just haven't realized that yet. So put a little scope on this. The actual GDPR is 260 pages long. And my favorite is that it has 99 sections. And the problem ain't one of them. And 173 different sort of recitals, which when you read them, they kind of look like the EU's tweets about what it should be. So it's a pretty big document.

    2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source

  16. In legal terms, there's a thing called long arm jurisdiction, and this is probably one of the longest of the long-armed jurisdictions. And what I mean by that is a situation where a local court can actually assert jurisdiction over someone in another state, another county. And in this case, from the European Union to other countries and companies who process personal data of EU data subjects. So in a nutshell, it applies to anyone, so any company that processes personal data of EU data subjects.

    2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source

  17. So we're going to just dive right in to GDPR, the general data protection and regulations of the European Union. So first off, like just who is going to be regulated by, like a bunch of people like our product managers and compliance people and engineering and ops are wondering whose job it is and they're pointed at each other. So like who is regulated by it?

    2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source

  18. Hi everyone, welcome to the A6 and Z podcast. I am Sonal. Today's topic is something that's top of mind for so many GDPR or general data protection regulation by the EU Parliament, which goes into effect very soon. Since this affects so many startups and actually companies of all kinds, we thought we'd share a sort of primer by podcast, but be sure to also check out the show notes for links to some of the resources mentioned in this episode. Our special guest is Lisa Hawk, who is VP of Security and Compliance at Everlaw, an A6NZ portfolio company. She started as an environmental scientist and lawyer but spent most of her career in regulatory compliance, and joining her to host this conversation is ASICNZ board partner Stephen Sinofsky.

    2018-04-12 · a16z Podcast · a16z Podcast: What to Know about GDPR · IDENTIFIED FROM THE TRANSCRIPT · source