Carta open forum

 View Only
Expand all | Collapse all

Ask an Expert: Data Privacy AMA with Ronni K. Gothard Christiansen

  • 1.  Ask an Expert: Data Privacy AMA with Ronni K. Gothard Christiansen

    Posted 07-09-2024 20:26

    Hello Carta Community,

    I am excited to announce that I will be hosting an "Ask an Expert" AMA event on Data Privacy on July 15th. As the creator of AesirX, I have dedicated my career to providing ethical data management solutions and helping businesses navigate the ever-evolving landscape of data privacy.

    Event Details:

    Date: July 15th
    Time: Jul 15, 2024 from 09:00 to 10:00 (PT)
    Location: Carta Community Forum
    Sign Up: Here

    About Me:

    With a 25-year track record in MarTech, Open Source, and Blockchain, I have been fortunate to significantly influence the Open Source community. My journey led me to found AesirX, where we offer cutting-edge Web3 business solutions that prioritize data privacy and tackle online tracking issues. In light of increasing compliance demands and the tightening of third-party cookie rules, our mission has never been more critical.

    What We'll Discuss:

    During the AMA, I will share insights and answer your questions on a range of topics, including:

    • Cross-border compliance for startups
    • Complying with GDPR and ePrivacy Directive for US-based companies
    • New privacy laws in the US 
    • Checking compliance of your site or e-commerce solution
    • Building a privacy-first culture

    This session is an excellent opportunity for us to discuss the challenges and opportunities in the realm of data privacy. I am eager to engage with you and provide guidance on how to ensure your business remains compliant and respects user privacy.

    How to Participate:

    Please post your questions in the comments below. I will address them during the AMA session. Don't forget to mark your calendars and prepare your questions in advance to make the most of this opportunity.

    Looking forward to a great discussion and your active participation!

    Best regards,

    Ronni K. Gothard Christiansen
    Founder of AesirX



    ------------------------------
    Ronni K. Gothard Christiansen
    Creator, AesirX.io
    E: ronni@aesirx.io
    W: aesirx.io
    ------------------------------


  • 2.  RE: Ask an Expert: Data Privacy AMA with Ronni K. Gothard Christiansen

    Posted 07-15-2024 06:46

    Hey Ronni. Thanks for doing this! Is there a good way to check if your site is compliant? I'm not sure if we need to ask a lawyer or not. We do have some traffic coming from the EU, and I know that gets complicated as well. Thanks in advance for anything that you can share. 



    ------------------------------
    Yuan Onida
    ------------------------------



  • 3.  RE: Ask an Expert: Data Privacy AMA with Ronni K. Gothard Christiansen

    Posted 07-15-2024 09:03

    Hi Yuan, thanks for your question!

     

    To check if your site is compliant, you don't necessarily need a lawyer for the initial steps. You can use tools like the AesirX Privacy Scanner. This tool leverages the European Data Protection Supervisor (EDPS) Inspection Tool and the EasyPrivacy list to evaluate your website's compliance and privacy posture.

     

    You can find the tool here: https://privacyscanner.aesirx.io/

     

    Here's a simple process:

    • Use AesirX Privacy Scanner: This will analyze your site for any compliance issues, categorizing them into low, medium, or high risk based on GDPR and ePrivacy Directive standards.

    • Identify Cookies and Trackers: The scanner will detect cookies and trackers that may be compromising user privacy by being loaded before consent is set.

    • Review Consent Mechanisms: Ensure that your site has proper consent mechanisms in place, as required by GDPR and the ePrivacy Directive. This means obtaining explicit user consent before any data collection or processing.

     

    You can get a free detailed report on your site's compliance status, and if you find it too technical or are in doubt, you can use our Privacy Advisor AI to explain the actual findings and what to do. This is a proactive way to ensure you meet regulatory requirements and build trust with your users. Our scanner and AI advisor are created to help increase awareness so it is tangible for both industry professionals and business owners to get access to the required knowledge to be able to act.

     

    A lawyer can help you with legal questions, but when it comes to ensuring your web-facing privacy, I strongly recommend using tools like our scanner or another easy-to-use tool to mention is https://urlscan.io/, but this is not as focused on consent and data models. It offers a wide range of data to show a good overview of what is going on when a user visits the website and all the network traffic associated with the visit. You need both Legal and Technical to be covered to ensure compliance.

     

    Remember that as a US company with customers in the EU, you are also liable for fines, and so the risk is equally high. Depending on your business model and what kind of data you process, there may very well also be cross-border compliance issues involved. However, a good starting point is to ensure that your website is not the primary cause of compliance risk, and here the privacy scanner is a very good place to start.

     

    Feel free to follow up if you have more questions!

     

    Best,
    Ronni



    ------------------------------
    Ronni K. Gothard Christiansen
    Creator, AesirX.io
    E: ronni@aesirx.io
    W: aesirx.io
    ------------------------------



  • 4.  RE: Ask an Expert: Data Privacy AMA with Ronni K. Gothard Christiansen

    Posted 07-15-2024 09:10

    Good to know! That's a great resource. I'll check into that this week. Thanks, Ronni.



    ------------------------------
    Yuan Onida
    ------------------------------



  • 5.  RE: Ask an Expert: Data Privacy AMA with Ronni K. Gothard Christiansen

    Posted 07-15-2024 09:00

    We're an ecommerce company based in the US, but we obviously have global sales. What should we stay up to date and on top of in order to stay compliant with GDPR? 



    ------------------------------
    Shawn Verobali
    ------------------------------



  • 6.  RE: Ask an Expert: Data Privacy AMA with Ronni K. Gothard Christiansen

    Posted 07-15-2024 09:10

    Hi Shawn, thanks for your question!

     

    As a US-based e-commerce company with global sales, staying compliant with GDPR involves several key steps:

     

    • Data Mapping: Understand and document how personal data flows through your organization. This includes what data is collected, how it is processed, where it is stored, and with whom it is shared.

     

    • Legal Basis for Processing: Ensure that you have a lawful basis for processing personal data. The most common bases are consent, contract, legal obligation, vital interests, public task, and legitimate interests.

     

    • Consent Management: Implement robust consent mechanisms. Users must provide explicit consent before their data is collected or processed. Ensure consent is freely given, specific, informed, and unambiguous.

     

    • Privacy Policy: Update your privacy policy to clearly explain how you collect, use, share, and protect personal data. It should be easily accessible and understandable.

     

    • Data Subject Rights: Be prepared to handle data subject requests, such as access, rectification, deletion (right to be forgotten), restriction of processing, data portability, and objection to processing.

     

    • Data Protection Officer (DPO): Appoint a DPO if required. This is mandatory if you process large amounts of sensitive data or engage in regular and systematic monitoring of individuals on a large scale.

     

    • Data Breach Response: Implement procedures to detect, report, and investigate data breaches. You must notify relevant authorities within 72 hours of becoming aware of a breach.

     

    • Vendor Management: Ensure third-party vendors and partners are GDPR compliant. This includes having Data Processing Agreements (DPAs) in place.

     

    • International Data Transfers: Ensure any data transferred outside the EU complies with GDPR requirements. This typically involves using mechanisms such as Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or ensuring the recipient country has an adequate level of data protection as determined by the European Commission.

     

    • Regular Audits and Training: Conduct regular privacy audits and ensure your staff is trained on GDPR requirements and data protection best practices.

     

    Using tools like the AesirX Privacy Scanner can help you monitor and ensure ongoing compliance. You can find more information and access the scanner here: https://privacyscanner.aesirx.io/

     

    Staying up to date with GDPR involves continuous monitoring and adaptation to new regulatory changes. It's essential to integrate privacy by design into your business processes to maintain compliance and build trust with your customers.

     

    I can also strongly recommend reading the new Consent Banner Report from NOYB that lists how all member states data protection authorities (DPAs) decide on specifics in relation to Consent Banner and the risks involved by not being compliant: https://noyb.eu/en/noybs-consent-banner-report-how-authorities-actually-decide

     

    Feel free to ask if you have more questions!

     

    Best,
    Ronni



    ------------------------------
    Ronni K. Gothard Christiansen
    Creator, AesirX.io
    E: ronni@aesirx.io
    W: aesirx.io
    ------------------------------



  • 7.  RE: Ask an Expert: Data Privacy AMA with Ronni K. Gothard Christiansen

    Posted 07-15-2024 09:04

    Hi Ronni. We do our best to stay compliant with privacy laws, but things can get murky at different levels of the org. Do you have any tips on how to encourage all employees to maintain compliance?



    ------------------------------
    Ron Abeline
    ------------------------------



  • 8.  RE: Ask an Expert: Data Privacy AMA with Ronni K. Gothard Christiansen

    Posted 07-15-2024 09:17

    Hi Ron, thanks for your question!

     

    Ensuring compliance across all levels of an organization can indeed be challenging. Here are some tips to encourage all employees to maintain compliance with privacy laws:

     

    • Regular Training and Education: Provide ongoing privacy and data protection training for all employees. This should cover the basics of GDPR, ePrivacy Directive, and other relevant privacy laws, as well as your company's specific policies and procedures.

     

    • Clear Policies and Procedures: Develop and distribute clear, easy-to-understand privacy policies and procedures. Ensure that all employees know where to find these documents and understand their importance.

     

    • Promote a Privacy-First Culture: Embed privacy into your company culture. This means making privacy a core value and emphasizing its importance in every aspect of the business. Leadership should set the example by prioritizing privacy in their decision-making processes.

     

    • Designate Privacy Champions: Identify and train privacy champions within each department. These individuals can help promote best practices, answer questions, and ensure that their teams stay compliant.

     

    • Regular Audits and Monitoring: Conduct regular audits and use monitoring tools to check for compliance across the organization. The AesirX Privacy Scanner is an excellent tool for this purpose, providing detailed insights into your website's compliance status.

     

    • Incentivize Compliance: Recognize and reward employees and teams who consistently demonstrate a commitment to maintaining privacy compliance. This could be through awards, public recognition, or other incentives.

     

    • Clear Communication Channels: Establish clear channels for employees to report privacy concerns or breaches without fear of retaliation. Ensure that these reports are taken seriously and addressed promptly.

     

    • Use Privacy-Enhancing Technologies: Implement tools and technologies that help maintain compliance, such as consent management platforms and data protection software. These tools can automate many compliance tasks and reduce the burden on employees.

     

    • Leadership Involvement: Ensure that senior leaders are visibly involved in privacy initiatives. Their commitment can motivate employees at all levels to take privacy seriously.

     

    • Regular Updates and Refreshers: Keep all employees informed about updates in privacy laws and internal policies through regular communications and refresher training sessions.

     

    By making privacy compliance a shared responsibility and integrating it into the daily operations of your business, you can foster a culture of accountability and ensure that everyone is working towards the same goal.

     

    Feel free to reach out if you have more questions!

     

    Best,
    Ronni



    ------------------------------
    Ronni K. Gothard Christiansen
    Creator, AesirX.io
    E: ronni@aesirx.io
    W: aesirx.io
    ------------------------------



  • 9.  RE: Ask an Expert: Data Privacy AMA with Ronni K. Gothard Christiansen

    Posted 07-15-2024 09:09

    Is there a good way to ensure that our third-party vendors and partners comply with data privacy regulations and maintain our same standards of data protection?



    ------------------------------
    Rose Jian
    ------------------------------



  • 10.  RE: Ask an Expert: Data Privacy AMA with Ronni K. Gothard Christiansen

    Posted 07-15-2024 09:28

    Hi Rose, thanks for your question!

     

    Ensuring that third-party vendors and partners comply with data privacy regulations and maintain the same standards of data protection, particularly for web-facing data, is crucial. Here are some steps to help you achieve this:

     

    • First-Party Data: Prioritize the use of first-party data collected directly from your users. This reduces reliance on third-party vendors and minimizes privacy risks. Tools like AesirX First-Party Foundation can help you collect, manage, and analyze first-party data securely and compliantly.

     

    • Data Minimization: Implement data minimization principles. Collect only the data that is necessary for your operations. This reduces the amount of data shared with third-party vendors, lowering the risk of exposure and ensuring compliance with regulations like GDPR.

     

    • Privacy by Design: Embed privacy into the design of your systems and processes from the outset. This means ensuring that data protection measures are an integral part of your business operations and not an afterthought. Regularly review and update your privacy practices to stay aligned with regulatory changes.

     

    • Vendor Due Diligence: Conduct thorough due diligence before engaging with third-party vendors. Assess their data privacy policies, security measures, and compliance with relevant regulations. Ensure they follow best practices in data protection.

     

    • Data Processing Agreements (DPAs): Ensure you have robust Data Processing Agreements with all third-party vendors who handle personal data on your behalf. These agreements should outline their obligations regarding data protection, including security measures, data handling practices, and breach notification procedures.

     

    • Regular Audits and Assessments: Perform regular audits and assessments of your vendors' data protection practices. Use tools like the AesirX Privacy Scanner to monitor their compliance with your data privacy standards and identify any potential issues.

     

    • Vendor Privacy Policies: Review and approve the privacy policies of your vendors to ensure they align with your company's data protection standards and regulatory requirements.

     

    • Contractual Clauses: Include specific data protection clauses in your contracts with third-party vendors. These clauses should cover aspects like data processing, confidentiality, data breach protocols, and the right to audit.

     

    • Certifications and Standards: Prefer vendors who have relevant data protection certifications such as ISO 27001 or SOC 2. These certifications demonstrate a commitment to high standards of data security and privacy.

     

    • Ongoing Monitoring: Implement continuous monitoring of your vendors' data protection practices. Use tools like AesirX's Privacy Monitor to regularly check their compliance status and ensure they adhere to your data privacy requirements.

     

    • Incident Response Plans: Verify that your vendors have robust incident response plans in place. They should be prepared to handle data breaches promptly and effectively, including notifying you in a timely manner.

     

    By focusing on web-facing data privacy, adopting first-party data strategies, implementing data minimization, and integrating privacy by design principles, you can significantly reduce vendor risk and ensure that your third-party vendors and partners comply with data privacy regulations.

     

    Let me also point out that if you were to swap to our open source and first-party unified analytics and consent solution; you would be converting a third-party data processor to first-party data processing, reducing your risk overall by limiting the data exposure and converting both consent and analytics from third-party to first-party. Every time you remove a 3rd-party data processor, you reduce your risk.

     

    Feel free to ask if you have more questions!

     

    Best,
    Ronni



    ------------------------------
    Ronni K. Gothard Christiansen
    Creator, AesirX.io
    E: ronni@aesirx.io
    W: aesirx.io
    ------------------------------



  • 11.  RE: Ask an Expert: Data Privacy AMA with Ronni K. Gothard Christiansen

    Posted 07-15-2024 09:30

    With the emergence of AI and machine learning, what are the emerging challenges in data privacy, and how can we stay ahead of them? 



    ------------------------------
    Julia Larsen
    ------------------------------



  • 12.  RE: Ask an Expert: Data Privacy AMA with Ronni K. Gothard Christiansen

    Posted 07-15-2024 09:43

    Hi Julia, thanks for your question!

     

    AI and machine learning brings new challenges to data privacy. Here are some of the key challenges and strategies to stay ahead of them:

     

    • Data Collection and Usage: AI and machine learning require vast amounts of data to function effectively, which increases the risk of data breaches and misuse. Ensuring data is collected and used ethically and transparently is crucial.

     

    • Strategy: Implement strict data minimization principles, collecting only what is necessary. Ensure transparency with users about how their data is being used and obtain explicit consent.

    • Bias and Discrimination: AI systems can inadvertently perpetuate biases present in the training data, leading to discriminatory outcomes.

     

    • Strategy: Regularly audit AI algorithms for bias and implement fairness checks. Use diverse and representative datasets to train your models and involve multidisciplinary teams in the development process.

    • Data Anonymization: AI and machine learning models can potentially re-identify individuals from anonymized datasets, compromising privacy.

     

    • Strategy: Employ advanced anonymization techniques and differential privacy methods to protect individual identities. Regularly review and update anonymization practices to counteract emerging re-identification techniques.

    • Data Security: The complexity of AI systems can introduce new vulnerabilities, making them targets for cyber-attacks.

     

    • Strategy: Implement robust security measures, including encryption, access controls, and regular security audits. Ensure that AI systems are designed with security in mind (security by design).

    • Regulatory Compliance: Keeping up with evolving data privacy regulations that impact AI and machine learning can be challenging.

     

    • Strategy: Stay informed about the latest regulatory developments and ensure that your AI systems comply with all relevant laws, such as GDPR and ePrivacy Directive. Engage with legal experts to navigate complex regulatory landscapes.

    • Transparency and Explainability: AI systems often operate as "black boxes," making it difficult to understand how decisions are made, which can undermine trust and accountability.

     

    • Strategy: Prioritize transparency and explainability in AI development. Use explainable AI techniques to make AI decisions understandable to users and stakeholders.

    • User Consent: AI applications that rely on personal data must ensure that users have provided informed consent.

     

    • Strategy: Implement clear and user-friendly consent mechanisms. Regularly update users on how their data is being used and provide options to withdraw consent if desired.

    • Third-Party Risk: Relying on third-party AI solutions can introduce additional privacy risks if those providers do not adhere to strict data protection standards.

     

    • Strategy: Conduct thorough due diligence on third-party providers, ensuring they comply with data privacy regulations and follow best practices in data protection. Use tools like the AesirX Privacy Scanner to monitor compliance.

     

    By proactively addressing these challenges and integrating privacy by design, data minimization, and transparency into your AI and machine learning projects, you can stay ahead of emerging data privacy issues and build trust with your users.

     

    Additionally, there is a significant opportunity in developing first-party AI and prediction solutions. These solutions, built on first-party data, can provide accurate insights while ensuring higher standards of privacy and compliance. Embracing first-party AI can not only mitigate privacy risks but also open up a vast market for privacy-conscious businesses looking to leverage AI responsibly.

     

    Feel free to reach out if you have more questions!

     

    Best,
    Ronni



    ------------------------------
    Ronni K. Gothard Christiansen
    Creator, AesirX.io
    E: ronni@aesirx.io
    W: aesirx.io
    ------------------------------



  • 13.  RE: Ask an Expert: Data Privacy AMA with Ronni K. Gothard Christiansen

    Posted 07-15-2024 10:01

    Thank you all for the excellent questions today!

     

    I hope my participation has brought more awareness to the critical importance of data privacy. I understand that many of you might have specific challenges you are facing, but due to the sensitive nature of these issues, you might not feel comfortable asking in a public forum.

     

    For those who need more in-depth assistance, we offer a comprehensive web-facing privacy review to help you identify and address your privacy concerns. You are also welcome to read more about AesirX and what we do on our website or to reach out to me directly.

     

    Thank you again for your engagement and dedication to improving data privacy practices.

     

    Best regards,
    Ronni K. Gothard Christiansen



    ------------------------------
    Ronni K. Gothard Christiansen
    Creator, AesirX.io
    E: ronni@aesirx.io
    W: aesirx.io
    ------------------------------



  • 14.  RE: Ask an Expert: Data Privacy AMA with Ronni K. Gothard Christiansen

    Posted 07-17-2024 22:35

    There is a new FAQ out on EU-US Data Transfers i just summarized on linkedin:

    Summary of the EU-U.S. Data Privacy Framework FAQ for European Businesses

    This should be on top of mind on US entities also operating in EU in relation to cross-border compliance.

    /R



    ------------------------------
    Ronni K. Gothard Christiansen
    Creator, AesirX.io
    E: ronni@aesirx.io
    W: aesirx.io
    ------------------------------