GDPR - what it means & the practicalities of

implementation in a SAP landscape
Melissa Dielman TECHday 2017

Do you know which personal data you are storing? Which data is GDPR relevant? Where it sits? Who can & is accessing it?

What is GDPR?

personal data has acquired enormous economic business intelligence the data identifiable information where it is not significance. personally identifiable material with artificial to grow to nearly €1 trillion annually by identifiers). According to some offers. analysed and to businesses to make use of the as anonymisation (removing personally moved across the globe. Collected. and encryption (encoding

The new EU rules will offer flexibility The Regulation promotes techniques such economy. the value of European citizens' personal data has the potential individuals' fundamental rights. messages so only those authorised can read it) to protect personal data. all while protecting needed). This will encourage the use of "big data" analytics. which can done using anonymised or pseudonymised data

All companies that collect personal data: all information that allows to identify a person In force as off 25/5/2018 Non-compliance Fines 4% of annual turnover.What is GDPR? The GDPR is intended to unify the privacyregulation in the whole of

Thus simplifying and allowing closer control on cross-border data processing. BUT: each country define do its own specificities at ratification. The processing of European personal data will need to comply to the same regulations in every memberstate of the EU as of may 2018. or 20mio€ whichever is the greater -> board level concern

Personal data": "any information relating to an identified or identifiable natural person" • ID card nrs. phonenrs.… • Name. age. bank accounts. credit cards. disabled status. date of birth. marital status. citizenship. address. languages spoken. email. social media addresses

Key components Right to be forgotten Protection of sensitive data Notification of Data breaches within 72 hours Transparancy/approval of data subjects Data Integrity Data protection impact assesments Data protection Officer

Data integrity Lawful. Fairness and Transparency Purpose Limitation Data Minimization Integrity and Confidentiality Accuracy Storage Limitation

Steps to take

(data protection impact assessment) Partners: when you supply/exchange data. the origin. risk impact. How What? Why? Where? Who? long? Access Risk Where used? User approval Change & remove Management Management

cloud It is your responsibility to ensure GDPR is complied with. Identification Data elements: map which data has been stored. who has access. storage location. the business reason. required data approval. and data sharing parties. retention requirement

Datasubject approval (1/2) Rights of the datasubject • Right to review the stored data • Right to request correction or deletion • Right to refuse direct marketing • Right to refuse automated decision making & profiling • Right to move data from one service provider to another

Datasubject approval (2/2) Improve Privacy statements: • Legal foundation for the data processing • The duration for which you will keep the data • Wether you share the data outside of the EUR • Complaints are the be reported to and handled by the local Privacycommission Faster access for data verification: • Request needs to be processed within 30 days. instead of 45 days • The person needs to be informed of the storage duration of the data • Inacurate data should be corrected when requested Request explicit consent (the right way) Minors need to approve through legal guardian (verified)

DPIA? DPO? DPIA: • Data Protection Impact Assessment is required to demonstrate your compliance. • Evidence of compliance is your responsibility • Regular updates needed DPO: • Data privacy Officer for companies that conduct a large amount of data processing on a daily basis – sensitive personal data or not. It doesn't get more specific than

Right to be forgotten • The right to be forgotten implies that data that is no longer business relevant. is to be removed from the records* • Taking into account legal requirements on identification & accountability ✓ Block/Anonymize data after certain period of inactive time – limited access only ✓ Delete data after legal retention term • Specific to data elements * or if subject objects to the

Protection of Sensitive Data • Identify sensitive data elements • Prevent access through authorizations • Scramble data in test systems

Data breach notification • Within 72hours • Identify scope & cause • Asses relevance • Inform Privacy Commission • Define reaction involved persons. • Define controls to identify data breach

Define & Document Processes • Storing data • Processing data • Accessing data • Responding to data requests • Responding to data breaches • Archiving personal data • Periodic update of data log

8 key steps

Identify: Which Data? • Most Data in SAP Business Suite and SAP S/4HANA might become personal data. A Sales Order is linked to the Business Partner (ID). The sales order itself contains additional personal data –so the whole Sales Order is to be protected. • ECC. HR. BI. CRM. SRM. • Combinations of attributes might become personal data –as soon as it is possible to identify the person

Where used? • Once the relevant master data fields are identified. the storage and (business) usage of these data fields needs to be mapped • For standard & custom developments (fields. tables. programs) • For protection and for "right to insight" • Keep in mind impact of system upgrades. new

SAP solution • SAP ABAP: list all the tables containing fields with personal information in the program Where-Used List for Domain in Tables • Custom development to identify. link & report on data elements • 3rd party solutions

Insight in data use • Data subjects have the right to see which data is stored on them • Request corrections • Manual process /automated tool? SAP solution • Custom report • 3rd party solutions

Consent Management • New SAP tools using social media integration. Hybris. HR Tools and ILM have consent documentation included SAP solution • Process Control. Policies • Process Control – Documentation • Your CRM/SRM? • Any database

Archiving • Limit the available data to the required minimum • TCO reduction • Less data to protect • Selective Archiving on filter criteria • For test & productive systems • Secure access to archive through authorizations SAP solution • SAP archiving

Authorize Limit access to sensitive data: • Use a solid. flexible and clear authorization concept • Define a strict access management policy and process • Consistent across SAP applications & dbase layer (ECC. CRM. S/4HANA. HR. BW. HANA. FIORI) • Restrict access to blocked data elements • Restrict access to data reports • Store data extracts at secure locations • Implement sufficient security parameters to prevent unauthorized access SAP solution • SAP Access Control

Sensitive data access Production Data: Test Data: • Authorized data processers • All users are "GDPR unauthorized" (selective end-users) • Data must remain meaningful & fit • Authorized data consultants: end. for testing users & IT • Restrict access to PRD-alike • Unauthorized users • Anonymize test consistently

Protect personal data in productive systems Anonymization • In case the subject requests so • Field based • Selective. finetuning of authorization • Does not change underlying data • Keeping historical data in reporting SAP solution • Regardless of access path • Multiple systems in sync • SAP UI Masking • Mass maintenance

Protect personal data in non productive systems • No business need -> needs to be handled differently • Pseudonymization/scrambling • Data can still be used. without link to persons • Needed for test systems & development systems • Respecting syntax/configuration requirements • Recognizable by situation/combination of data elements needs to be removed ! • Make test data a selective set/ data copy SAP Solution: • SAP TDMS: Test Data Migration Server

Data blocking/removal • When data is no longer active or needed for its primary purpose. the data needs to be "inactivated". Yet legal retention periods require traceability of

SAP Solution: • SAP ILM (Information Lifecycle Manager) • Define data specific policies (blocking & retention) • Trace data lifecycle • Inactivate data • Archive & delete • Delete from archived data (based on timestamp)

Per organization per document type. data type. diff retention periods will be taken into account.

Data Breach notification • Continuous monitoring of who accesses specific data elements • Insight to data usage – authorization finetuning • Alert when not compliant to predefined rules • Document data breach • Impact analysis – cause & extent of breach • Inform data owners SAP Solution: • Read Access Logging. UI Logging or SAP Process Control to identify possible data breach • Identify access to data elements • Define all possible approaches • SAP Process Control/Risk Management for response follow-up

DPIAs. Processes Data Privacy Impact Assessments • Show compliancy • Document controls • Test controls • Process & Policy Documentation • Issues & action plans Controls • Controls on user access (role based) • Controls on data reading Consent management • Automated for internal use • Documentation for external • Response policies Data breach

Other SAP Solutions to explore • Fraud Management: big data analysis on complex patterns to identify breach • Data Services / Information Steward • Tagging and profiling of data across SAP and non-SAP landscapes • Analyze repositories for types of data • Leverage lineage analysis to create transparency on data flows • Manage personal data accuracy & consistency • Process Mining by Celonis: Powered by understand and visualize in real- time which business processes 'touch' personal data • Enterprise Threat Detection: Security monitoring of your SAP business systems

