Intralot: GDPR and the 4th industrial revolution

Our world is ever changing through the rapid proliferation of technologies that impacts industries, our professional and personal lives. This proliferation has been called the 4th industrial revolution by the World Economic Forum which has recently published its Digital Transformation Initiaive report[1] in collaboration with Accenture. According to the report, digital transformation in businesses and government can unlock an estimated $100 trillion value over the next decade, with Artificial Intelligence (AI), the Internet of Things (IoT), Big Data and the Cloud being at the front of technologies and models that will enable innovation. These results are aligned with ISACA’s Digital Transformation Barometer study[2] in which the potential of these technologies is being identified together with the perceived risks from their adaptation, communicating the importance of managing risk as an integrated element of digital transformation. The criticality of managing risk is validated by the worldwide effect of data breaches which have reached an average cost of $3.62 million per incident[3], as well as the increasing regulatory compliance requirements demonstrated, for example, by the European General Data Protection Regulation (GDPR).

Christos K. DIMITRIADIS PhD, CISA, CISM, CRISC Group Director of Information Security, INTRALOT

GDPR is about protecting personal data but fundamentally requires us to understand the types of data we process, why and how we process them and how we serve the rights of the data subjects.

GDPR in digital Transformation initiatives

GDPR is about protecting personal data but fundamentally requires us to understand the types of data we process, why and how we process them and how we serve the rights of the data subjects. Protection is covered by cyber and information security principles. This is what security is all about: protecting the confidentiality, integrity and availability of data and services, as well as detecting, responding to and recovering from incidents. The rest of the questions asked by GDPR are about data and technology governance and compliance. This is why digital transformation requires a strong data and technology governance model in place for implementing a holistic and correlated study on the organizational, procedural, technical, human and cultural elements of an ecosystem.

Big data can add value if not transform an industry as a whole. Lotteries can gain a better understanding of player, retailer, channel, game behaviors among others and enhance their products and services or provide brand new innovative ones.

The Big Data transformation example

Let’s use the example of a big data analytics initiative in order to briefly understand the dynamics of GDPR implementation. Big data can add value if not transform an industry as a whole. Lotteries can gain a better understanding of player, retailer, channel, game behaviors among others and enhance their products and services or provide brand new innovative ones. Being GDPR compliant with the introduction of big data fundamentally requires the understanding of the notion of privacy (and security) by design. This must be embedded in the transformation framework, while ineffective and silo approaches of considering privacy and data protection as side projects with their own owners, budgets and accountabilities should be abandoned. Instead, privacy and security controls should be embedded, accountabilities should be assigned to all stakeholders of the initiative and budgets should be integrated, also being addressed as investments (vs compliance costs) towards increasing the competitiveness, sustainability and trust of the overall initiative. In other words, privacy by design starts with the development of a holistic business case, identifying both opportunities and risks.

The first step is to create a data register. While this would be implemented as an obvious step in a big data transformation initiative, it is not as obvious when discussing AI, Cloud or IoT. The data register should clearly identify personal data, their owners and processors, their flow between systems and through processes, their processing location (geographically and technically), possible exports and imports between jurisdictions, the purpose and legality of processing and their retention periods. After developing the register, a risk assessment should be conducted towards identifying the impact, risks and controls, together with a data privacy impact assessment that focuses on the data subjects. Controls concern technology, organization, policies and procedures, also taking into account skills, competencies, culture and the human factor as a whole.

Technical controls concern for example the encryption or pseudonymization of personal data at rest and in transit, or the procurement of data leakage prevention tools, or extensions on an existing Security Information and Event Management system for covering the transformed ecosystem. Technology considerations also relate to the big data solution having features in place for serving the rights of the data subjects such as the right to be forgotten, the right to rectify information, or to restrict processing if the data subject did not provide consent for specific types of processing. When designing the solution, the right of not being subject to automated decision-making including profiling, should be considered as well, taking into account the effect of decision making or profiling, as well as the categories of data that are being processed by the big data solution.

Organizational controls may concern the creation of a Data Privacy Office and the appointment of an officer, as well as the change in existing roles for including accountabilities on personal data protection. They may also concern the interactions with third parties involved in the big data solution – subcontractors and partners – and under which contractual clauses they operate for ensuring GDPR compliance.

Policies for informing the data subjects and processes for obtaining clear consent prior to processing, as well as for protecting the rights of the data subjects, are critical as well. The right to object, right to access and generally all requests by data subjects should be supported by a respective process in order for the organization to be able to respond in a timely manner and according to the requirements of the law. The incident response processes should be revisited as well for ensuring timely breach notification, while response capability should be enabled by the big data solution in order to be able to detect and respond to a possible breach. Response plans should be retested in the transformed ecosystem, while agreements on processes with subcontractors of the big data solution should be put in place for jointly responding and managing communications.

Awareness and training programs should be provisioned for all roles involved in the big data operation, minimizing the risk from the human factor and ensuring that appropriate skills are in place for operating the big data solution in a trusted manner. Most importantly the common property of digital transformation and data protection must become part of the organizational culture: they are both continuous initiatives and not one-off projects.

The common property of digital transformation and data protection must become part of the organizational culture: they are both continuous initiatives and not one-off projects.

Conclusion

GDPR is a strict regulation. The message conveyed, however, is much broader than ensuring compliance. It is about respecting the data subjects and also about responsibly and securely creating value out of data, making the products and services that we offer more innovative, competitive and trusted.

GDPR is about respecting the data subjects and also about responsibly and securely creating value out of data, making the products and services that we offer more innovative, competitive and trusted.

[1] http://reports.weforum.org/digital-transformation/

[2] http://www.isaca.org/info/digital-transformation-barometer/index.html

[3] https://www.ibm.com/security/data-breach/index.html

Related Articles

View all

Synopsis

Français

Intralot: Le GDPR et la 4e révolution industrielle

En plus d’être une exigence de conformité, l’intégration de la sécurité et de la vie privée dans les projets de transformation numérique est un moyen important d’accroître la compétitivité et la confiance dans les produits et les services. La transformation numérique des entreprises et des gouvernements peut générer une valeur de plusieurs milliards d’euros au cours de la prochaine décennie, l’intelligence artificielle (IA), l’Internet des objets (IoT), le Big Data et le Cloud étant à la pointe des technologies et des modèles qui permettront l’innovation.

L’exemple d’une réalisation du GDPR dans des initiatives de transformation des Big Data est utilisé pour expliquer la nécessité d’une approche holistique combinant des contrôles techniques, organisationnels, procéduraux et liés aux facteurs humains. La nature du GDPR, qui n’est pas entièrement technique, nous est présentée, soulignant le besoin de comprendre le type de données que nous traitons, comment et pourquoi nous les traitons, et comment nous servons les droits des personnes concernées. Le besoin d’une conformité GDPR continue et non pas basée sur des projets ponctuels est également souligné, transmettant ainsi le message que la protection des données est plus un investissement pour pouvoir créer des produits et des services de grande qualité qu’un simple coût associé à la conformité.

Español

Intralot: El GDPR y la 4.ª revolución industrial

Integrar la seguridad y la privacidad en proyectos de transformación digital es un modo importante de aumentar la competitividad y la confianza que generan productos y servicios, además de ser un requisito que hay que cumplir. La transformación digital en las empresas y el gobierno puede abrir la puerta a valores de miles de billones de euros en la próxima década, con la Inteligencia Artificial (Artificial Intelligence, AI), el Internet de las Cosas (IoT), Big Data y la nube al frente de las tecnologías y los modelos que posibilitarán la innovación.

Ya se usa el ejemplo de la implementación del GDPR en iniciativas de transformación de grandes bases de datos para explicar la necesidad de un enfoque holístico que combine controles técnicos, organizativos, de procedimiento y de factor humano. Se presenta la naturaleza no solo técnica del GDPR, remarcando la necesidad de entender los tipos de datos que procesamos, por qué lo hacemos y cómo, y cómo satisfacemos los derechos de los interesados. También se subraya la necesidad del cumplimiento constante del GDPR en contraposición con proyectos únicos de este tipo, transmitiendo el mensaje de que la protección de datos es más bien una inversión para crear grandes productos y servicios, en lugar de un coste con el que hay que cumplir.

 
Deutsch

Intralot: DSGVO und die vierte industrielle Revolution

Sicherheit und Privatsphäre als integrale Bestandteile digitaler Transformationsprojekte sind nicht nur behördlich vorgeschrieben, sondern steigern auch die Wettbewerbsfähigkeit und das Vertrauen, das Kunden Produkten und Dienstleistungen entgegenbringen. Die digitale Transformation bei Unternehmen und Behörden kann Gewinnpotentiale in Höhe mehrerer Billionen freisetzen. Dabei sind künstliche Intelligenz (KI), das Internet der Dinge, Big Data und die Cloud an vorderster Front der Technologien und Modelle, die Innovationen den Weg ebnen.

DSGVO-Implementationen bei Big-Data-Transformationsinitiativen werden als Beispiel herangezogen, um die Notwendigkeit einer ganzheitlichen Methodik zu illustrieren, die technische, organisatorische, verfahrenstechnische und von Mitarbeitern verantwortete Kontrollen kombiniert. Die DSGVO ist dementsprechend keine ausschließlich technische Angelegenheit. Wir müssen vielmehr verstehen, welche Datenarten wir warum und wie verarbeiten und wie wir dabei die Rechte der betroffenen Personen wahren. Die DSGVO muss zudem kontinuierlich und nicht im Rahmen punktueller Projekte umgesetzt werden. Datenschutz ist also vielmehr als Investition in exzellente Produkte und Dienstleistungen zu betrachten denn als Quelle von Compliance-Kosten.

Other Articles

View all

Consumer driven innovations

Jana Smejcova, Kantar   Millennials, Gen Xers and Boomers Differences in consumer behaviour in the sector are evident between “Millennials, Gen Xers and Boomers”. According to Kantar’......

Read more Synopsis: fr / es / de

EU: CEN TF456 standardisation online gambling commences its work and EL participates in discussions on illegal platforms and Subsidiarity

In April 2018, following long consultations with stakeholders, the European Commission mandated the European Standardisation Committee CEN to draft a standard for a list of criteria for reporting to t......

Read more Synopsis: fr / es / de

Digital Opportunities in a Player’s World

Eight-second attention span “45% of people have participated in any form of gambling in the past four weeks”, stated Robin Bowler, Playtech’s Government Markets Director, as he referenced a r......

Read more Synopsis: fr / es / de

Transformative Technologies and Lottery

A mobile identity? “People’s phones equals their identity, passively and actively”, Mr Riley kicked off his presentation. He added that, in his view, mobile phones could become a digital pass......

Read more Synopsis: fr / es / de

The Holy Grail

Lotteries need to stay relevant to the next generation of players and “compete on a level playing field against direct and indirect competition”. NLS believe that having engaging content is key......

Read more Synopsis: fr / es / de

Enhancing Lottery Responsiveness to Player Needs through Intelligent Systems Design

Accenture’s Alberto Bergamini kicked off the panel with a passionate presentation on unlocking the value of digitisation through intelligent systems design for the customer experience. Creating an......

Read more Synopsis: fr / es / de

Digital Empowerment of the Lottery Industry

Data, data, data Customer data received by lottery and gaming companies is undoubtedly crucial to the provision of lottery solutions and tailoring solutions to customer preferences. The data being......

Read more Synopsis: fr / es / de

How technology is raising the bar in sportsbook integrity

10,000 football matches per week! Sports betting, Kambi’s main service provisions, certainly has its differences as compared to traditional lottery businesses. However, many of the challenges and......

Read more Synopsis: fr / es / de

Sport 4 Life UK received the EL Sport Award 2018

Olli Sarakoski, President & CEO of Veikkaus Oy handing the EL Sport Award 2018 to Jack Skinner and Matthew Forsyth from Sport 4 Life UK The first EL Sport Award, along with a check for 5000 euro......

Read more Synopsis: fr / es / de

Industry Days 2018 – Navigating Towards Digital Opportunity

Masters of ceremony Jutta Buyse (deputy EL Secretary-General) and Arjan van’t Veer (EL Secretary General) were lively hosts throughout the two-day meeting, keeping delegates well informed of the a......

Read more Synopsis: fr / es / de

EL/WLA Sports Betting Seminar 2018: Winning in Sports Betting

  The19th edition of the yearly EL/WLA Sports Betting Seminar took place in Lyon on 15-17 May with the great support of the hosting lottery La Française des Jeux (FDJ). The event registered......

Read more Synopsis: fr / es / de

PR/Communications and Social Media Seminar

Nikola Vrdoljak, Director 404 Agency Croatia, set the scene by describing how “anxious” the world has become; where sharing is the natural choice rather than owning and where in our “non-linear......

Read more Synopsis: fr / es / de

Knowledge Sharing 2.0

The 2018 Knowledge Sharing seminar took place in Geneva on April 18-19, where it gathered around 50 participants interested to learn more about the latest trends in lottery markets and exchange of i......

Read more Synopsis: fr / es / de

A new President & CEO for SELAE

Jesús Huerta Almendro, President & CEO for Sociedad Estatal Loterías y Apuestas del Estado Jesús Huerta Almendro was born in Cadiz/Spain in 1965. He holds a Law degree, a Master's degree in H......

Read more Synopsis: fr / es / de

European Lotteries launches new European Lotteries Corporate University

Following a review of the requirements in this area EL is presenting a new 3-module European Lottery Corporate University (ELCU). Designed for various levels of participants, three separate modules wi......

Read more Synopsis: fr / es / de

A great success for the joint EL/WLA CSR-RG seminar in Lisbon

These numbers show both a high level of interest in CSR and RG across the lottery sector, as well as an enduring commitment from EL and WLA members to each issue as a core tenet of their business. Aft......

Read more Synopsis: fr / es / de

Upcoming EL Seminars & Events

Reserve your spot now for the EL Seminar that could change the course of your Lottery! EL and its Members are producing many educational programs designed to tackle real-world issues in a meaningful......

Read more

A new CEO for Svenska Spel

Patrik Hofbauer, CEO for Svenska Spel Patrik Hofbauer has extensive senior management experience and, in addition to his current role as CEO of Telenor Sweden, he has previously been CEO of Telenor......

Read more Synopsis: fr / es / de