Intralot: GDPR and the 4th industrial revolution

Our world is ever changing through the rapid proliferation of technologies that impacts industries, our professional and personal lives. This proliferation has been called the 4th industrial revolution by the World Economic Forum which has recently published its Digital Transformation Initiaive report[1] in collaboration with Accenture. According to the report, digital transformation in businesses and government can unlock an estimated $100 trillion value over the next decade, with Artificial Intelligence (AI), the Internet of Things (IoT), Big Data and the Cloud being at the front of technologies and models that will enable innovation. These results are aligned with ISACA’s Digital Transformation Barometer study[2] in which the potential of these technologies is being identified together with the perceived risks from their adaptation, communicating the importance of managing risk as an integrated element of digital transformation. The criticality of managing risk is validated by the worldwide effect of data breaches which have reached an average cost of $3.62 million per incident[3], as well as the increasing regulatory compliance requirements demonstrated, for example, by the European General Data Protection Regulation (GDPR).

Christos K. DIMITRIADIS PhD, CISA, CISM, CRISC Group Director of Information Security, INTRALOT

GDPR is about protecting personal data but fundamentally requires us to understand the types of data we process, why and how we process them and how we serve the rights of the data subjects.

GDPR in digital Transformation initiatives

GDPR is about protecting personal data but fundamentally requires us to understand the types of data we process, why and how we process them and how we serve the rights of the data subjects. Protection is covered by cyber and information security principles. This is what security is all about: protecting the confidentiality, integrity and availability of data and services, as well as detecting, responding to and recovering from incidents. The rest of the questions asked by GDPR are about data and technology governance and compliance. This is why digital transformation requires a strong data and technology governance model in place for implementing a holistic and correlated study on the organizational, procedural, technical, human and cultural elements of an ecosystem.

Big data can add value if not transform an industry as a whole. Lotteries can gain a better understanding of player, retailer, channel, game behaviors among others and enhance their products and services or provide brand new innovative ones.

The Big Data transformation example

Let’s use the example of a big data analytics initiative in order to briefly understand the dynamics of GDPR implementation. Big data can add value if not transform an industry as a whole. Lotteries can gain a better understanding of player, retailer, channel, game behaviors among others and enhance their products and services or provide brand new innovative ones. Being GDPR compliant with the introduction of big data fundamentally requires the understanding of the notion of privacy (and security) by design. This must be embedded in the transformation framework, while ineffective and silo approaches of considering privacy and data protection as side projects with their own owners, budgets and accountabilities should be abandoned. Instead, privacy and security controls should be embedded, accountabilities should be assigned to all stakeholders of the initiative and budgets should be integrated, also being addressed as investments (vs compliance costs) towards increasing the competitiveness, sustainability and trust of the overall initiative. In other words, privacy by design starts with the development of a holistic business case, identifying both opportunities and risks.

The first step is to create a data register. While this would be implemented as an obvious step in a big data transformation initiative, it is not as obvious when discussing AI, Cloud or IoT. The data register should clearly identify personal data, their owners and processors, their flow between systems and through processes, their processing location (geographically and technically), possible exports and imports between jurisdictions, the purpose and legality of processing and their retention periods. After developing the register, a risk assessment should be conducted towards identifying the impact, risks and controls, together with a data privacy impact assessment that focuses on the data subjects. Controls concern technology, organization, policies and procedures, also taking into account skills, competencies, culture and the human factor as a whole.

Technical controls concern for example the encryption or pseudonymization of personal data at rest and in transit, or the procurement of data leakage prevention tools, or extensions on an existing Security Information and Event Management system for covering the transformed ecosystem. Technology considerations also relate to the big data solution having features in place for serving the rights of the data subjects such as the right to be forgotten, the right to rectify information, or to restrict processing if the data subject did not provide consent for specific types of processing. When designing the solution, the right of not being subject to automated decision-making including profiling, should be considered as well, taking into account the effect of decision making or profiling, as well as the categories of data that are being processed by the big data solution.

Organizational controls may concern the creation of a Data Privacy Office and the appointment of an officer, as well as the change in existing roles for including accountabilities on personal data protection. They may also concern the interactions with third parties involved in the big data solution – subcontractors and partners – and under which contractual clauses they operate for ensuring GDPR compliance.

Policies for informing the data subjects and processes for obtaining clear consent prior to processing, as well as for protecting the rights of the data subjects, are critical as well. The right to object, right to access and generally all requests by data subjects should be supported by a respective process in order for the organization to be able to respond in a timely manner and according to the requirements of the law. The incident response processes should be revisited as well for ensuring timely breach notification, while response capability should be enabled by the big data solution in order to be able to detect and respond to a possible breach. Response plans should be retested in the transformed ecosystem, while agreements on processes with subcontractors of the big data solution should be put in place for jointly responding and managing communications.

Awareness and training programs should be provisioned for all roles involved in the big data operation, minimizing the risk from the human factor and ensuring that appropriate skills are in place for operating the big data solution in a trusted manner. Most importantly the common property of digital transformation and data protection must become part of the organizational culture: they are both continuous initiatives and not one-off projects.

The common property of digital transformation and data protection must become part of the organizational culture: they are both continuous initiatives and not one-off projects.

Conclusion

GDPR is a strict regulation. The message conveyed, however, is much broader than ensuring compliance. It is about respecting the data subjects and also about responsibly and securely creating value out of data, making the products and services that we offer more innovative, competitive and trusted.

GDPR is about respecting the data subjects and also about responsibly and securely creating value out of data, making the products and services that we offer more innovative, competitive and trusted.

[1] http://reports.weforum.org/digital-transformation/

[2] http://www.isaca.org/info/digital-transformation-barometer/index.html

[3] https://www.ibm.com/security/data-breach/index.html

Related Articles

View all

Synopsis

Français

Intralot: Le GDPR et la 4e révolution industrielle

En plus d’être une exigence de conformité, l’intégration de la sécurité et de la vie privée dans les projets de transformation numérique est un moyen important d’accroître la compétitivité et la confiance dans les produits et les services. La transformation numérique des entreprises et des gouvernements peut générer une valeur de plusieurs milliards d’euros au cours de la prochaine décennie, l’intelligence artificielle (IA), l’Internet des objets (IoT), le Big Data et le Cloud étant à la pointe des technologies et des modèles qui permettront l’innovation.

L’exemple d’une réalisation du GDPR dans des initiatives de transformation des Big Data est utilisé pour expliquer la nécessité d’une approche holistique combinant des contrôles techniques, organisationnels, procéduraux et liés aux facteurs humains. La nature du GDPR, qui n’est pas entièrement technique, nous est présentée, soulignant le besoin de comprendre le type de données que nous traitons, comment et pourquoi nous les traitons, et comment nous servons les droits des personnes concernées. Le besoin d’une conformité GDPR continue et non pas basée sur des projets ponctuels est également souligné, transmettant ainsi le message que la protection des données est plus un investissement pour pouvoir créer des produits et des services de grande qualité qu’un simple coût associé à la conformité.

Español

Intralot: El GDPR y la 4.ª revolución industrial

Integrar la seguridad y la privacidad en proyectos de transformación digital es un modo importante de aumentar la competitividad y la confianza que generan productos y servicios, además de ser un requisito que hay que cumplir. La transformación digital en las empresas y el gobierno puede abrir la puerta a valores de miles de billones de euros en la próxima década, con la Inteligencia Artificial (Artificial Intelligence, AI), el Internet de las Cosas (IoT), Big Data y la nube al frente de las tecnologías y los modelos que posibilitarán la innovación.

Ya se usa el ejemplo de la implementación del GDPR en iniciativas de transformación de grandes bases de datos para explicar la necesidad de un enfoque holístico que combine controles técnicos, organizativos, de procedimiento y de factor humano. Se presenta la naturaleza no solo técnica del GDPR, remarcando la necesidad de entender los tipos de datos que procesamos, por qué lo hacemos y cómo, y cómo satisfacemos los derechos de los interesados. También se subraya la necesidad del cumplimiento constante del GDPR en contraposición con proyectos únicos de este tipo, transmitiendo el mensaje de que la protección de datos es más bien una inversión para crear grandes productos y servicios, en lugar de un coste con el que hay que cumplir.

 
Deutsch

Intralot: DSGVO und die vierte industrielle Revolution

Sicherheit und Privatsphäre als integrale Bestandteile digitaler Transformationsprojekte sind nicht nur behördlich vorgeschrieben, sondern steigern auch die Wettbewerbsfähigkeit und das Vertrauen, das Kunden Produkten und Dienstleistungen entgegenbringen. Die digitale Transformation bei Unternehmen und Behörden kann Gewinnpotentiale in Höhe mehrerer Billionen freisetzen. Dabei sind künstliche Intelligenz (KI), das Internet der Dinge, Big Data und die Cloud an vorderster Front der Technologien und Modelle, die Innovationen den Weg ebnen.

DSGVO-Implementationen bei Big-Data-Transformationsinitiativen werden als Beispiel herangezogen, um die Notwendigkeit einer ganzheitlichen Methodik zu illustrieren, die technische, organisatorische, verfahrenstechnische und von Mitarbeitern verantwortete Kontrollen kombiniert. Die DSGVO ist dementsprechend keine ausschließlich technische Angelegenheit. Wir müssen vielmehr verstehen, welche Datenarten wir warum und wie verarbeiten und wie wir dabei die Rechte der betroffenen Personen wahren. Die DSGVO muss zudem kontinuierlich und nicht im Rahmen punktueller Projekte umgesetzt werden. Datenschutz ist also vielmehr als Investition in exzellente Produkte und Dienstleistungen zu betrachten denn als Quelle von Compliance-Kosten.

Other Articles

View all

The European Commission closes all infringement probes and pending complaints in the gambling sector

EU Flags at the European Commission Building The College of Commissioners decided on 07 December 2017 to close all the pending infringement probes and complaints in the gambling sector. Thereby the......

Read more Synopsis: fr / es / de

EL and the Women’s Initiative in Lottery Leadership WILL

The mission of WILL is to drive high-performance business growth through supporting the advancement of women into top positions of lottery management, leadership and responsibility. WILL powered the......

Read more Synopsis: fr / es / de

Major trends in marketing

It is essential to influence the consumer at the very moment of his or her decision-making. Hence, timing is very crucial. The opportunities for marketers becomes broader with the number of digital......

Read more Synopsis: fr / es / de

EL replies to the European Commission public consultation on fair taxation of the digital economy

The current tax framework does not fit with modern realities Following a narrative that the current tax framework cannot capture activities which are increasingly based on intangible assets and d......

Read more Synopsis: fr / es / de

EL INDUSTRY DAYS 2018

The beautiful city of Prague will be the background scenery for finding answers to the question of how traditional lotteries can reinvent themselves in the digital world. The EL Industry Days 2018 i......

Read more Synopsis: fr / es / de

An Introduction to Nigel Railton, CEO, Camelot UK

Nigel Railton, CEO, Camelot UK   Before becoming CEO of Camelot UK last year, Nigel was previously CEO of its sister company, Camelot Global, which runs a growing portfolio of consultancy an......

Read more Synopsis: fr / es / de

Disruption in the age of technological innovation

Jon Duschinsky, a social innovator from Canada, has the hypothesis that a lot of people in the Lotteries behave like Kodak, pretending that such disruption will not happen to the sector. Duschinsky’......

Read more Synopsis: fr / es / de

How to earn media attention without becoming fake news

  Avoiding fake news Her advice for marketers is straightforward: Be honest. Don’t give in to the impulse of using clickbait headlines. Tell a true story, and......

Read more Synopsis: fr / es / de

EL/WLA Marketing Seminar, 7-9 February 2018, London UK

Keynote speaker highlights At the conference, a number of top-class keynote speakers focused their attention on communication strategies relevant to the lottery sector. Jon Du......

Read more Synopsis: fr / es / de

Georg Wacker: “EL provides important international standards for state-lotteries which demonstrate to consumers that the games we offer are absolutely trustworthy.”

Georg Wacker, Managing Director of Staatliche Toto-Lotto GmbH Baden-Württemberg   Georg Wacker gives his opinion on the current gaming sector and the challenges faced by lotteries: “As ma......

Read more Synopsis: fr / es / de

INSERTA-inspired project aids people with disabilities, showcases CSR practices of lotteries

INSERTA Network activity with HR & CSR managers Moreover, it will be an important collaboration between lotteries, European Institutions and national governments to achieve the objectives of the......

Read more Synopsis: fr / es / de

Dr. Bettina Rothärmel, new Board Member of GKL Gemeinsame Klassenlotterie der Länder

Dr. Bettina Rotharmel, Board Member of GKL Gemeinsame Klassenlotterie der Länder   Bettina Rothärmel has a degree in economics and many years of experience in marketing and sales. During h......

Read more Synopsis: fr / es / de

A new Managing Director for Lotto-Toto GmbH Sachsen-Anhalt

Ralf von Einem, Managing Director of Lotto-Toto GmbH Sachsen-Anhalt (LTSA)   Ralf von Einem was born in 1966 in Hamburg and studied economics and organizational sciences, as well as business......

Read more Synopsis: fr / es / de

A sector like none other: The societal benefits of Lotteries

Lotteries are bound by strict rules; they cannot simply make money, but also have a duty to protect society. If Lotteries want to advertise, they are prohibited by law from painting an overly rosy p......

Read more Synopsis: fr / es / de

Upcoming EL Seminars & Events

Reserve your spot now for the EL Seminar that could change the course of your Lottery! EL and its Members are producing many educational programs designed to tackle real-world issues in a meaningful......

Read more