A turn to Privacy
Spoiler alert: this is more of a self-reflecting post than anything else. Iām not trying to lure anyone into the world of Data Privacy or Privacy Governance; itās simply a recollection of what happened to me professionally in the last months. I've recently become a CIPT (Certified Information Privacy Technologist) by IAPP in an interesting drift from my usual career chores.
As I sit down to write this, I feel still tired from the effort that was preparing for the CIPT certification, which I achieved last Friday. My background in technology had always been an engineering one: understanding how things work in detail to then find solutions to user&business problems. Little I knew about compliance, regulations and the absolute need of answeringĀ āit dependsā to questions related to those fields. In my mind, everything either worked or didnāt work and responses to queries were mostly binary:Ā āyes, it works (or could work)ā,Ā āno, Iām afraid thatās not possibleā. When it comes to interpreting frameworks for data management, conforming to standards, implementing privacy policies or responding to queries about regulations, there is certainly a bit more than that.Ā
It all started last year as the efforts to prepare for the upcoming GDPR regulation were gearing up. I was asked to join an internal workgroup of representatives from all business areas to coordinate efforts needed to achieve compliance. Being part of the sales organization, my focus would be ensuring that we had everything we needed to address customer concerns while at the same time making sure we were conducting business following the new requirements. Easy. Thatās until, on a flight from Dublin to San Francisco, I tried to read the entire regulation (which comprises 99 articles and 173 recitals) in one go; massive fail (and the flight is 11 hrs long).
Iāve read now the entire thing but taking a more pragmatic approach. I started with the principles, the basics, and then drilled down into each of the chapters whenever I got a question related to it or we were discussing that area in one of our fortnightly meetings in the working group. If you want a list of all things I used to get acquainted, see the end of this post.Ā
I also started to network and expand my social profiles to include organizations, companies and professionals that were much more experienced than me in Privacy. I used mostly Twitter and LinkedIN to connect. As part of these efforts, I joined the IAPP organization, went to the Infosecurity 2018 event in London and joined a few groups on LinkedIN. And then I came to explore how I could certify all my efforts, to prove both myself (to know if I was up to the level expected) but also to demonstrate to customers that I did my duties and know the stuff. From the different certifications available by IAPP, the CIPT is the one that made the most sense, taking into account my previous education and background. I might post a follow up article to this explaining what I did to prepare because I found the exam quite challenging and thereās not too much information out there that can guide people to prepare well.Ā
And so, here I am now taking a bit of a drift in my career and exploring the area of Privacy in Technology. Is it something that I enjoy? Well, yes, it is challenging in a way that itās different from what Iāve done in the past and as I said, there are no definitive answersĀ to problems or situations, which pushes you to really be listening and understand the context. It really develops the consultative skills Ā which are sometimes forgotten in sales.Ā
So from now on expect some posts on the topic and also on some of the situations I face on a regular basis at work talking to customers. As promised before, some of the resources I used to get started:
Read the GDPR regulation. This site offers a better user friendly interface than the official one.
The guys from OneTrust (a vendor that has a software to help you in your compliance journey to GDPR) have created a really nice app for mobile devices that has the text of the GDPR well organized as well as links to the main DPAs of each EU country and the main privacy associations. Get it here (for iOS) and here (for Android). And read again the GDPR.
Follow a few accounts on Twitter: @EU_EDPS (the European Data Protection Supervisor), @ICOnews (the UK Information Commissioner Office), @maxschrems (a troublemaker for some, a privacy hero for others), @ToSDR (Terms of Service;Didnāt Read. Name says it all).
Consider joining an organization that deals with Privacy. The main one is IAPP.Ā
Have any other resources to share? Comments? Please do!
Chema













