SlideShare a Scribd company logo
PRODUCT MANAGEMENT – GDPR
FOCUS & STRATEGY
Ankita Kapoor
› IMPACT OF GDPR ON BUSINESSES
› GDPR SDLC
› PRODUCT MANAGER’S STRATEGY FOR GDPR
› KEY PODUCT FEATURES FOR GDPR
› EXAMPLE GDPR PRODUCT BACKLOG
AGENDA
Ankita Kapoor
IMPACT OF GDPR ON BUSINESSES
GDPR Compliance – Benefits
› No additional spending on Customer Acquisition Cost (CAC) and Customer Retention Cost (CRC)
› Competitive edge over businesses who aren’t compliant or marketing enough
› Expansion of customers base around the world because of additional trust
› Availability of consented and dependable customer data
› Intelligent digital marketing campaigns and hyper-personalization
GDPR Non-compliance – Loss
› Loss of EU customer base worldwide
› Loss of revenue and profits from the EU region
› Fines of up to 4% of annual global turnover, or 20 million EURO
Ankita Kapoor
GDPR SDLC
› Privacy by Design and Default
› Threat Modelling
› Secure Development Lifecycle
› Dynamic Testing
› Penetration Testing
› Configuration Guidelines
Design
Development
Testing
Release
Ankita Kapoor
PRODUCT MANAGER’S STRATEGY FOR GDPR
› Interface with the Legal team and DPO
› Fresh look at Customer and Customer Data
› Understanding what data 3rd Party Service Providers/Vendors have
› GDPR Compliant Product Backlog
› GDPR focused Non-functional Documentation
› Configuration Guidelines for every Release / Production
› Testing is the key!
Ankita Kapoor
MAIN PRODUCT FEATURES FOR GDPR
Right to data
portability – Import/
export
Right to access
and
accuracy
Erasure (right to be
forgotten)
Redefine customer
data
mapping
Vendor onboarding
and complianceRight to restrict
processing
Security
and encryption
Consent
management
platform
Ankita Kapoor
EXAMPLE GDPR PRODUCT BACKLOG
# Epics Stories
1 Redefine customer data
mapping
› Create new database system for storing and accessing data
› Interface for internal users to interact with data and retrieve it
2 Right to access and accuracy › Interface for customers to view data
› Interface for customers to request for rectification
3 Right to data portability – Import
customer data
› Create central repository to host data from different data storage
locations
› Define mapping, file extensions, sources
› Interface for internal users to view and process data
4 Right to data portability – Export
customer data
› Convert imported data into a human readable format
› Define file structure and extension
› Interface for internal users to process the request
› Interface for customers to request data
Ankita Kapoor
# Epics Stories
5 Erasure (right to be forgotten) › Impact on internal applications and customer facing applications
› Impact on backend/database
› Auto-delete once data is no longer required
› Exempted data – what cannot be deleted (UI and DB handling)
6 Right to restrict processing › Add ‘data private’ option – impact of blocking and suppressing data
7 Consent management platform › Robust cookie policy – detailed consent form for customers
› Add ‘opt-in’ option
› Update agreement policies in all applications
8 Vendor onboarding and
compliance
› Checklist of compliance and necessary certificates
› Awareness program, DIY tutorials videos and support team
› Interface for processing customer requests (to view, edit, delete or port
customer data)
EXAMPLE GDPR PRODUCT BACKLOG (CONTD…)
Ankita Kapoor
# Epics Stories
9 Workspace setting center › Interface for team collaboration and administrator
› Data consolidation from different departments
10 Register of data processing
activities
› Audit trails and change logs to be maintained – DB and UI
11 Login and password policies › Revisit login and password policies
› Evaluate different options like cryptography hash functions etc.
12 Security and encryption › Revisit data security and encryption layer through out the application
13 Marketing GDPR › Mention GDPR compliance on all possible places in the application
14 Technical Debt › Assessment and scoping for the same
Ankita Kapoor
EXAMPLE GDPR PRODUCT BACKLOG (CONTD…)
THANK YOU!
Ankita Kapoor

More Related Content

PDF
Steinberg - Customer identity as the cornerstone of our approach to digitaliz...
PDF
Partner enablement GDPR
PPTX
#GDPR Compliance - Data Minimization via ArchivePod
PDF
Partner enablement GDPR
PPTX
Establishing sustainable GDPR compliance
PDF
Analyst Webinar: Best Practices In Enabling Data-Driven Decision Making
PDF
Auditing With Automation
PPTX
GDPR: 20 Million Reasons to get ready - Part 1: Preparing for compliance
Steinberg - Customer identity as the cornerstone of our approach to digitaliz...
Partner enablement GDPR
#GDPR Compliance - Data Minimization via ArchivePod
Partner enablement GDPR
Establishing sustainable GDPR compliance
Analyst Webinar: Best Practices In Enabling Data-Driven Decision Making
Auditing With Automation
GDPR: 20 Million Reasons to get ready - Part 1: Preparing for compliance

Similar to Product management gdpr focus and strategy ankita kapoor-24 april 2018 (20)

PPTX
Monitoring in the DevOps Era
PPTX
Customer-Centric Data Management for Better Customer Experiences
PPTX
Customer-Centric Data Management for Better Customer Experiences
PDF
Entry Points – How to Get Rolling with Big Data Analytics
PPTX
Mark logic Industrialize Your Data IOT Berlin Sept 2019
PDF
GDPR- The Buck Stops Here
PDF
Data Con LA 2022 - Practical Solutions to Complex Supply Chain Problems
PDF
Privacera Databricks CCPA Webinar Feb 2020
PPTX
CCPA Compliance for Analytics and Data Science Use Cases with Databricks and ...
PPTX
How Cloudera SDX can aid GDPR compliance
PDF
Logical Data Fabric: Maturing Implementation from Small to Big (APAC)
PDF
[Webinar] - How to Future-proof Your ERP Applications with Intelligent Automa...
PPTX
Improving Agility While Widening Profit Margins Using Data Virtualization
PPTX
Klarna Tech Talk - Mind the Data!
PPTX
Medical Device UDI Compliance in the Cloud
PDF
Denodo DataFest 2016: ROI Justification in Data Virtualization
PDF
Accelerating the Data to Value Journey
PPTX
Pistoia Alliance European Conference 2015 - Stuart Robertson / Exostar
PPTX
CASE STUDY: SCHUBERG PHILIS
PDF
ERP Software Solution
Monitoring in the DevOps Era
Customer-Centric Data Management for Better Customer Experiences
Customer-Centric Data Management for Better Customer Experiences
Entry Points – How to Get Rolling with Big Data Analytics
Mark logic Industrialize Your Data IOT Berlin Sept 2019
GDPR- The Buck Stops Here
Data Con LA 2022 - Practical Solutions to Complex Supply Chain Problems
Privacera Databricks CCPA Webinar Feb 2020
CCPA Compliance for Analytics and Data Science Use Cases with Databricks and ...
How Cloudera SDX can aid GDPR compliance
Logical Data Fabric: Maturing Implementation from Small to Big (APAC)
[Webinar] - How to Future-proof Your ERP Applications with Intelligent Automa...
Improving Agility While Widening Profit Margins Using Data Virtualization
Klarna Tech Talk - Mind the Data!
Medical Device UDI Compliance in the Cloud
Denodo DataFest 2016: ROI Justification in Data Virtualization
Accelerating the Data to Value Journey
Pistoia Alliance European Conference 2015 - Stuart Robertson / Exostar
CASE STUDY: SCHUBERG PHILIS
ERP Software Solution
Ad

Recently uploaded (20)

PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Encapsulation theory and applications.pdf
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Review of recent advances in non-invasive hemoglobin estimation
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Electronic commerce courselecture one. Pdf
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Approach and Philosophy of On baking technology
PPTX
MYSQL Presentation for SQL database connectivity
PPT
Teaching material agriculture food technology
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Encapsulation theory and applications.pdf
Mobile App Security Testing_ A Comprehensive Guide.pdf
Review of recent advances in non-invasive hemoglobin estimation
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
“AI and Expert System Decision Support & Business Intelligence Systems”
NewMind AI Weekly Chronicles - August'25 Week I
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
The AUB Centre for AI in Media Proposal.docx
Electronic commerce courselecture one. Pdf
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Advanced methodologies resolving dimensionality complications for autism neur...
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Per capita expenditure prediction using model stacking based on satellite ima...
Approach and Philosophy of On baking technology
MYSQL Presentation for SQL database connectivity
Teaching material agriculture food technology
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Ad

Product management gdpr focus and strategy ankita kapoor-24 april 2018

  • 1. PRODUCT MANAGEMENT – GDPR FOCUS & STRATEGY Ankita Kapoor
  • 2. › IMPACT OF GDPR ON BUSINESSES › GDPR SDLC › PRODUCT MANAGER’S STRATEGY FOR GDPR › KEY PODUCT FEATURES FOR GDPR › EXAMPLE GDPR PRODUCT BACKLOG AGENDA Ankita Kapoor
  • 3. IMPACT OF GDPR ON BUSINESSES GDPR Compliance – Benefits › No additional spending on Customer Acquisition Cost (CAC) and Customer Retention Cost (CRC) › Competitive edge over businesses who aren’t compliant or marketing enough › Expansion of customers base around the world because of additional trust › Availability of consented and dependable customer data › Intelligent digital marketing campaigns and hyper-personalization GDPR Non-compliance – Loss › Loss of EU customer base worldwide › Loss of revenue and profits from the EU region › Fines of up to 4% of annual global turnover, or 20 million EURO Ankita Kapoor
  • 4. GDPR SDLC › Privacy by Design and Default › Threat Modelling › Secure Development Lifecycle › Dynamic Testing › Penetration Testing › Configuration Guidelines Design Development Testing Release Ankita Kapoor
  • 5. PRODUCT MANAGER’S STRATEGY FOR GDPR › Interface with the Legal team and DPO › Fresh look at Customer and Customer Data › Understanding what data 3rd Party Service Providers/Vendors have › GDPR Compliant Product Backlog › GDPR focused Non-functional Documentation › Configuration Guidelines for every Release / Production › Testing is the key! Ankita Kapoor
  • 6. MAIN PRODUCT FEATURES FOR GDPR Right to data portability – Import/ export Right to access and accuracy Erasure (right to be forgotten) Redefine customer data mapping Vendor onboarding and complianceRight to restrict processing Security and encryption Consent management platform Ankita Kapoor
  • 7. EXAMPLE GDPR PRODUCT BACKLOG # Epics Stories 1 Redefine customer data mapping › Create new database system for storing and accessing data › Interface for internal users to interact with data and retrieve it 2 Right to access and accuracy › Interface for customers to view data › Interface for customers to request for rectification 3 Right to data portability – Import customer data › Create central repository to host data from different data storage locations › Define mapping, file extensions, sources › Interface for internal users to view and process data 4 Right to data portability – Export customer data › Convert imported data into a human readable format › Define file structure and extension › Interface for internal users to process the request › Interface for customers to request data Ankita Kapoor
  • 8. # Epics Stories 5 Erasure (right to be forgotten) › Impact on internal applications and customer facing applications › Impact on backend/database › Auto-delete once data is no longer required › Exempted data – what cannot be deleted (UI and DB handling) 6 Right to restrict processing › Add ‘data private’ option – impact of blocking and suppressing data 7 Consent management platform › Robust cookie policy – detailed consent form for customers › Add ‘opt-in’ option › Update agreement policies in all applications 8 Vendor onboarding and compliance › Checklist of compliance and necessary certificates › Awareness program, DIY tutorials videos and support team › Interface for processing customer requests (to view, edit, delete or port customer data) EXAMPLE GDPR PRODUCT BACKLOG (CONTD…) Ankita Kapoor
  • 9. # Epics Stories 9 Workspace setting center › Interface for team collaboration and administrator › Data consolidation from different departments 10 Register of data processing activities › Audit trails and change logs to be maintained – DB and UI 11 Login and password policies › Revisit login and password policies › Evaluate different options like cryptography hash functions etc. 12 Security and encryption › Revisit data security and encryption layer through out the application 13 Marketing GDPR › Mention GDPR compliance on all possible places in the application 14 Technical Debt › Assessment and scoping for the same Ankita Kapoor EXAMPLE GDPR PRODUCT BACKLOG (CONTD…)