American Data Protection Act – Noris Ismail, Breakwater Solutions
Noris Ismail, managing director for Breakwater Solutions, explains what organizations should expect once the American Data Protection Act becomes the law of the land in the U.S.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Norris Ishmael who is managing director for Breakwater Solutions? And we're talking about data privacy in the legislation that we're all about to see go through Congress Norris. Welcome to the shop.
Thank you so much Mike for having me here. Hello from London, right? So we are finally putting together something that looks like the American data protection act.
It's Sure, it will change in its many forms as we wind through the legislative process, but from your perspective, we've already seen in Europe the gdpr and these two efforts are somewhat similar. So what should it organizations in cybersecurity professionals get prepared for here as we put this all together. Sure, I'll text myself very very good question as we learn throughout the process, you know, not just in a context of the current debate in the Congress.
But as well as the outside the US view about the current progress privacy professional cyber Security Professionals, not the government's professionals. Even CPO chibiency offices General console, even if level have been looking into how exactly the car in. Ongoing you know kind of progress.
Okay would actually be much more pragmatic rather than over prescriptive and too prescriptive like the gdpr experience of five years ago during the debate and also the lobbying in Brussels. So it is one angle that perhaps you know, relevant stakeholders need to think about because of twofold. The first is we've seen many data driven organizations have been innovating and also Reinventing and re-engineering the technology The Innovation and just to ensure that everything is like, you know based on your business model and strategy, but at the same time, okay, whatever legislation at the federal level that the current, you know are initiative by the Congress is currently debating.
Hopefully, it would not undermine and inhibit whatever Innovation and digital picture from the US perspective, which is important because we've seen some of these, you know blocking mechanism not only from the perspective. Of the technological, you know sophistication and as well as in nutrition, but also we've seen lots of debate about okay, whether some technologies and the business model might be relevant and ethical in a context of data processing activities and the principles of privacy laws, you know that are quite you know dominant not just from the gdpr perspective but also other state privacy laws in the US and of the sector especially laws in the US, so that's the first very high level in a lens another very hell of Alliance that we have seen based on HTTP experience Mike Visa V the US experience. Is that even though gdpar is a One-Stop shop, but in reality we've seen regulate this individual Regulators dictionary authorities in the UK, I feel for example, and also kneel French and hamburger Bavaria in the Germany and the Dutch Authority in the Netherlands and the Irish Commission in Ireland.
Might have sipped in difference in terms of how they View and provide that kind of guidance. So I think that one stop shot mechanism is actually not fully One Stop Shop partly because of different views the technical views the commercial views and also the cultural aspect on the ground. Okay within the European economy area in the UK.
So I think it's also an aspect which in America maybe it's learning and will be fully aware especially from the FDC perspective, but we'd be good to actually like really take some of this Lessons Learned in the current debate, you know in the Congress within the widest stakeholders. It's probable that the US version of this will be less prescriptive than gdpr given the nature of the politics that we deal with here. But it's also probable to that right now our situation may be worse than it is without this legislation because right now we have 50 states that are all going to have different versions of these laws put into place and the ones in California are likely to be more prescriptive than say the ones in Texas.
So do you think at the end of the day that we should all be kind of rooting for this because it would bring some clarity to the situation. I love the question why I think there's two set of the coin. The first of the coin is if we look into the more Innovative State like California, for example, right?
There's a CCPA cpra and very much like a mini gdpr, even if not 100% late gdpr, but in reality on the ground what we've seen is that most of the compliance activ It's very much like pepper base box taking exercise, right? Okay, we have updated they noticed we're not in the previous policy. Okay, if you want to complaint, okay, there's a complete mechanism and you have the right to actually like request for delicious not excess or Eurasia or perhaps, you know, correct the data.
And it's still an evolving process in California, which actually in a way some of their jurispritives are influenced by or triggered by the gdpr on the other hand. If you look into other success rate legislation in the US like, you know the copper and as well as jailba and people, you know, which really come cover the covered entities in the US there are certain level of maturity, which I think that needs to be maintained and partly because the data sets are very much personal data set. So to speak I think the challenge that America is having right now as I say 50 states or 50 states like more than 20 States own relevant it state laws and there are also for coming legislation that will be paused at a state level and you also have this ongoing debate in the federal level.
And this is the preemption, you know, kind of mechanism which is still being debated, you know by the Congress and also even by policy makers and Also, there's also the private right of action, which is a very delicate, you know angle as well, you know in the context of America, you know landscape and on the one hand the business or the cab of Commerce in the US argue that okay. This should not be really, you know, be passed to the Congress because there's a lack of stakeholders consultation because politician across a wide Industries in the you know driven sectors, but on the other hand this actually, you know, really high enthusiasm and law being towards, you know, really push and as the rate this because this has been around for quite sometimes that more than five years, you know initially when they wanted to really have this at the federal level, I think because of the complexity of the Mosaic of the US landscape in my view is important to look into you know, what exactly the highest risk and versus the technological innovation technological kind of breakthrough because Actually did a technology, you know, when it comes to anything that deals with Innovation and at the same time how to stabilize whatever kind of innovation versus the legislation because we do not want it to be over-regulated. I'm not saying that the gdpr is over-regulated.
But at the same time there is still an encouragement, you know for the business to get engaged and then to keep on telling the regulators and as well as a draft test that actually in relative is what it means. I think it's important for the stakeholders to really outline scenarios by scenarios based on sectors by sectors and to look into the top three the top five race so that it will be well articulated a spot of the logic and the conversation in the Congress. mmm A lot of the organizations especially here in the US or a little haphazard when it comes to data management.
Shall we say did you see in Europe that once gdpr went in that people's elevated their data management capabilities and their best practices and they got better at managing data or you know did have minimal effect. I like to answer this way. It depends my it's like a lawyer kind of answer.
It depends on how it's like lead organization is it depends of the governance structure and how mature the government structure is and it depends on how exactly the board of directors the leadership and as well as security Champion dictator Champion really Cascade the importance of data management into the why the business we're taking example if let's say Fortune 500 companies or 1450 companies in the US if they have a very strong leadership strong tone that telling to The Wider in entities globally a slightly us. Okay guys previously by Design Secret by Design on me. That's a life cycle.
That's our retention that the religion is all very very important and we need to Cascade it to the weather, you know operations and why they're entities like, you know the us but of course there's a local variation Regional variation into the daytime management. So that will be like the best model to be repl. That however, what we've seen right now is that companies are innovating and structuring and restructuring the business partly because of geopolitical risks partly because other risks that triggered, you know by other unsystematic risk, you know from the business partly because of sanction and partly because of other, you know, estimated investigation by Tech party or Auditors or even Regulators.
So at that management level is important to really look into treating the first is understand that taxonomy. I have been re-emphasizing this many many times not just in the context of the UK and Europe but also the US take all this and US organizations and second understanding the data life cycle. How what is like your debt of life cycle?
And how you deal with this? Do you actually bring siso in the conversation the CPO in the conversation Marketing in the conversation HR in the conversation even strategy guys in the conversation. And and the third is prioritizing what needs to be prioritized take the top two or top three highest risk in your data management, you know environment assuming your highest rates is transferred data outside the US especially to countries which are actually quite high risk in terms of the business dealing or perhaps, you know a market then you need to think about a very different Innovative approach towards that but the reality Mike that we've seen in the market is that you need technology and solution to do is you can't use spreadsheet you can use what form what what format you can't use manual, you know steps or workflow and this is where a lot of organizations are struggling not only in the context of you know multinational but also the contest of startup medium-sized companies and as well as companies that might be subjected to merge as an acquisition.
So in short to ask your question might yes determination is important. Go back to basic try to simplify the narratives, especially at the bot level management level and case get it to the widest stakeholders so that they understand what is it all about? Okay, do not assume that they understand your technical expertise and language and try to tell them like as if that you're teaching, you know sculpture and so to speak should I just fight the bullet and try to comply with gdpr now and the assumption that if I meet that one, I'll comply with the American one and I'll just be ahead.
Yeah, I think what we have seen a lot, you know in the market globally. Mine is that most of this, you know multinationals in the US that really regard Brands and also just products and services as like a strategy kind of positioning in the market. They actually take gdpr as a global framework Baseline framework.
So what it meant by Baseline is that right? We uses a baseline, but it doesn't mean that we are going to use 100% what gdpr says right and we still have the CCPA cpra for California. And we also have the second specific, you know legislation, you know in the US and as well as some of the states in the US and there's different kind of like kind of scorecard but you look into the richest sport.
It might be right. It might be Amber. It might be green.
So the risk posture and maturity might be different in its compared to want to another so we've seen most of the multinationals are taking that approach what I'm saying is To it, you know multinational which have a very strong brand to sort of yeah brand premium and also their brand value and Market valuation on the other hand. We have to see lots of online businesses or even startup or even if startup that might be, you know, a quiet by a big boys a big companies where they actually focus on information security cyber security first because they know that okay. This is very important and we need to invest more on the controls on the framework, but when it comes to privacy, they will actually prioritize and reparatize and read align one is to be realigned and it's actually just strategy it works in in a very small and sizeable environment.
But once you go into the cloud environment, that's where the complexity will come in because you'll be potential risks in terms of where did that goes? How long you really how long you keep the data and you delete the data or you to keep the data forever, so there will be like the Scenarios mic that of the Racine in in the market, but then again, you know this actually a journey and still working progress. hmm Do you think that these privacy regulations change the way people think about cybersecurity and the cybersecurity becomes something more than just kind of an ounce of prevention.
It's more about we need to actually think about this in terms of these finds and the fines are substantial. So now the security issues are much higher level boardroom discussion. Yeah, if you look into how exactly the data button authorities in the EU or the economic area and in the UK find organizations or even multinationals or the way, they actually investigate it certain breaches of quite delicate and quite Torah.
So to speak even today. It's actually a debate where they highlighted that. Hey Regulators have not done much even though depresses that you might be subjected to 4% of the global annual turnover.
But if you see and if you compare and contrast how the depiction authorities in each of the member states in the EU or even a pretty common area, even if you read and report of the Irish different potential commission diesel in the UK canal in France and some of the German, you know, regulate this, oh the the level of fine it differs, you know from one to another because it goes back to The organizational measure security measure the controls and also the resilience organizational resilience and even very simple stuff like training and awareness data campaigns security Campaign, which actually is a very important as part of, you know, ongoing, you know, kind of Engagement what is stakeholders and also a partners and third-party vendors. So we've seen the trend now Mike is that Global chip obviously officer and siso are actually working closely together. Where previously five years ago, even 10 years ago.
It was very silent in isolation. All right, when it comes to it matters, we just actually give to the Cisco or press the head of ID, you know to deal with this when it comes infrastructure, but now because of this emergence of privacy regulation around the world not just in a context of the US landscape, but also in the Middle Eastern North Africa and also outside, you know, Middle East like in APAC and it's really civilization. We're seeing that the role of information security and cyber security is a much much more important.
It's not like a typical like the help there's or just you know, what through the controls and in the context of data bridge for example the siso and as well as the chip officer have to work together and bring in the data governance guys, even a general console and really, you know, socialize and stress tests the better rich environment or either having a tabletop exercise Market by market Because each of the respective Market has its different approach. Okay, even though gdpr for example says 72 hours, but it doesn't mean that all right, you have to like deal with this space again in the context of you know, the 72 hours again. It depends on the severity of the bridge.
It depends on to what extent that you know the data set. Okay, really affected, you know by the breach and having legal consoles to really really involve with the engagement and negotiation and discussion with the regulators and the whitest decorate as well. So in short to summarize, you know aptly to your question answer to your question is that cyber security dictator purposely data governance.
Okay, whatever the role that America, you know has okay typically is cheaper so officer siso shift at the governor's officer shift at the office they have to work and align because if you have this kind of alignment, it can accelerate any kind of matters not only in the context of Each but also engagement with regular this worldwide. Alright, so what's your best advice to folks as we kind of get ready for this next round of legislation that seems inevitable but what should people be doing or what do you wish most people would do before they get started that you've seen from your gdpr experience. I think there are three things that you know, perhaps the US landscape Canada and from you know, the EU we open the coming year and as well as the UK the first is of address the basic principles very clearly and in Clarity because if the principles are not address in Clarity in a very clear way with illustration with example, okay, the debate will be like, you know around the bush you'll be like ongoing, you know, having brother having a consensus to do is it because the principles are so important and when I look to the text when I cross referred to the current tax of this American did protection Privacy Act versus gdpr there's some similarities, but I think that A quite small Clarity in terms of you know, the principles and as well as exemption and a second you'll be good to also provide in a clear kind of illustration to what extent that exemption applies, you know versus other state laws or preemption versus other state laws.
And as well as certain definition that requires more specific in illustration rather than very vague and very broad, you know, kind of illustration. Oh with a cave it I'm not a lawyer but based on my experience as a data protection practitioner Consulting impression, which help organizations to operationalize the global different program. Once you know, the organization has secured a secure son of the good advice is important to really dissect the things on me that triggered by the relevant principles and then simplify, you know to the whitest.
They call this I think that's a second, you know guidance, which I think is important the Third. Which I think that the relevant stakeholders in America, you know, whether corporate policymakers academics or even insurance or Brokers and as well as a privacy Advocate, even you know, any, you know about political parties, of course, it's a very bipartisan continitative. They also need to engage with some of their peers in the EU institutions when I say engagements that all right?
Okay, we are undergoing what you guys have undergone like five years ago. Okay. 0 which still you know will be debated, you know in your big commission, hopefully in by Future for or next year onwards and still working progress.
And having that kind of Engagement with the depression authorities in the EU with the UK Ico and even with Apex that opportunities because they're quite very useful lesson that can be learned from the Singapore personal data protection commission or even Japan and even you know, even China because China has pipl which is a federal law very much like gdpr but in China called China context. So once you have this kind of compare and contrast kind of analysis the next step is right? Okay.
What can we do for America to make this clear Clarity with Clarity and we see in a very practical illustration because of the day business want to get clarity what they need to do, you know, once the law will be passed here. All right. Hey Norris.
Thanks for sharing your insights. Thanks so much my plan here. All right guys back to you in the studio.