Search Results
Search this site
197 results found with an empty search
- How to Bake a Cake
Step-by-step guide to baking a delicious cake How to Bake a Cake Step-by-step guide to baking a delicious cake Next Item Previous Item
- IAF Submission to the GDPR Review 2024
IAF Submission to the GDPR Review 2024 February 2024 Home / Publications / Download PDF
- Global CBPR and the Long Dance towards Interoperability
In mid-May I joined colleagues from around the globe for the recent Global CBPR Forum in Tokyo. The event was well attended with over 100 participants – 30 different countries were represented and 28 different DPAs were there as well. The interest in the CBPR is clearly growing with Africa, the Middle East and South America all represented alongside delegates from APEC and across Asia. Representatives from the UK Government, ICO d the German Federal DPA attended as well. The switch from APEC to a Global Forum has generated a new interest and there was a lot of discussion about how the CBPR now needs to scale and create momentum – with government, regulators and companies. While we know that work is underway to consider reforms to the CBPR Framework, there was no detail revealed on the plans to make it more interoperable with other DP laws internationally. There should hopefully be more news on this at the next Forum later in 2024. The reform issue is the key pivot in getting greater involvement from countries, companies and regulators. Aside from the UK’s Associate Membership there were no announcements about new members. Therefore, the CBPR still has the feel of dancefloor with a few participants, many sat on the chairs around the side deciding whether to move on to the floor on join the disco. Multi-stakeholder discussion As part of the Forum, I led a panel on Global CBPR Interoperability with IAF Board Chair Scott Taylor (CPO, J&J), Jacobo Esquenazi (WW Data Protection Officer and Privacy Strategy Director, HP Inc), Stefano Fratta (Global Advocacy and Privacy Policy, Meta), Miguel Bernal-Castillerro from the Canadian Privacy Commissioner’s Office and Evelyn Goh from the Singapore Government. The panel discussed benefits of CBPR as a global accountability mechanism, what the current barriers are, what different stakeholders need to do to address them and create incentives to join the system. The aim of panel was to ensure a multi stakeholder discussion. Key points covered on the panel included: the role of CBPR in creating trust, how it can work as part of wider toolkit to support data transfers and accountability the value CBPR as corporate demonstration and verification of standards applied – mistakes may happen but the certification demonstrates to regulators that due diligence was in place the importance of there being regulatory certainty in how CBPR operates – including statutory recognition of the system in data protection laws and promotion by regulators, including how they consider during enforcement and investigations the challenge of convincing vendors to certify, even if the procuring company offered to pay – as the wider benefits were not clearer enough to the vendor. The panelists agreed there is need to demystify CBPR. Throughout the event there were positive references to the multi-lateral nature of the CBPR, that it generates collaboration between stakeholders and the global dimension now creates an inclusive approach. Discussion also covered the issue of trust and how the structure, process and reliability of CBPR can all contribute to realising it in practice. Despite the lack of detailed plans for reforming CBPR to enhance interoperability with other data protection laws internationally, the conference highlighted the importance of such reforms as a pivotal factor in encouraging countries to join the initiative. AI and CBPR There was also considerable discussion about the role CBPR can play in AI governance and demonstration of accountability across borders. The panel discussing AI and CBPR suggested the CBPR principle on preventing harm could play a significant role in AI governance. There were mixed views on how far CBPR should go to cover AI as this could be make the certification more complex and daunting for new companies. The discussion suggested that there could be a CBPR + plus AI as one solution. There was also interest in how CBPR certification was often put in place alongside ISO certifications such 27001 (less so for 27701). The future is likely to require companies to undertake data governance plus compliance plus ethics – CBPR could help link these elements. The Dance of Participation The Global CBPR System is now up and running and accountability agents can start issuing new certifications from this summer. However, with the APEC certification grandfathered over, and the framework and country membership still the same, this is not much of a step forward towards the dance floor. There were some interesting sessions that looked at the practical mapping of CBPR to other DP laws. Bojana Bellamy from CIPL presented a mapping on Brazil’s law to CBPR, highlighting the level of commonality was strong and how gaps could be bridged, including use of regulatory guidance. The mapping also looked at the picture in reverse and whether the CBPR meets the Brazilian law – highlighting gaps on areas such as automated decision making and breach notification. Building Trust through Collaboration As part of the international data flows initiative in the G7 Group of Data Protection Authorities, the German DPA presented a mapping of GDPR certification system and CBPR, with a particular focus on enforceability of data subject rights and differences between the regimes. Some attendees responded by highlighting the relevance of consumer law in countries such as US, which could hold companies accountable for public assurances they provide, including certification statements, indicating that the gap may not be as great as some assume There was also some discussion as to whether the GDPR certification approach was a fair comparison to CBPR as the GDPR approach requires conformity assessment – discussion then took place as to whether GDPR codes of conduct were a fairer match to CBPR, while noting that GDPR codes are intended to have a sector based scope. Sebastian Ziegler (Director General of Mandat International, with special consultative status to the UN) presented a proposal to bridge between the Europrise Privacy Seal under Article 42 and CBPR – this was an interesting proposal but some saw challenges because of the EU system’s focus on certifying processing activities not privacy management and accountability programmes – companies are likely to be more interested in the latter. The UK also presented a plan to introduce CBPR in their jurisdiction by using a special SCC to bridge gaps with UK GDPR (this was quite light on detail and more will be coming later this year). These technical discussions illustrated the importance of the CBPR system being reformed first and this then makes some of questions around bridging less complex. The collaborative focus of these discussions is a welcome and positive feature of the Forum. The Road Ahead for CBPR Forum participants recognized that a patchwork of approaches will not serve anyone well – there is hope for global interoperability and to recognise data subjects as global citizens. Throughout the event there were positive references to the multi-lateral nature of the CBPR, that it generates collaboration between stakeholders and the global dimension now creates an inclusive approach. The IAF is enthusiastic about the increasing momentum towards greater interoperability, expansion through the Global CBPR Forum. Global CBPR and the Long Dance towards Interoperability June 5, 2024 Steve Wood Articles and News Publications Media
- Apple, Inc.
Apple, Inc. Apple, Inc.
- 2021 Annual Report
2021 Annual Report January 2022 Home / Publications / Download PDF
- Marc Groman
Senior Strategist, U.S. Marc Groman Senior Strategist, U.S. Marc Groman, an internationally recognized expert in privacy and information risk management, advises senior leaders in both business and government on complex, data-driven initiatives. Marc helps clients implement global privacy programs, launch new products and services, conduct due diligence on potential partners, assess privacy risk, and respond to data security incidents. He teaches data breach response at Georgetown Law School and is actively engaged in the policy debate on federal privacy legislation in the U.S. Marc’s expertise in privacy has deep roots: as Senior Advisor for Privacy in the White House, he had government-wide responsibility for privacy policy. He chaired the Federal Privacy Council established by President Barack Obama and was the privacy lead on the President’s Cybersecurity National Action Plan. Prior to his stint in the Obama Administration, Marc was President and CEO of the Network Advertising Initiative, the first Chief Privacy Officer of the U.S. Federal Trade Commission, Counsel to the Energy and Commerce Committee of the U.S. House of Representatives, and Advisor to the Director of the FTC’s Bureau of Consumer Protection. Marc currently serves on the Privacy Advisory Panel of the National Security Agency, the Information Security and Privacy Advisory Board of NIST, and several other boards. He is a frequent speaker on issues relating to privacy, technology, and innovation, and conducts highly customized seminars and tabletop exercises for executives. Marc Groman Senior Strategist, U.S. Marc Groman, an internationally recognized expert in privacy and information risk management, advises senior leaders in both business and government on complex, data-driven initiatives. Marc helps clients implement global privacy programs, launch new products and services, conduct due diligence on potential partners, assess privacy risk, and respond to data security incidents. He teaches data breach response at Georgetown Law School and is actively engaged in the policy debate on federal privacy legislation in the U.S. Marc’s expertise in privacy has deep roots: as Senior Advisor for Privacy in the White House, he had government-wide responsibility for privacy policy. He chaired the Federal Privacy Council established by President Barack Obama and was the privacy lead on the President’s Cybersecurity National Action Plan. Prior to his stint in the Obama Administration, Marc was President and CEO of the Network Advertising Initiative, the first Chief Privacy Officer of the U.S. Federal Trade Commission, Counsel to the Energy and Commerce Committee of the U.S. House of Representatives, and Advisor to the Director of the FTC’s Bureau of Consumer Protection. Marc currently serves on the Privacy Advisory Panel of the National Security Agency, the Information Security and Privacy Advisory Board of NIST, and several other boards. He is a frequent speaker on issues relating to privacy, technology, and innovation, and conducts highly customized seminars and tabletop exercises for executives.
- Origins of Accountability: Accountability Phase I – Galway Project
Origins of Accountability: Accountability Phase I – Galway Project October 2009 Home / Publications / Download PDF
- New State Privacy Laws Square the Assessment and Controls Circle
Demand for advanced data analytic impact assessments has moved from a nice to have to a legal requirement. Twelve new state privacy laws in the United States require these impact assessments that weigh the benefits to all stakeholders and the potential risks to the rights of consumers related to the data processing. These rights are broader than data protection rights more commonly associated with existing privacy laws. To comply with these new laws, many organizations will have to evolve assessment and governance processes to meet the new legal requirements. That much is clear. As of yet, however, there is no common defined standard or common regulatory expectation to direct what the new demonstrable processes should look like. The IAF believes that we can help clarify the evolving regulatory environment by developing a framework of standards for demonstrable accountability. The advent of artificial intelligence (AI) generated the demand for AI impact assessments. Academics, NGOs, and some policymakers increasingly have recommended that organizations enhance their governance systems. Many have pointed to the need for Algorithmic Impact Assessments (AIAs), which assess the potential benefits, risks, and controls to achieve responsible and ethical AI. In response, for example, the Information Accountability Foundation (IAF) and PwC in 2021 drafted Evolving to an Effective Algorithmic Impact Assessment . The 2021 AIA Paper was a result of the drafters’ views that the risks associated with AI introduce a need for impact assessments that are much more expansive and rigorous than those required by current data protection and privacy laws. However, such an assessment soon could be mandated by new laws governing the use of AI and the associated fair implications to people, e.g., EU Proposed Artificial Intelligence Regulation and Canada’s Bill C-27 (specifically the Artificial Intelligence and Data Act (AIDA) part of C-27). In the U.S., standalone AI related legislation is part of some proposed and enacted Federal and State legislation. No consensus has emerged to give us reliable best practices for structuring AI impact assessments. We can say, however, that their scope is broader than requirements found in, for example, GDPR Article 35’s Data Protection Impact Assessments or what is outlined in the EU’s Proposed AI Regulation relating to conformity assessments. While work continues on a federal U.S. AI regulation, an EU Proposed Artificial Intelligence Regulation, and Canada’s Bill C-27 , several U.S. States have passed privacy laws that in effect regulate AI through their broad and comprehensive data protection assessment (DPA) requirements when processing activities “present a heightened risk of harm to consumers” (i.e., risky processing). Key to this particular requirement are the Colorado Rules promulgated under the Colorado Privacy Act (CPA) that came into effect July 1, 2023 and California’s Draft Risk Assessment Regulations (Draft California Regulations). The IAF conducted a rich analysis of this impact in our blog US State Privacy Laws Will Fundamentally Change the Way Businesses Assess Harm and our related Assessment Framework . These new state laws require that a DPA identify and weigh the benefits that may flow, directly or indirectly, to the controller, the consumer, other stakeholders, and the public . The assessments must account for potential risks to the rights of consumers that could result from data processing, while documenting a plan to mitigate risks through commensurate safeguards. The benefit versus risk analysis required by these state privacy laws is different from the weighing required by privacy laws anywhere else in the world. These closely aligned developments in the world of AI governance have resulted in the squaring of the many different impact assessment and control requirement circles from public policy, legislative, and responsible AI standpoints. And so, these twelve new state privacy laws have the potential to influence the way current laws, regulations, and rules are applied. Further, they are well-positioned to shape the way future laws will be structured globally. However, these new laws and proposed AI laws, such as in Europe and Canada, could have a much broader impact in at least two respects. First, these new or emergent pieces of legislation require enhanced governance controls and processes (either explicitly or implicitly) that go beyond those envisioned by the original Essential Elements of Accountability and Accountability Guidance issued by several regulators. [1] For example, the Colorado Rules and Draft California Regulations require the explicit description and communication of specific processes that have been employed by the organization to mitigate risk. The Guidance on AI and Data Protection by the Information Commissioner’s Office in the United Kingdom and the NIST AII Risk Management Framework are two examples of where policy makers and regulators are expecting more explicit and demonstrable accountability processes. In many organizations, these controls do not exist, and so organizations are caught playing catch up in a quickly evolving regulatory landscape. Second, and relatedly, the new set of laws coming out of the U.S. could pave the way for increased interest from regulators in impact assessments. A regulator, for example, a State Attorney General, can ask to receive a DPA, and it is therefore likely they also would ask for details on processes and controls associated with key risk mitigators. This same requirement to produce an assessment to a regulator exists in the proposed EU AI Act and Canada’s C-27. This production potential leads to the asking of the following types of questions outlined in IAPP’s Regulators’ rulebook for AI: Bit by bit ( iapp.org ) : What policies, procedures and people do you have in place to assess AI risk and safety? Who is involved in assessing AI risks and have they have been sufficiently mitigated for product release? What are those individuals’ roles, reporting structures, titles, departments, and relevant expertise? What risks did you take into consideration? What risk mitigation measures did you implement? What methods did you use to train or retrain your models? New requirements for DPAs will trigger regulators’ requests to show or demonstrate new accountability requirements. The immediate impact of this likely will be felt first in the U.S. as a result of the new state privacy laws. Today, there is no common standard or common regulatory expectation as to what these new demonstrable processes should consist of. The unknown factors include how DPAs and other assessment requirements should be structured. This lack of clarity can create uncertainty for businesses who wish to increase their use of data as part of their strategies. And so, we risk regulators stepping in and setting standards that may not reflect a full understanding about business imperatives or how technology works, all without the involvement of business. Let us hope that in the months and years ahead we do not affirm the saying that “bad facts make for bad law”. But let us do more than hope. By working together, business and regulators can develop effective “demonstrable accountability” standards of practice for regulatory guidance (this was the result of the original accountability dialogue in 2009-11) and provide some clarity for business. The IAF believes that we can help clarify the evolving regulatory environment by developing a framework of standards for demonstrable accountability. Look for a specific proposal from the IAF in the coming months as our research progresses. [1] In April 2012, the Office of the Privacy Commissioner of Canada (OPC) and the Offices of the Information and Privacy Commissioners (OIPCs) of Alberta and British Columbia worked together to develop “Getting Accountability Right with a Privacy Management Program” (Canadian Guidance), which set forth the appropriate policies and procedures an accountable organization must have in place that promote good practices which, taken as a whole, constitute a privacy management program. New State Privacy Laws Square the Assessment and Controls Circle September 10, 2023 Peter Cullen Articles and News Publications Media
- Anonos
Anonos Anonos
- 2024: Quarterly Spotlight - Q2-3
IAF 2024 Q2-3 Quarterly Spotlight The second quarter has focused on building out the content for our two projects designed to support organization need to innovate responsibly with data while being responsive to compliance demands in Europe and the U.S. States – “ Demonstrable Evidence of Accountability for U.S. States ” and “ Legitimate Interest for an AI World ”. We conducted several participant interviews, held four workshops and published blogs on the topics. Final reports will be published in the fall. April 1, 2024, IAF hosted a Cocktail Reception for members and friends. Chief Strategist Elizabeth Denham gave a talk on the necessary Renaissance of the Privacy Profession . April 2, 2024, IAF Chief Strategist Elizabeth Denham hosted a conversation with Baker McKenzie Tech Policy Forum, on re-architecting governance in organizations in response to the demands of AI innovation . Discussants included IAF members and non-members. April 3, 2024, IAPP Global Privacy Summit, IAF Chief Strategist Elizabeth Denham introduces keynote speaker Anu Bradford , author of “Digital Empires: The Global Battle to Regulate Technology.” April 10-11, 2024, Elizabeth Denham CBE contributed to Canadian government discussions on Bill C27 approach to “the best interests of the child”. April 11, 2024, a chat led by Elizabeth Denham unpacked the week after the IAPP Global Summit trends in information governance, the role of the privacy leader , and the omnipresence of AI. April 15, 2024, Publication – IAF Comments to ICO AI Consultation, Part II . Strategists Lynn Goldstein and Steve Wood submitted the IAF comments, noting the consultation’s overly broad approach to generative AI, suggesting the distinction and nuance of “thinking and acting with data.” April 16, 2024, Blog by Chief Strategist Elizabeth Denham, A Renaissance for the Privacy Profession. Liz shares her perspective on the external and internal drivers and changes pushing traditional privacy leaders into a renaissance approach – building and applying multiple new skills. May 2, 2024, Demonstrable Accountability for U.S. States Business Workshop, San Jose, CA (hosted by IAF Advisory Board member Cisco). Business members provided feedback to the content and process to the normative risk framework. May 9, 2024, a chat highlighting the insights from the business workshop on what Demonstrable Accountability with supporting evidence looks like in response to U.S. State laws. We learned that how the State requirements are driving deep thoughts about how to implement governance requirements in their own environment. Mid-May, 2024, Global CBPR Forum in Tokyo. IAF Senior Strategist Steve Wood represented IAF, moderating a panel on “Global CBPR Interoperability” with IAF Board Chair Scott Taylor (CPO, J&J), IAF Policy Board Member Jacobo Esquenazi (HP Inc), Stefano Fratta (Meta), Miguel Bernal-Castillerro (Canadian Privacy Commissioner’s Office) and Evelyn Goh (Singapore Government). Steve wrote about his observations and what’s likely next in a blog Global CBPR and the Long Dance towards Interoperability. May 23, 2024, Policy & Strategy call on Digital Marketplace of Mental Health Apps and the broader privacy and security issues. Featured speakers: Maneesha Mithal, Partner, Wilson Sonsini (former Head, FTC Privacy and Identity Protection Division); Jolynn Dellinger, Senior Lecturing Fellow in Privacy, Ethics, and Technology, Duke University School of Law; IAF strategist Marc Groman. May 30, 2024 and June 2, 2024, Legitimate Interest for an AI World Business Workshop, Dublin, Ireland and London (hosted by IAF Board members IPG and Cognizant). Business members provided feedback to the content and process for the Legitimate Interests assessment. June 13, 2024, a chat on all things Europe -What might be the policy impacts and implications resulting from the dramatic EU Parliamentary elections, and what shifts can be anticipated out of the upcoming UK elections. June 20, 2024, a Policy & Strategy call about the increasing demands from the C-Suite and regulators to create sustainable data and technology frameworks, changing the role of privacy and privacy professionals in an age of Gen AI and sprawling new legislation. Do we face a renaissance in the profession in an unpredictable world? Featured speakers Hilary Wandall, Chief Ethics and Compliance Officer, Dun & Bradstreet, and Lauren Reid, Founder, The Privacy Pro. July 10, 2024, Multi-Stakeholder Session on Demonstrable Accountability for U.S. States, Pleasanton, CA (hosted by IAF member Workday). Business members, academics and regulators (California and Colorado) provided feedback to improve the content and process to the risk framework under development. July 18, 2024, Policy & Strategy call was a deep dive into what we learned during the multistakeholder session, attended by regulators, academics and business – and what’s next for business as we see the passage of over 20 U.S. state privacy laws and one state AI Act, almost all of these states require a risk or data protection assessment which are broader in scope than other impact assessments. Sheila Colclasure and Stan Crosley were featured commenters. July 25, 2024, a chat about the evolving nature of expectations of assessments in light of AI innovation. The U.K. ICO Office decision on Snap's My AI and the need for a complete DPIA and DPA consultation per GDPR Articles 35 and 36, and the NIST plan to align its Privacy Framework (PF) V.1.0 with NIST Cybersecurity Framework (CSF) v.2.0, plus future alignment with the AI Risk Management Framework (AI RMF). July 31, 2024, IAF submits comments to the U.S. NTIA on the NIST Privacy Framework v1.1 Concept Paper. August 9, 2024, Blog by IAF President Barb Lawler noting that the IAF Sees NIST Making Notable Advances in Their NIST Privacy Framework v.1.1 Concept Paper. Coming Up: September 11-12, 2024, IAF Annual Member Retreat (hosted by J&J, New Jersey) September 26, 2024, Multi-Stakeholder Session on Legitimate Interest in an AI World, Dublin, Ireland (hosted by IAF member Workday). Business members, academics and DPAs will provide feedback to the content and process to the Legitimate Interests assessment for uses of AI. October 28, 2024, 3-5pm, Global Privacy Assembly in Jersey - side event on the results of the Legitimate Interest Assessment for AI and Forward-looking Projects. 2024: Quarterly Spotlight - Q2-3 September 2024 Home / Publications / Download PDF
- Artificial Intelligence, Ethics and Enhanced Data Stewardship
Artificial Intelligence, Ethics and Enhanced Data Stewardship September 2017 Home / Publications / Download PDF
- TELUS
TELUS TELUS
- Fair Processing Principles to Facilitate Privacy and Data Protection Legislation
Fair Processing Principles to Facilitate Privacy and Data Protection Legislation January 2019 Home / Publications / Download PDF
- Lynn A. Goldstein
Senior Strategist Lynn A. Goldstein Senior Strategist Lynn A. Goldstein is the former Chief Data Officer for the Center for Urban Science + Progress at New York University. Prior to joining NYU, Lynn was the Chief Privacy Officer and Privacy General Counsel for JPMorgan Chase from 2004 to 2013 and was the Chief Privacy Officer for Bank One from 2003 to 2004. From 2001 to 2004, Lynn was General Counsel for Bank One’s credit card company, and from 1983 to 2001, she was Head of Litigation for Bank One, First Chicago NBD and First Chicago. Prior to joining JPMorgan Chase and predecessor entities, Lynn was in private practice and clerked for a federal judge. Lynn is a lawyer and a Certified Information Privacy Professional and a frequent speaker on privacy topics. Lynn A. Goldstein Senior Strategist Lynn A. Goldstein is the former Chief Data Officer for the Center for Urban Science + Progress at New York University. Prior to joining NYU, Lynn was the Chief Privacy Officer and Privacy General Counsel for JPMorgan Chase from 2004 to 2013 and was the Chief Privacy Officer for Bank One from 2003 to 2004. From 2001 to 2004, Lynn was General Counsel for Bank One’s credit card company, and from 1983 to 2001, she was Head of Litigation for Bank One, First Chicago NBD and First Chicago. Prior to joining JPMorgan Chase and predecessor entities, Lynn was in private practice and clerked for a federal judge. Lynn is a lawyer and a Certified Information Privacy Professional and a frequent speaker on privacy topics.
- IAF comments to the Article 29 Data Protection Working Party draft Guidelines on Transparency under EU Regulation 2016/679
IAF comments to the Article 29 Data Protection Working Party draft Guidelines on Transparency under EU Regulation 2016/679 January 2018 Home / Publications / Download PDF
- MasterCard
MasterCard MasterCard
- IAF Comments on Big Data Filed with S. NTIA
IAF Comments on Big Data Filed with S. NTIA August 2014 Home / Publications / Download PDF
- Photography Composition Techniques
Mastering composition techniques for stunning photographs Photography Composition Techniques Mastering composition techniques for stunning photographs Next Item Previous Item
- DIY Home Decor Ideas
Creative and budget-friendly home decor projects DIY Home Decor Ideas Creative and budget-friendly home decor projects Next Item Previous Item
- Referential: Singapore Model AI Intelligence Governance Framework Annex
Referential: Singapore Model AI Intelligence Governance Framework Annex February 2020 Home / Publications / Download PDF





