USER FORUM - SAS · SAS for Personal Data Protection Business Data Glossary Personal Data...

Preview:

Citation preview

Copyright © SAS Inst itute Inc. A l l r ights reserved.

SAS® USER FORUMFINLAND 2017

USER FORUMDetect, Protect, and Monitor Personal Data

SAS® USER FORUMFINLAND 2017

Copyright © SAS Inst itute Inc. A l l r ights reserved.

PresenterCecily Hoffritz, Principal Advisor, SAS Institute

• Employed at SAS Institute in Denmark for more than 25 years.

• Focus areas: SAS for Personal Data Protection, GDPR & SAS® Data Management

• Data Protection Officer.

SAS® USER FORUMFINLAND 2017

Copyright © SAS Inst itute Inc. A l l r ights reserved.

BackgroundThe EU General Data Protection Regulation (GDPR)

• Enforced next year in May.• Protects your rights and your personal data.• Affects all businesses and not only in Europe!• Non-compliance is costly - very large fines and

loss of trust. • Introduces high standards for collecting, storing,

processing and removing personal data.• Proving compliance through governance and

proactive data management.

SAS® USER FORUMFINLAND 2017

Copyright © SAS Inst itute Inc. A l l r ights reserved.

Typical GDPR Compliance Program

SAS® USER FORUMFINLAND 2017

Copyright © SAS Inst itute Inc. A l l r ights reserved.

Typical GDPR Compliance ProgramThe end-to-end SAS fit

SAS® USER FORUMFINLAND 2017

Copyright © SAS Inst itute Inc. A l l r ights reserved.

Personal Data Discovery DashboardProviding Timely Overview

SAS® USER FORUMFINLAND 2017

Copyright © SAS Inst itute Inc. A l l r ights reserved.

Personal Data Identification

SAS® Quality

Knowledge Base

SAS®

Fede

ration

Server

The Process

SAS® USER FORUMFINLAND 2017

Copyright © SAS Inst itute Inc. A l l r ights reserved.

SAS® Quality Knowledge Base

Names

Phone numbers

4-digit zip codes

E-mail addresses

Street addresses

IP address

Health data

DOB

Gender

HR data

Personal files

Social security numbers

IBAN (International Bank Account Number)

Credit card numbers

Personal Data Identification Methods

Parsing

Extraction

Pattern Analysis

Identification Analysis

Gender Analysis

Standardization, Casing

Matching

Personal Data Categories

Customised for PD Identification and Extraction

SAS® USER FORUMFINLAND 2017

Copyright © SAS Inst itute Inc. A l l r ights reserved.

Personal Data IdentificationCategorizing the Information

?Jens Pedersen Individual

jens.pedersen@sas.com E-mail

123.234.156.278 Network Address

?

?

SAS® USER FORUMFINLAND 2017

Copyright © SAS Inst itute Inc. A l l r ights reserved.

Personal Data IdentificationFields with Free Text

SAS® USER FORUMFINLAND 2017

Copyright © SAS Inst itute Inc. A l l r ights reserved.

Personal Data Protection

SAS® Federation ServerPseudonymisation, anonymisation, encryption, table/column/row level permissions, logging, monitoring

Masking Social Security Numbers

Data LakeCRM DWHOperational Systems

SAS

SAS® USER FORUMFINLAND 2017

Copyright © SAS Inst itute Inc. A l l r ights reserved.

Personal Data MonitoringFrom Logs to Dashboard

SAS® USER FORUMFINLAND 2017

Copyright © SAS Inst itute Inc. A l l r ights reserved.

SAS for Personal Data Protection

Business Data Glossary

Personal Data Identification

Lineage

Reports & Dashboards

Data AccessSecurity

DataMasking

Audit Log&

CentralAdmin.

Data Access

Data QualityConsent Data Management

Policies & Controls

Management

Data Protection

Impact Assessment

Enterprise view of your risk exposure

Remediation

Capabilities

SAS® USER FORUMFINLAND 2017

Copyright © SAS Inst itute Inc. A l l r ights reserved.

SAS® Data Management

SAS for Personal Data ProtectionSAS® Software Components

SAS® Federation

ServerAnalyticalSystems

AnalyticsActivities

SAS® eGRC

Copyright © SAS Inst itute Inc. A l l r ights reserved.

SAS® USER FORUMSWEDEN 2017

Demo

Copyright © SAS Inst itute Inc. A l l r ights reserved.

SAS® USER FORUMFINLAND 2017

Thank youcecily.hoffritz@sas.com

http://support.sas.com/resources/papers/proceedings17/SAS0639-2017.pdf

Recommended