Published Sep 3, 2019

SE Radio Episode 342 - István Lam on Privacy by Design with GDPR

István Lam delves into the intricacies of GDPR, emphasizing privacy by design and its transformative impact on digital trust and software development, while offering practical insights into data management, compliance strategies, and the prevention of system breaches.
Episode Highlights
Software Engineering Radio - the podcast for professional software developers logo

Popular Clips

Episode Highlights

  • GDPR Principles

    The General Data Protection Regulation (GDPR) establishes a framework for data privacy, emphasizing proactive measures and privacy as a default setting. explains that organizations must design systems to prevent data breaches rather than merely reacting to them. He highlights the importance of understanding roles such as data controllers and processors, which are crucial for GDPR compliance 1.

    GDPR sets a new way of looking at private information and private data, and I think this regulation can take back to the trust in the industry.

    ---

    This regulation is not limited to the EU; it affects any entity handling EU citizens' data, making it a potential global standard 2.

       

    Compliance Essentials

    Ensuring GDPR compliance involves meticulous documentation and transparency in data handling practices. emphasizes the need for organizations to document their data management processes and privacy policies thoroughly. He notes that undocumented data practices are illegal under GDPR, and companies must provide clear reasons for data collection 3.

    GDPR is just about letting the people know what you are doing.

    ---

    Additionally, systems must allow users to access, modify, and delete their personal data, requiring robust processes to manage these requests effectively 4.

       

    Potential Fines

    Non-compliance with GDPR can lead to severe financial penalties, including fines up to 20 million euros or 4% of global revenue. explains that while some countries offer a warning system for first-time violations, gross negligence can result in immediate fines 5.

    A fine can be quite high, so it can be up to 20 million or 4% of your global revenue.

    ---

    These potential fines underscore the importance of designing systems that comply with GDPR, as customers are likely to value and pay extra for compliant services.

Related Episodes