Copyright © SAS Inst itute Inc. A l l r ights reserved.
SAS® USER FORUMFINLAND 2017
USER FORUMDetect, Protect, and Monitor Personal Data
SAS® USER FORUMFINLAND 2017
Copyright © SAS Inst itute Inc. A l l r ights reserved.
PresenterCecily Hoffritz, Principal Advisor, SAS Institute
• Employed at SAS Institute in Denmark for more than 25 years.
• Focus areas: SAS for Personal Data Protection, GDPR & SAS® Data Management
• Data Protection Officer.
SAS® USER FORUMFINLAND 2017
Copyright © SAS Inst itute Inc. A l l r ights reserved.
BackgroundThe EU General Data Protection Regulation (GDPR)
• Enforced next year in May.• Protects your rights and your personal data.• Affects all businesses and not only in Europe!• Non-compliance is costly - very large fines and
loss of trust. • Introduces high standards for collecting, storing,
processing and removing personal data.• Proving compliance through governance and
proactive data management.
SAS® USER FORUMFINLAND 2017
Copyright © SAS Inst itute Inc. A l l r ights reserved.
Typical GDPR Compliance Program
SAS® USER FORUMFINLAND 2017
Copyright © SAS Inst itute Inc. A l l r ights reserved.
Typical GDPR Compliance ProgramThe end-to-end SAS fit
SAS® USER FORUMFINLAND 2017
Copyright © SAS Inst itute Inc. A l l r ights reserved.
Personal Data Discovery DashboardProviding Timely Overview
SAS® USER FORUMFINLAND 2017
Copyright © SAS Inst itute Inc. A l l r ights reserved.
Personal Data Identification
SAS® Quality
Knowledge Base
SAS®
Fede
ration
Server
The Process
SAS® USER FORUMFINLAND 2017
Copyright © SAS Inst itute Inc. A l l r ights reserved.
SAS® Quality Knowledge Base
Names
Phone numbers
4-digit zip codes
E-mail addresses
Street addresses
IP address
Health data
DOB
Gender
HR data
Personal files
Social security numbers
IBAN (International Bank Account Number)
Credit card numbers
Personal Data Identification Methods
Parsing
Extraction
Pattern Analysis
Identification Analysis
Gender Analysis
Standardization, Casing
Matching
Personal Data Categories
Customised for PD Identification and Extraction
SAS® USER FORUMFINLAND 2017
Copyright © SAS Inst itute Inc. A l l r ights reserved.
Personal Data IdentificationCategorizing the Information
?Jens Pedersen Individual
[email protected] E-mail
123.234.156.278 Network Address
?
?
SAS® USER FORUMFINLAND 2017
Copyright © SAS Inst itute Inc. A l l r ights reserved.
Personal Data IdentificationFields with Free Text
SAS® USER FORUMFINLAND 2017
Copyright © SAS Inst itute Inc. A l l r ights reserved.
Personal Data Protection
SAS® Federation ServerPseudonymisation, anonymisation, encryption, table/column/row level permissions, logging, monitoring
Masking Social Security Numbers
Data LakeCRM DWHOperational Systems
SAS
SAS® USER FORUMFINLAND 2017
Copyright © SAS Inst itute Inc. A l l r ights reserved.
Personal Data MonitoringFrom Logs to Dashboard
SAS® USER FORUMFINLAND 2017
Copyright © SAS Inst itute Inc. A l l r ights reserved.
SAS for Personal Data Protection
Business Data Glossary
Personal Data Identification
Lineage
Reports & Dashboards
Data AccessSecurity
DataMasking
Audit Log&
CentralAdmin.
Data Access
Data QualityConsent Data Management
Policies & Controls
Management
Data Protection
Impact Assessment
Enterprise view of your risk exposure
Remediation
Capabilities
SAS® USER FORUMFINLAND 2017
Copyright © SAS Inst itute Inc. A l l r ights reserved.
SAS® Data Management
SAS for Personal Data ProtectionSAS® Software Components
SAS® Federation
ServerAnalyticalSystems
AnalyticsActivities
SAS® eGRC
Copyright © SAS Inst itute Inc. A l l r ights reserved.
SAS® USER FORUMSWEDEN 2017
Demo
Copyright © SAS Inst itute Inc. A l l r ights reserved.
SAS® USER FORUMFINLAND 2017
Thank [email protected]
http://support.sas.com/resources/papers/proceedings17/SAS0639-2017.pdf