GDPR Interface Testing
www.hklaw.com
Are Your End-User Interfaces Ready for the Data Protection Authorities (DPAs)?
WHY TEST?
1
Because they may represent your greatest GDPR risk.
2
The DPAs can test these interfaces without notice because your web, mobile and IoT interfaces are publicfacing.
Organizations typically don’t realize the nature and extent of the data collected or disclosed to third parties. The time pressure of so-called “agile development” and “dev ops” means your
developers probably have not tested the privacy properties
used by third-party code in your interfaces (e.g., SDKs, APIs, JavaScript tags), and the chances that they have tested the code sufficiently to meet GPDR standards is likely zero.
Inadvertent disclosure of personal and sensitive data to third parties is common because:
Development is increasingly modularized – a large amount of third-party code is used for advertising, analytics, graphics, functionality, etc., meaning more disclosure.
Testing for privacy compliance is difficult and requires economies
of scale and legal analysis to do well.
3 Disclosure caused by third-party code won’t show up in your logs.
4
The reason the disclosure to third parties is invisible is because it is almost always intermediated by the end-user’s device.
This means the thirdparty disclosure is publicly visible, but not susceptible to your server-side audit.
No industry sector is immune – including healthcare, financial services, media, retail, energy, and more.
GDPR Interface Testing WHY YOU SHOULD USE HOLLAND & KNIGHT
www.hklaw.com
There are several reasons why privacy vendors are not able to adequately evaluate the compliance of GDPR interfaces.
REASON 1 The Legal Nature of the Required Test
the disclosure of “sensitive” data under GDPR, are a function not only of disclosing
Privacy vendors lack the necessary legal expertise to discriminate between the disclosed language combinations that will be GDPR-compliant and those that will not.
tracking information (device IDs, geolocation, personally identifiable information), but also the subject matter or content information that is collected along with it.
Necessary legal distinctions aren’t engineered by design. As a result, their solutions are not formulated to detect these issues or draw distinctions between legally compliant and non-compliant events.
Many legal violations – including
Onus on the Customer Many times the customer is left to make arcane configurations in the solution to actually work for GDPR.
order to try to get
REASON 2 Transmission of Subject Matter Data Analysis
This goes beyond what appears on the face of the site or app. Third-party code (especially advertising and analytics SDKs) may perform automated processing, make predictions, or render classification decisions that have nothing to do with the facial content of the site and app – and then transmit those GDPR-sensitive predictions and classifications to third parties. The privacy vendors are not engineered to detect these issues nor do they have legal expertise to draw distinctions between legally compliant and non-compliant events.
Attorney-Client Privilege Additionally, there is a question of potentially competing interests and privilege protections. A number of privacy vendors not only provide corporate services, but also provide consumer-facing “privacy rights” services that would easily enable plaintiffs’ class action counsel or privacy researchers to use those same services to investigate potential claims against companies, and create litigation or enforcement exposure. Furthermore, privacy vendor notes, working papers and test results are also not protected by attorney-client privilege.
the necessary
GDPR Interface Testing
www.hklaw.com
We conduct testing of websites, mobile apps, IoT services and APIs,
OUR APPROACH TO GDPR-INTERFACE TESTING
all within the law firm setting, under
attorney-client privilege.
We test for: the collection and disclosure of device IDs, geolocation, and personally identifiable information
GDPR-sensitive subject matter
content based on natural language processing tuned for assessing GDPR by lawyers
the transmission of obfuscated data (“hashed” identifiers, hashes of hashes and encoded data)
In addition to our analysis of data
transmission and disclosure, we also evaluate the effectiveness of consent mechanisms, opt-outs and notice presentment to ensure that these components of the online app or service comply with GDPR.
1
We use a special networking environment and “stand in the shoes” of the would-be consumer or end-user.
2
Using a TLS-enabled, intercepting web proxy, we capture all network traffic to and from the interfaces we test.
Thus, all information collected or disclosed by the GDPR interface is captured, including information disclosed to third parties (analytics companies, advertisers, social networks, data brokers, cloud resources, etc.).
Following the capture of network traffic, the captured data is analyzed with custom scripts, then findings and legal recommendations are generated regarding the transmission of device IDs, personally identifiable information, geolocation, sensitive data, appropriateness of disclosures, and effectiveness of opt-outs and/or user privacy controls.
During this phase, we walk through account creation/registration, feature selection, use of functionality, actual use of the service and opt-outs. We also conduct automated crawls, as appropriate.
4
3
5
Data collected and transmitted from customer or consumer-facing websites, mobile apps, IoT devices and networkconnected services presents significant GDPR exposure. This is because data collected and transmitted behind the scenes (i.e., buried in the network traffic that constitutes the normal functioning of the online service or app) can be readily tested and evaluated by enforcement authorities (DPAs), private plaintiffs’ lawyers, privacy advocates, academic researchers and the media using sophisticated tools and testing regimes.
GDPR Interface Testing
www.hklaw.com
It is critical that organizations understand the fundamental questions posed by the specific GDPR articles that may affect their business. We help translate the significance of these articles and offer customers effective solutions that comprehensively address GDPR compliance issues and help ensure end-user interfaces are ready for DPA evaluation.
GDPR Article
Questions Posed
Solutions
Articles 3 and 44-50: Territorial Scope; Transfer of Data
Where is data transmitted? In the EU? Outside of the EU?
Identify territorial scope using DNS records query and IP address trace
Article 6: Lawfulness of Processing
To which parties is personal data transmitted?
Identify all hosts receiving personal data through network traffic analysis
Article 6: Lawfulness of Processing
What functions does each third party perform?
Identify function of each third party based on network traffic analysis and analysis of online data
Article 6: Lawfulness of Processing
Can transmitted data be linked to real persons?
Evaluation of the linkability of transmitted data (advertising IDs, carrier-related IDs, hardware IDs, serial numbers, social network cookies, IP address, etc.)
Articles 6 and 9: Lawfulness of Processing; Special Categories of Data
Are special categories of data transmitted to any party?
Perform natural language processing (NLP) on captured network traffic to evaluate the extent to which the tested interface transmits special categories of data
Articles 6 and 9: Lawfulness of Processing; Special Categories of Data
To which parties are personal data and special categories of data transmitted?
Sort by host and tracking IDs the special categories of personal data collected and transmitted (racial, ethnic, political, religious, trade union, genetic, biometric, health-related, sexual orientation, sex life)
Article 6: Lawfulness of Processing
Is there a lawful basis for the observed use and transmission of data?
Holistic analysis of use case, network traffic and user interface
Articles 25 and 32: Data Protection by Design and by Default; Security of Processing
Is transmitted personal data pseudonymized effectively?
Evaluation of potential threat of lookup tables or other linkability of pseudonymized data
Article 25: Data Protection by Design and by Default
Has the transmission of personal data been minimized (i.e., is there over-collection)?
Assessment of personal data transmitted versus intended use case
Article 30: Records of Processing Activities
Are back-end recordkeeping and audit processes in place?
Evaluation of back-end processes based on information provided by client versus data transmission observed in network traffic captures
Article 32: Security of Processing
Is data encrypted in transit?
Protocol analysis
Article 35: Data Protection Impact Assessment
Has a data protection impact assessment been conducted for the use and transmission of special categories of data?
Conduct PIA if appropriate
Steven B. Roosa
LEARN MORE. CONNECT WITH US. Copyright Š 2018 Holland & Knight LLP All Rights Reserved
Partner New York 212.513.3544 steven.roosa@hklaw.com