Improving GDPR compliance in hours, not months — Tide’s story of automating privacy
Prukalpa ?
Co-Founder at Atlan –?Home for Data Teams | Forbes30 & Fortune40 lists | TED Speaker
One of the reasons, I’m so personally excited about active metadata is how it takes the use cases of metadata?beyond just data catalogs. In the past year, one of my personal highlights has been working with amazing data leaders and seeing how they do amazing things with metadata automation.
Today, I’d like to spotlight Metadata Weekly on two such data leaders —?Hendrik Brackmann?and?Michal Szymanski?from?Tide, a fast-growing mobile-first financial platform focused on small business users, who are using active metadata to enable GDPR compliance.
Why I love what they did:
Keep reading for the TL;DR or get the full story?here. Happy reading!
??Spotlight: How Tide embedded privacy into automated data processes
“We wanted to embed data protection and privacy into our running processes, rather than discussing it at the end of projects.” (Michal Szymanski, Tide)
Like every company, it’s critical that Tide is compliant with GDPR. A key component is the right to erasure, more commonly known as the “Right to be forgotten”, which gives Tide’s customers across the EU and UK the right to ask for their personal data to be deleted.
This was important but far from easy. Whenever someone wanted to delete PII data, the production support team would go through Tide’s back-end databases and delete personal data fields. They had a script to handle a lot of this, but it didn’t catch everything. The script caught personal data in the key data source, but it had trouble capturing data from all the new sources that kept appearing in the organization. Tide’s team had to manually go through secondary systems to find and delete local projections of the personal data fields.
As Tide continued to grow, its technology stack and architecture grew more complicated, new products and services were introduced, and customers increased over time, this just took more time and effort.
领英推荐
In an ideal world, when a customer exercised their right to be forgotten, a single click of a button would automatically identify and delete or archive all data about the customer in accordance with GDPR.?Immense manual effort, and the risk of delays or human error, would be eliminated.
And that’s what they built!
Here’s the TL;DR of their implementation:
The Tide team was ready to spend 50 days of effort on a task that would make clear improvements to Tide’s risk profile. But after integrating their data estate with Atlan and driving consensus on definitions,?they used Playbooks’ automation to?accomplish their goal in just a few hours.
Here’s a nugget of advice for fellow data leaders from Hendrik to wrap up: “Focus on business value, and the actual value you’re generating for your organization rather than finding a process everyone in the industry follows and adopting the same thing. Don’t try to do governance everywhere. Figure out what data sets are relevant to you, and focus on these ends.”
???More from my reading list
P.S. Liked reading this edition of the newsletter? I would love it if you could take a moment and share it with your friends on social! If someone shared this with you, subscribe to upcoming issues?here.
VP Data
2 年Thanks for the kind words - really loved working with the Atlan team to make this happen! You've built an amazing culture Prukalpa ?