28
Director, WSO2 GDPR impact on Consumer Identity and Access Management (CIAM) Sagara Gunathunga

GDPR impact on Consumer Identity and Access Management (CIAM)

Embed Size (px)

Citation preview

Page 1: GDPR impact on Consumer Identity and Access Management (CIAM)

Director, WSO2

GDPR impact on Consumer Identity and Access Management (CIAM)

Sagara Gunathunga

Page 2: GDPR impact on Consumer Identity and Access Management (CIAM)

Digital Transformationwill decide and shape

the destiny of your business

Page 3: GDPR impact on Consumer Identity and Access Management (CIAM)

Digital Transformation is no longer a nice to have or a differentiator, it’s about the survival of your business

Is it the Right Time to Think?

A nice to have

A differentiator

For survival

Page 4: GDPR impact on Consumer Identity and Access Management (CIAM)

Is it Real? Look Around You!

Page 5: GDPR impact on Consumer Identity and Access Management (CIAM)

Is it Real?

Page 6: GDPR impact on Consumer Identity and Access Management (CIAM)

• Sales increasingly based on real user reviews and ratings than traditional marketing

• Physical stores replaced with digital channels (web stores, mobile apps, IVR solutions)

• Fast consumer response time and convenience means connectivity (e.g. Facebook, Twitter, WhatsApp)

Digitize Delivery Channels

Page 7: GDPR impact on Consumer Identity and Access Management (CIAM)

Generic user experiences don’t work, consumers now expect

– A highly personalized experience

– Control over preferences – Relativeness of content

Personalized User Experience

Page 8: GDPR impact on Consumer Identity and Access Management (CIAM)

Knowing Your Customer is Key!

Page 9: GDPR impact on Consumer Identity and Access Management (CIAM)

Personalized experience

What Does CIAM Offer?

CIAM

Connect with consumers

Consumer data protection

Page 10: GDPR impact on Consumer Identity and Access Management (CIAM)

What Does CIAM Offer? Bring Your Own Identity (BYOI)

Minimizes registration fatigue by providing wide range of options for consumer on-boarding through trusted social identity providers, such FB, Twitter, Google

Page 11: GDPR impact on Consumer Identity and Access Management (CIAM)

Bring Your Own Identity (BYOI)

New to Hi! Sign Up

WelcomeSagara

Page 12: GDPR impact on Consumer Identity and Access Management (CIAM)

Consumer Authentication• Social logins eliminate password management

complexities from consumer and business side • Out-of-the-box support for strong authentication

options, such as two-factor authentication• Risk-based adaptive authentication options

What Does CIAM Offer?

Page 13: GDPR impact on Consumer Identity and Access Management (CIAM)

Social Logins

New to Hi! Sign Up

WelcomeSagara

Page 14: GDPR impact on Consumer Identity and Access Management (CIAM)

Two-Factor Authentication

STEP 1

STEP 2

WelcomeSagara

Page 15: GDPR impact on Consumer Identity and Access Management (CIAM)

What Does CIAM Offer? Single sign-on (SSO)

• Social logins eliminate password management complexities from consumer and business side

• Out-of-the-box support for strong authentication options, such as 2-factor authentication

Welcome

Welcome

Page 16: GDPR impact on Consumer Identity and Access Management (CIAM)

What Does CIAM Offer? Progressive profiling

The process of how the system learns about a customer in a progressive manner

Page 17: GDPR impact on Consumer Identity and Access Management (CIAM)
Page 18: GDPR impact on Consumer Identity and Access Management (CIAM)

• Regulation implemented in EU and goes in effect May 2018

• Personal data processing organizations established in EU, and organizations outside EU that process personal data from individuals in EU need to comply

• Up to 4% of revenue penalties for violations

GDPR

Page 19: GDPR impact on Consumer Identity and Access Management (CIAM)

• Recognizes protection of personal data and control over processing of personal data as a fundamental right of an individual

• Provides processing organizations certainty on personal data processing

• Wider definition for personal data as personally identifiable information (PII)

GDPR

Page 20: GDPR impact on Consumer Identity and Access Management (CIAM)

• Consent lifecycle management– User onboarding based on active consent – Ability to review given consent and revocation– Ability to demonstrate proof of consent– Consent per purpose – Consent design

GDPR Impact on CIAM

Page 21: GDPR impact on Consumer Identity and Access Management (CIAM)

Consent Lifecycle Management

WelcomeSagara

New to Hi! Sign Up

Page 22: GDPR impact on Consumer Identity and Access Management (CIAM)

• CIAM solutions should provide a self-care portal for consumers– Review already given

consent– Revoke given consent

Consent Lifecycle Management

Page 23: GDPR impact on Consumer Identity and Access Management (CIAM)

Consent Design• Consents from a CIAM solution should meet design

consideration mandate by the GDPR– Informed– Active opt-in  – Unbundled– Named– Easy to Withdraw – Granular – Considerations for children's consent

Page 24: GDPR impact on Consumer Identity and Access Management (CIAM)

GDPR Impact on CIAM • A CIAM solution

should address– Privacy by design – Privacy by default

Page 25: GDPR impact on Consumer Identity and Access Management (CIAM)

A CIAM solution should facilitate implementation of consumer rights

GDPR Impact on CIAM The right of transparency

and modalities

The right to be informed

The right of access

The right to notification

obligation

The right to rectification

Rights in relation to

automated decision making

and profiling

The right to data

portability

The right to object

The right to restrict processing

The right to be forgotten

Page 26: GDPR impact on Consumer Identity and Access Management (CIAM)

• Self-care portal is an ideal solution to implement consumer rights– Review user profiles– Alteration of user profiles– Deletion for user profiles– Keep user profile up-to-

date – Support user profile

portability

GDPR Impact on CIAM

Page 27: GDPR impact on Consumer Identity and Access Management (CIAM)

• Digital transformation is critical for business survival

• GDPR enhances consumer privacy, poses new challenges for organizations

• A proper CIAM tool can help you win the digital transformation battle in a GDPR compliant manner

Conclusion

Page 28: GDPR impact on Consumer Identity and Access Management (CIAM)

wso2.com