277 karma · joined June 12, 2011
[1] https://www.cnil.fr/en/cnils-restricted-committee-imposes-fi... [2] https://www.datainspektionen.se/globalassets/dokument/beslut... [3] https://www.autoriteprotectiondonnees.be/publications/decisi...
Important is also how you handle data analytics and this is why we're deploying high restrictions on raw data. Analytics will only be able to be done through an analytics service which can give the employees access to only certain parts of the data which is approved for the use-case. We're using Apache Sentry for fine grained role based authorisation to data and metadata and a directory services for user auth.
Things we've learned:
* Minimise data usage
* Don't use personally identifiable data
* You will need to be able to prove consent when it comes to data usage and it cannot be consent by default, it has to be opt-in
* Log all data access so that use cases can be proved. This needs to be evaluated and audited
* Encrypt in transit and at rest
* Centralise mapping for all data
* Create an AWS Cognito User pool
* Create an Azure AD Enterprise Application
* Set up Azure AD federation to the Cognito User Pool
- Use environment variables
- Use step functions to create to create state machines
- Deploy using cloudformation templates and serverless framework
http://www.saltybet.com/ does just that.
"Statement": [{
"Effect": "Allow",
"Principal": {"Service": [
"firehose.amazonaws.com"
]
},
"Action": ["sts:AssumeRole"]
}
]
}I already have the DSLR, tripod and floodlight so it was the natural choice for me. I guess this one is good if you have none of that.