{"id":18517,"date":"2022-03-16T08:00:45","date_gmt":"2022-03-16T16:00:45","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/03\/16\/news-12250\/"},"modified":"2022-03-16T08:00:45","modified_gmt":"2022-03-16T16:00:45","slug":"news-12250","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/03\/16\/news-12250\/","title":{"rendered":"Manage subject rights requests at scale with Microsoft Priva"},"content":{"rendered":"<p><strong>Credit to Author: Lauren Goodwin| Date: Wed, 16 Mar 2022 16:00:00 +0000<\/strong><\/p>\n<p>Privacy is of increasing importance to our customers. In addition to the well-known European General Data Protection Regulation (GDPR), privacy regulations are emerging in nearly every region with more than 70 percent of countries now having data protection and privacy legislation.<sup>1<\/sup> <\/p>\n<p>As the number and scope of privacy standards have proliferated, privacy becomes an expectation of customers and stakeholders to enable a trusted business. Many of the large organizations I work with are mature in their privacy compliance processes. Some have had to be GDPR compliant since 2018. Even those without GDPR compliance obligations saw GDPR as a watershed event, recognizing that broader privacy regulation was coming. Organizations have now shifted their focus from privacy compliance to privacy leadership in order to provide value to their customers and their brands.&nbsp;To assist organizations on their privacy journey, we introduced <a href=\"https:\/\/aka.ms\/priva\/web\">Microsoft Priva<\/a> in October 2021 to help customers safeguard personal data and respect privacy rights.<\/p>\n<p>The concept of respecting an individual\u2019s privacy rights has been emphasized by the Organization for Economic Cooperation and Development (OECD) as \u201cThe Individual Participation Principle\u201d in the Fair Information Practice Principles (FIPPs) since 1980.<sup>2<\/sup> The principle includes an individual\u2019s right to access and control their own data. In some cases, they have the right to have this data corrected or deleted. Since GDPR went into effect, the concept has become more mainstream, known as data subject requests or subject rights requests. In the United States, 12 states have laws passed or active bills that mandate a subject\u2019s right to data access.<sup>3<\/sup><\/p>\n<h2>Subject rights requests (SRRs) management is time-consuming and costly<\/h2>\n<p>Responding to subject rights requests (SRRs) can be resource-intensive, costly, and difficult to manage. There are challenging time frames for a response, with GDPR mandating a response time of 30 days and California Privacy Rights Act (CPRA) allowing 45 days. More than half of organizations handle SRRs manually, while one in three has automated the process.<sup>4<\/sup> According to Gartner\u00ae, most organizations process between 51 and 100 SRRs per month at a cost of more than USD1,500 per request.<sup>5<\/sup> As more privacy regulations come into force and the public becomes more informed about their rights, the volume of SRRs is expected to grow substantially, impacting organizations\u2019 resources even further.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"968\" height=\"522\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Picture1.png\" alt=\"Pie chart showing 1 in 3 organizations have partially automated subject rights requests.\" class=\"wp-image-108921\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Picture1.png 968w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Picture1-300x162.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Picture1-768x414.png 768w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Picture1-389x209.png 389w\" sizes=\"auto, (max-width: 968px) 100vw, 968px\" \/><\/figure>\n<p><em>Figure 1. Approximately one in three organizations have partially automated subject rights requests.<\/em><\/p>\n<h2>Scaling SRR management is challenging<\/h2>\n<p>To process an SRR, an organization must verify the data subject to make sure that the individual is who they say they are and has the rights to the information, then collect the information, review, redact where appropriate, and provide the response to the requester in an auditable manner.<\/p>\n<p>Most organizations have processes in place for SRR responses but rely on email for collaboration, eDiscovery tools for search, and manual reviews to identify data conflicts like a file containing multiple people\u2019s privacy relevant data. These processes can work but they don\u2019t scale. They also create data sprawl and additional security and compliance risk.<\/p>\n<h2>Manage at scale and respond with confidence with Microsoft Priva<\/h2>\n<p>To help organizations deal with these challenges, Microsoft has created <a href=\"https:\/\/www.microsoft.com\/security\/business\/privacy\/privacy-management-software\">Microsoft Priva<\/a>, a privacy management solution that helps safeguard and respect privacy while streamlining the process for responding to SRRs.<\/p>\n<p><a href=\"https:\/\/docs.microsoft.com\/privacy\/priva\/priva-overview\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Priva<\/a> SRRs helps gather a subject\u2019s data from the Microsoft 365 environment automatically, including emails, messages, documents, spreadsheets, and more that contain the requestor\u2019s personal data. It then detects and flags conflicts like the personal data of others or confidential information included in the collected files. Automated data collection and detection can help you capture conflicts more accurately to avoid any data leakage.<\/p>\n<p>Additionally, the solution allows collaboration in a protected platform for stakeholders to review, triage, and redact collected files in their native views. Unlike other solutions that might only provide you with a report of file paths, Microsoft Priva can bring the files to you and save you time and effort manually copying and pasting the file paths in your browser, or emailing and messaging files to others to review.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"1920\" height=\"1080\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Picture2.gif\" alt=\"Animated image of Microsoft 365 compliance dashboard user redacting files.\" class=\"wp-image-108924\"\/><\/figure>\n<p><em>Figure 2. Review, triage, and redact collected files in their native views when multiple people\u2019s data is detected<\/em>.<\/p>\n<p>Privacy admins can also leverage <a href=\"https:\/\/www.microsoft.com\/microsoft-teams\/group-chat-software\">Microsoft Teams<\/a> and <a href=\"https:\/\/docs.microsoft.com\/privacy\/solutions\/privacymanagement\/privacy-management-subject-rights-requests-automate-tasks\" target=\"_blank\" rel=\"noreferrer noopener\">Power Automate<\/a>, integrated with the Microsoft Priva solution, to work with HR, legal, and other departments in an efficient, compliant, and auditable way. All your collaboration data is centralized in one platform that ensures security and compliance along the way. Microsoft Priva SRRs helps organizations manage SRRs at scale with confidence while avoiding personal data sprawl.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"1024\" height=\"576\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Subject-Rights-1024x576.jpg\" alt=\"Flow chart showcasing how Microsoft Priva Subject Rights Requests helps manage requests at scale and with confidence.\" class=\"wp-image-109170\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Subject-Rights-1024x576.jpg 1024w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Subject-Rights-300x169.jpg 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Subject-Rights-768x432.jpg 768w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Subject-Rights-1536x864.jpg 1536w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Subject-Rights-2048x1152.jpg 2048w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Subject-Rights-687x385.jpg 687w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Subject-Rights-1083x609.jpg 1083w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Subject-Rights-767x431.jpg 767w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Subject-Rights-539x303.jpg 539w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<p><em>Figure 3. Microsoft Priva SRRs helps manage requests at scale and with confidence.<\/em><\/p>\n<p>The solution dashboard provides visualization of SRR metrics and the ability to filter and manage requests to completion. This establishes to internal stakeholders and regulators that SRR responses were made with compliant processes in the required timeframe.&nbsp;<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"1024\" height=\"562\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Picture4-1024x562.png\" alt=\"Microsoft 365 compliance center dashboard showing SRR progress over time.\" class=\"wp-image-108930\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Picture4-1024x562.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Picture4-300x165.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Picture4-768x421.png 768w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Picture4.png 1283w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<p><em>Figure 4: Microsoft Priva SRRs&nbsp;helps provide insights on SRR progress and show trends over time.<\/em><\/p>\n<h2>Integrate with your privacy solutions<\/h2>\n<p>Many organizations are using other tools to manage SRRs. We want to bring the value of Microsoft Priva and its native integration with Microsoft 365 to them as well to provide a better-together solution. Part of this is to integrate Microsoft Priva with the solutions of other software vendors and customers\u2019 homegrown solutions through our <a href=\"https:\/\/docs.microsoft.com\/graph\/api\/resources\/subjectrightsrequest-subjectrightsrequestapioverview?view=graph-rest-1.0\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Graph subject rights request API<\/a>. The API allows <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/security-compliance-and-identity\/expanding-microsoft-365-privacy-management-with-api-ecosystem\/ba-p\/2850620\" target=\"_blank\" rel=\"noreferrer noopener\">integration with privacy independent software vendors<\/a> (ISVs), like OneTrust, Securiti.ai, and WireWheel, to automate the SRR handling process and provide a response that encompasses the organization\u2019s entire data estate.<\/p>\n<p>For example, an organization can use the API to send a request they received in their homegrown application to Microsoft Priva, which then collects the subject\u2019s personal data automatically, enables collaboration to review and redact files, creates a link to the data package, and sends it back to the homegrown application through the API. The organization then can combine all the reports and data from various environments together to respond to the requestor.<\/p>\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Picture5-1024x535.png\" alt=\"Microsoft Graph A P I showing how organizations leverage Microsoft Priva along with their existing privacy tools.\" class=\"wp-image-108933\" width=\"840\" height=\"438\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Picture5-1024x535.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Picture5-300x157.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Picture5-768x401.png 768w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2022\/03\/Picture5.png 1206w\" sizes=\"auto, (max-width: 840px) 100vw, 840px\" \/><\/figure>\n<p><em>Figure 5. Microsoft Graph API enables organizations to leverage Microsoft Priva along with their existing privacy tools.<\/em><\/p>\n<h2>Learn more<\/h2>\n<p>We are excited to help ease the complexity of SRR management. To learn more about how to manage SRRs at scale, download the e-book <a href=\"https:\/\/aka.ms\/PrivaSRReBook\" target=\"_blank\" rel=\"noreferrer noopener\">Five tips from Microsoft to automate your SRRs<\/a> or <a href=\"https:\/\/aka.ms\/priva\/webinar\/SRRs\/5tips\" target=\"_blank\" rel=\"noreferrer noopener\">join our webinar<\/a> on April 5, 2022.<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/privacy\/privacy-management-software\">Microsoft Priva<\/a> solutions are generally available for customers as an add-on to all Microsoft 365 or Office 365 enterprise subscriptions. You can <a href=\"https:\/\/aka.ms\/trypriva\" target=\"_blank\" rel=\"noreferrer noopener\">try out Microsoft Priva SRRs<\/a> for 90 days or create up to 50 subject rights requests (whichever limit expires first) at no cost.<\/p>\n<p>To learn more about Microsoft Security solutions,&nbsp;<a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/solutions\">visit our&nbsp;website<\/a>.&nbsp;Bookmark the&nbsp;<a href=\"https:\/\/www.microsoft.com\/security\/blog\/\">Security blog<\/a>&nbsp;to keep up with our expert coverage on security matters. Also, follow us at&nbsp;<a href=\"https:\/\/twitter.com\/@MSFTSecurity\" target=\"_blank\" rel=\"noreferrer noopener\">@MSFTSecurity<\/a>&nbsp;for the latest news and updates on cybersecurity.<\/p>\n<hr class=\"wp-block-separator is-style-wide\"\/>\n<p><sup>1<\/sup><a href=\"https:\/\/unctad.org\/page\/data-protection-and-privacy-legislation-worldwide\">UNCTAD Data Protection and Privacy Legislation Worldwide<\/a><\/p>\n<p><sup>2<\/sup><a href=\"https:\/\/www.oecd.org\/sti\/ieconomy\/oecdguidelinesontheprotectionofprivacyandtransborderflowsofpersonaldata.htm\" target=\"_blank\" rel=\"noreferrer noopener\">OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data<\/a>, OECD. 2013.<\/p>\n<p><sup>3<\/sup><a href=\"https:\/\/iapp.org\/resources\/article\/us-state-privacy-legislation-tracker\/\" target=\"_blank\" rel=\"noreferrer noopener\">US State Privacy Legislation Tracker<\/a>, Taylor Kay Lively, iapp. March 3, 2022.<\/p>\n<p><sup>4<\/sup><a href=\"https:\/\/iapp.org\/media\/pdf\/resource_center\/IAPP_EY_Annual_Privacy_Governance_Report_2021.pdf\">IAPP-EY Consulting and Annual Privacy Governance Report for 2021<\/a>, iapp, EY. 2021.<\/p>\n<p><sup>5<\/sup><a href=\"https:\/\/www.gartner.com\/en\/documents\/4007899\" target=\"_blank\" rel=\"noreferrer noopener\">Market Guide for Subject Rights Request Automation<\/a>, Gartner. November 2021.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/security\/blog\/2022\/03\/16\/manage-subject-rights-requests-at-scale-with-microsoft-priva\/\">Manage subject rights requests at scale with Microsoft Priva<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/security\/blog\">Microsoft Security Blog<\/a>.<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/security\/blog\/2022\/03\/16\/manage-subject-rights-requests-at-scale-with-microsoft-priva\/\" target=\"bwo\" >https:\/\/blogs.technet.microsoft.com\/mmpc\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Lauren Goodwin| Date: Wed, 16 Mar 2022 16:00:00 +0000<\/strong><\/p>\n<p>Having the right technology and processes in place can make it possible to manage a large volume of SRRs efficiently and auditable. This post discusses SRR response use cases and how Microsoft Priva subject rights requests can be used for this purpose.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/security\/blog\/2022\/03\/16\/manage-subject-rights-requests-at-scale-with-microsoft-priva\/\">Manage subject rights requests at scale with Microsoft Priva<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/security\/blog\">Microsoft Security Blog<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10759,10378],"tags":[4500,5897],"class_list":["post-18517","post","type-post","status-publish","format-standard","hentry","category-microsoft","category-security","tag-cybersecurity","tag-privacy"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18517","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=18517"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18517\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=18517"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=18517"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=18517"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}