top of page

Data Protection Insights with Laura Palmariello

Ildiko Almasi Simsic
12 hours ago
24 min read

Watch the episode


Summary

In this episode of The No Nonsense Sustainability Podcast, host Ildiko Almasi Simsic invites Laura Palmariello, the E&S Solutions Data Protection Officer, to discuss the often overlooked subject of data protection in environmental and social projects. Laura shares her passion for making data protection relatable and understandable, emphasizing its importance beyond mere compliance.

The conversation delves into the complexities of data protection, exploring practical strategies to safeguard sensitive information and the ethical considerations involved. Laura explains the concept of data protection without jargon, discusses the importance of accountability, and highlights the challenges of balancing transparency with privacy.

Listeners are encouraged to rethink their approach to data handling, focusing on ethical practices and the importance of stakeholder mapping. The episode concludes with a discussion on the need for cultural change within organizations to prioritize data protection and the role of education in fostering a more informed approach to managing personal information.


Highlights

  • Laura Palmariello emphasizes making data protection relatable and understandable.

  • Data protection involves safeguarding personal information from misuse and ensuring ethical handling.

  • Accountability and governance are crucial in managing data protection effectively.

  • Balancing transparency with data protection requires careful consideration of ethical implications.

  • Practical examples illustrate the challenges of data protection in field projects.

  • Cultural change and education are key to improving data protection practices.

  • Stakeholder mapping is essential for understanding data flows and protecting personal information.


Key takeaways

1. Data protection is about safeguarding personal information and ensuring ethical use.

2. Accountability and governance are critical for effective data protection management.

3. Balancing transparency with privacy requires careful ethical considerations.

4. Cultural change and education are necessary to improve data protection practices.

5. Stakeholder mapping helps in understanding data flows and protecting personal information.


Timestamped breakdown

[0:09] — Introduction to Data Protection: The episode introduces the topic of data protection and its importance in field projects.

[0:51] — Making Data Protection Relatable: Laura discusses her approach to making data protection relatable and understandable.

[2:15] — Defining Data Protection: Laura explains data protection without using buzzwords, focusing on ethical handling.

[3:18] — Importance of Accountability: The discussion highlights accountability as a key principle in data protection.

[5:23] — Challenges in Data Handling: Laura shares shocking findings about data handling practices in environmental projects.

[7:36] — Understanding Accountability: Explaining accountability in data protection and its implications for projects.

[11:46] — Consent in Data Collection: The complexities of obtaining valid consent in field data collection are explored.

[17:26] — Balancing Transparency and Privacy: Strategies for balancing transparency with data protection are discussed.

[29:48] — Starting the Data Protection Journey: Guidance on beginning a data protection journey with stakeholder mapping.

[33:23] — Cultural Change and Education: The need for cultural change and education in data protection practices is emphasized.


Edited transcript

Welcome back to the No Nonsense Sustainability podcast. Today we'll be talking about something that usually doesn't make it in the report or the headline: data protection. It's essential as we're recording people's private information, GPS data, their names, participation, the impacts they would suffer as a result of a project. Today I have a very special guest, our in-house data protection officer, Laura Palmariello. Welcome to the show, Laura.

Hi, Elma. Thank you very much for inviting me. Really excited to have this chat with you today. To kick things off, can you tell us what's the most exciting aspect of data protection?

Well, I think when most people think about data protection, they don't think exciting, but for me personally, I think it's the ability to make it relatable to people. I like to use complex language from legislation, but make it relatable to people and their everyday lives. It's about how does it apply to me in my job in what I do. And I think I've managed to do that because I've got an operational background. So, I've been at the front line. I've worked in a variety of businesses and worked my way up. So, to me, the most exciting thing is that relatability to go to an organization that is like, "Oh my god, UK GDPR data protection, please don't," but actually show them that relatable, that human side, how it affects them, not only in their job and what they do for other people, but also how they can protect themselves and their families a bit better. So that's what I find exciting.

I think that's probably why we work so well together because we have this hands-on project experience and your practical experience with other companies and other people translate very easily into solutions for our industry. So let's get into the buzzer battle. Explain what data protection is without using a buzzword.

Sure. So data protection is about looking after people's personal information. Any information that can identify them personally, whether that's directly or indirectly, if it's a set of information that together can identify them. And it's about making sure it doesn't end up in the wrong hands, that you protect it so that it is used in a way that is legal, lawful, ethical, but also in a way that ensures that no harm can come to them, whether it's physical or emotional harm. But it's also about being very clear about what you intend to do with the information or what you're going to do with the information, who has access to it, and making sure that you follow a set of principles to protect that data. And one of the reasons that you might use the information can be consent, but it isn't the only reason. So you can have a contract with somebody, you might have a legal obligation, but it is important that set of principles is followed. And I know data protection, not all countries have it, but I think it's not so much just about the law, but it's about the ethical side of things. Should we do this? Shouldn't we do it? And protecting people and it matters because especially in your work, Alma, you deal with very sensitive details.

Yeah, exactly. So I was wondering, first of all, it was a very good explanation, but the second thing is, you know, when you say information, that could literally mean anything. Not just what would be the obvious thing like the name, the image, the photograph, the address, but there's a lot more in that in terms of identifiability.

And I know we met through training. So we were doing martial arts and self-defense together. And a lot of the principles for data protection as we were talking are very similar to those principles of self-defense. And I think this is what makes our work so enjoyable together but also so very practical. I know that when we started working together a lot of the information we collected and the way we handle things were just mind-blowing to you and not in a good way. So what was the most shocking finding when you started working with the environmental social impact assessments and data handling practices?

So I have to say I came across shocking things, heard shocking things but at the same time as it being shocking to me it is also understandable because I see it from a point of view that people might not always understand that some information a set of numbers GPS whatever it is might actually identify a person so I can understand that and you know I'm not in the sector myself but I think with you I've learned just about how much personal information is being handled and how exposed that information can be if it's not protected and you know it's in the name environmental and social impact. So I think data protection shouldn't just be on the radar. It should be part of how you operate from day one. And whether the country has a data protection law or not, I think it's not about whether you can or can't do something. It's about whether you should or shouldn't. And I've heard of reports being made public that included names of people who oppose projects alongside their villages and reasoning for objecting. And just talking about it gives me goosebumps because people don't understand the damage that you can cause, you know. So you've got somebody who opposed the project and you've got hundreds of people having access to that information. So that makes the person who's been identified very vulnerable. So if anyone can access the fact that you know the person has objected the reasons for objecting it's not just careless it's potentially dangerous because people can find out who they are and literally they can go and knock on their door and cause harm whether it's emotional.

Exactly.

And that was shocking to me. It actually gives me goosebumps. But I think people if you're not in data protection, you don't think about it. So I can understand the human side of it.

Yeah. Exactly. And also it's the way we consume information and like how the process has evolved because the number one is we collect this personal data as part of the social socioeconomic surveys. But then that's often collected by outsourced survey agencies that then feed it into the local consultancy, the international consultancy that goes into a shared folder with all the lenders. And there's just this supply chain of companies and people who have access to this data without any requirement to dispose of it or hand it over when the project is closed. And then the second aspect that you're talking about is the disclosure. So previously these reports, yeah, there might have been a hard copy in a municipal office. The affected people had a hard copy to their own information and it was buried on a website. But now we consume information so differently. It's a lot more in the public eye.

Yeah. It doesn't sound like there's any governance and the main principle in data protection is accountability. So I struggle to understand how anybody can be made accountable because you're talking about

What do you mean by that? Because for us accountability means exactly that being transparent with how we make decisions, what impacts we identified and that's based on people's personal data and then how we apply as I mean we as like a lender how we apply our policy to that. But what does accountability mean for data protection? Accountability is the overarching sort of principles of all the principles. It means that you can there are people that are responsible that are aware of the personal data practices if that makes sense. So it's about ensuring that they are aware what's happening. They have a risk management system in place to say okay these are the risks maybe this is too risky because it could cause harm and then decisions are made based on that. So if something happens to farmer one who was identified and he opposed the project and people went to his house and knocked on his door and caused him physical or emotional harm or both who is accountable there is a whole chain of suppliers and third parties how do you trace that back to whose responsibility it was to protect that person and in data protection I'm going to use a buzz word because that is what it's called. It's the controller. It's the organization that has decided how that information is collected and used and what is done with it. But they are accountable and responsible for what happens with that information while they have it. And that's what accountability is about. And then governance is about making sure that you implement proper measures to protect those peoples technical measures, operational measures and to ensure that everybody knows what they're doing, training is in place, but so that you can trace the information back, you know where it is at all times. And so in a project where you have an international financier let's say a development bank you have the project developer you have their set of consultants and subcontractors who would be this controller there need to be agreements in place. So the very first thing you need to start doing is writing down what the plan is. The controller is the person that decides the means and the purposes of the information. and you can partner up with another organization. When I say organization, it can be a legal person. Like I'm self-employed, I would be the controller, but generally it's the organization. So if I'm the only organization that decides makes the decisions, then I make all of the decisions and everybody else I work with has to do as I tell them. You might work with several organizations together and that makes you joint controllers. The controllers are the bosses.

Okay?

So controllers are the bosses, if that makes sense. The processors are the employees. I think that's the best way to explain it.

Okay. So in this instance, the controller would be the development bank that has these requirements to collect this information and disclose. Also the developer or project owner who is responsible for the project development. And these data processors are the consultants who are executing the collection and analysis based on these organizations.

Exactly. Data processors work on your behalf. They're not allowed to do anything that goes against what you tell them they can do. So you have a contract in place. Of course, there are other things that happen. One controller can share information with another controller, but there must be a basis in law for doing that. And you know, one of them could be consent. But when we talk about consent and I think we get into that in a little bit consent is a huge topic. It's not just like a tick in a box or yes sure no problem. And I think people don't understand what consent actually means. I know we're getting into that in a bit. Yeah. So let's get to it. What does it really mean in a field? So let me give you an example. What if I'm just like on the site visit and I'm asking people, can I ask you a couple questions? we fill out these questionnaires for this project and they say yes fine and they answer the questions is that real consent?

No.

No. I mean to be honest what I would say is with every single question I'll probably answer with it depends. The reason I say no is because consent in under data protection law and again let's not just talk about law. Let's talk about what is fair and ethical. Consent must be specific. It must be informed and it must be unambiguous. So it means that you must be very clear with people what you do with that information. They can't feel any pressure to give you the consent. Let's talk let's say for example

Okay what does it mean be very clear what I do with that information. So in our field we have the public consultations. We explain that this project is coming. We need to do this impact assessment. we will have to collect this data and it will go into the report and they will have access to it. Is that enough of an explanation?

That is enough of as an explanation. As long as you don't do anything else with this, that's absolutely fine. And what you have there is verbal consent. But other things that you have to look at is there any reason why one could assume that maybe they felt under pressure to consent. So let's talk for example about an employer and employee relationship. If an employer says well you know can we have your consent if you don't consent then you know you lose your job or there's some sort of implication then that isn't valid consent. So there can't be any negatives for the person that gives the consent but it can be verbal. That's the tricky thing for us because when we go there and they say, "Yeah, we don't consent," then we explain that if we can't collect livelihood information, we will not be able to come up with appropriate mitigation measures or compensation for their losses and so they might be worse off than they were before. Is that a threat? Is that us pressuring them or is that just objectively disclosing more information to make their decision making more informed? Like I don't know I would just buzz myself for all of this but I'm just wondering because it's such a real issue that most of us had faced on the field. I think it comes back down to applying the principles about what is ethical and what is right. If you're there to help and there's no reason to believe that it is your fault that negative impacts happen as a result of it then sure you can go down the consent route but there are other things you can do. You could go down the legitimate interest route. So there is a lawful basis. Let's unpack this a little bit more.

So under GDPR UK GDPR you get lawful basis that you can use to use data. So you don't always need consent despite many people's belief. One of them is legitimate interest. So if it is in the business's legitimate interest and possibly also the individual's legitimate interest, you'd have to do an assessment to say actually we are going to collect that information because it is in their legitimate interest. And then you do an assessment and then there could be a legal basis and then they could opt out of it. So there are several legal bases that you can use and I could talk to you about them all day but at the end of the day when it comes to using the information you need to be clear it needs to be unambiguous and yes as I said there shouldn't be any negatives outcome but if you're not the reason that the outcome is negative it is as it is you know it's nothing you can do about it that that's also fine you can still you know if they don't consent then you can't help them you can you can prove that.

Yes.

So as long as you can justify and document all of your decisions. That's all anybody can ask for. And that's the beauty of data protection law, at least in the EU and the UK, is that it's based on common sense and it's based on a set of principles because what you believe to be right in that situation could be different for somebody else in a different situation and there is a lot of freedom to use what we call common sense if I can still use that phrase. Yeah, that's questionable what it means different things to different people, I guess. So, but it's about justifying and documenting. And this is where again it links in with self-defense, doesn't it? When you use self-defense, it has to be necessary. It has to be proportionate. You have to be able justify why you acted in the way you do. And I think this is why me and you both might be so passionate about all of the projects and subjects that we do because it kind of links together. It's all about protecting humans and the fundamental rights of humans.

Yes. And very often we're dealing with extremely vulnerable people and I feel like exposing their personal data just makes them even more vulnerable and that's what I think we should all avoid. So how do we balance transparency with these data protection principles? Because obviously on the one side you have this need to demonstrate procedural fairness that you've gone to the right people. You've collected the information. You've done your homework. But on the other hand you end up with this data and you end up with these people in your supply chain like the outsourcing surveying agency without any requirements for them to delete or dispose of that data when the project ended. What are some like pragmatic ideas to inspire people on balancing transparency and data protection?

There's two sides to it and one is the cultural aspect. I think there needs to be a fundamental change in the culture in these organizations to understand what personal information is and what harm can happen with it. And I think rather than starting with legislation and the law and what you should and shouldn't do, if you talk to people on a human level and make it relatable, you start seeing changes because they're like, "Oh, yes, okay, that makes sense." And then they start behaving in better ways that protects people data. And then the other side to it is the governance where you ask yourself, do we need the information? What do we need as an absolute minimum? Who needs access? Is it secure? and what's the harm if it is leaked. And this is how you make decisions on what measures to use, what safety security measures to use because it has to be proportionate, right? For some organizations, sending spreadsheets out with very basic information if it's encrypted or whatever that might be just fine because there's nothing too sensitive. It's about assessing the risks. It's all about risk assessment. And I'm sure you do a lot of that as well in your area of work. So risk assessments should be very relatable in the environmental and social sector.

Yeah. Like all of these processes and who does what responsibility, the scope, this is all extremely relatable. We do this for ENS. We set up these management systems and we tell our clients how and what they should be doing. But I guess most of these companies are really good at data protection when it comes to their employee data. But that's where the thinking stops. So they don't think okay how do our operations impact on people what kind of data we collect from them and I mean by people I mean people who are not customers because they're very aware of employee and customer information but they don't go beyond that. It's very interesting you say that because that seems shocking to me. It is the exact opposite of what I see in all other industries I work with. They look after their customers, their service users first and then employees come second. So it's like total different worlds that we live in. I think the very first thing anybody should do if you want to start protecting people not only your employees and your main stakeholders but everybody that is involved in the project then you need to do a stakeholder mapping exercise. You need to know

But we do that. That's the thing. We have stakeholder mapping. We have the stakeholder engagement plan. We know exactly who are those communities who are affected directly in we even group them. It's just we don't take that next step when we have someone with this awareness of data protection who could be like okay maybe we don't outsource the surveys or maybe we make sure that this local company like hands it all over to us and then deletes it because I think when we were having a conversation about this exact example you said they might be selling it for market research purposes and it never even occurred to me that that would be the case. Yeah, it is. In that case, if all of these things are in place, the only thing we can do is educate people. We need to shout about it. We need to explain it because I think maybe where it is failing is that people do not understand the difference between just normal basic information like your name, your address. You know, these are normal things that we know. Yeah, that's identifiable information. Maybe we need to educate people more about the information that doesn't appear to be personal information, but you can identify somebody. We call this the FBI test. And what we do is we say if you had all the resources in the world, all the money in the world, whatever is available to you, could you identify a person directly or even indirectly? Could the person be identified? If the answer is yes, then we must protect their information. That information should be protected. It's personal data.

Yeah. Well, we don't have to be the FBI. We had this one case that I asked you about. It's a project. I'm not going to bring you the whole example because I don't want people to pass the FBI test and find him. But it's a project in a country in a rural area with only 10 people affected. We have the map of the area. We have this is this farm, this is that farm, farm number five, farm number six. And we have the full description of what everybody owns like how many chickens, camels, horses, cows. Not saying anything identifiable, could be anywhere, right? But in the report, we know that farmer 5 has a long-term disability and a mental illness and a wife and three kids and this is their income and this is how many animals they have. And we have a picture of their house. That's not nonidentifiable, right?

No. No, that's not. No, it's not. It's 100% identifiable. And as I said that is an example that I find a little bit shocking because that's a lot of information that you have on a very vulnerable person and the worst thing is that we don't even know how many people have access to it and where that information is and if it goes into the wrong hands because he is vulnerable and involved in some sort of project. You can have people go knock on his door and threaten him for whatever reason.

It would be a long trip but this is it. Okay, but how do we fix it? How do we fix it for projects where for land acquisition you have very small number of people in a rural area and beyond everyone knowing everyone in the area, you do have the map, the borders of each plot and that makes it super identifiable. How do we fix a project like this? You need to look at what information is absolutely necessary. Do you need his health information? Is there any way to pseudonymize some of the information? So the first thing is to look at what information do we absolutely need and then making sure it's lawful. The reason for you having the information that it's lawful but then mostly if you get to a point where you're like we need all this information or we can't delete some of it. It is just available for whatever reason it is. Make sure that only those that need access to it have access. Set retention.

Yeah. Well, that's the thing. The policy says it's publicly disclosable or let's go let's stay with this this example. Is it okay from a data protection perspective to say that he has a long-term disability and a mental health issue without naming what those are?

No, absolutely not. Unless you have explicit consent from him to publish that information. But that's the thing we kind of do because we explain that it will go into these set of documents that will be disclosed for consultation but I don't think the person actually understands that it's on a public website and anyone from anywhere in the world can go and look into it and then you don't have valid consent because valid consent means that they should know and understand what happens to the information and this is quite interesting because you see a lot of privacy notice for example, which exactly explains to people their rights and a lot of them are over complicated and people can't read or understand them. I work on a lot of privacy notices for children at the moment or for vulnerable adults and because and I go to organization I said okay so you're aiming your product and your website at children. My 11-year-old daughter does not understand what you're saying in there at all. You must make it understandable. So it's not consent unless the person understands what you are saying to them and I guess this is the issue then. So I guess the right roots are being followed but not properly. So I would say there's a bit of an ethical issue there because we're not being totally either not totally honest or we're not explaining it in a way that is understandable and accessible to the person.

Yeah. Okay. Next example on photographs. I know that maybe 15, 20 years ago, we would ask people for consent if they would consent to being photographed and especially if they attended a public hearing. And then that photo may or may not have made its way into the publicly disclosed things. But in any case, it was on multiple people's laptops along this chain of participants in the project. often we got verbal consent but there was nothing in writing. Now the we've evolved, we've taken a step forward and often we just like blur out the faces and then that's how the picture is there because that is from a developer perspective that's evidence that they conducted these engagement meetings, right? And it's evidence that the people were there, they had access to the information. And my question now is, is it enough to just blur out the faces?

It depends. Is there any way that you can link it back to the individual who is in the picture? Then not.

I mean the FBI test probably because you know the village, the location, the time, the rest of the clothing.

In that case, it is still identifiable, but it might be a good security measure to make it pseudonymized if you know what as well. How do you do that for a photo?

Well, if the face is blurred, for example, you can't identify the person directly, but maybe there's something in the picture that gives away where they were, what the location was, something very specific to them. Or if you can't identify the person, but if you gave it to somebody else that could reidentify it, then it's because it's not identifiable to the naked eye.

Okay?

But together with another bit of information, then you make it identifiable. So blurring might not be a way of anonymizing the individual but it might be a good security measure so that the person isn't identifiable to the naked eye. Okay. So let's say there's a developer that has to conduct multiple engagement meetings in multiple villages and then they blur the faces and they don't put in the photo caption which meeting this was or in which village this meeting took place. Why do you need it then if it doesn't give you any information?

Because it shows that they talk to people. That's one way to evidence it. And now I see it less and less in the reports. It's usually as an appendix and very often we just choose not to disclose it and just keep it for internal due diligence purposes. I mean, I don't work in your sector, but I would say that there are possibly other ways that are less intrusive to evidence that you had meetings with people because from a just from a human point of view, I would find it a little bit of an invasion, you know, sort of having pictures taken of me just to evidence that you had a meeting with me. I'm sure, you know, especially, you know, in our world, we have lots of different ways of evidencing that we had a meeting. It could be just documenting it. It could be having the person sign something to say, "Yeah, we met with them. I'm just not sure pictures unless you know tell me otherwise. I'm not sure pictures are absolutely essential. If you can evidence it in other ways and that's the thing we're looking at what is the absolute minimum information that we need. So it's about going all the way back and saying why do we do this? What do we do with it? Because as you said everything is in place but I think we need to go all the way back to say okay what do we need? Why do we need it? Is it absolutely necessary? rather than what I assume happens a lot is saying we've always done it this way. So we need to question everything that is happening. Get rid of the we've always done it that way. That's the first thing that needs to go and then we can start making changes.

Okay. So let's say we have inspired some consultancies and development banks to look at their practices. What's the minimum they should be looking at? Where do they begin their data protection journey?

So you said to everybody do stakeholder mapping. I would always start with stakeholder mapping because that tells us whose information we have. So we look at whose information do we have. Then we look at where is the information coming from and where is it going through. So an entire flow map and it starts really messy but this is where we start. Then we look at do we only have basic information or do we have information that could cause particular harm, physical harm, emotional harm. And in Europe we talk about special category data. So that's health data. And I'm sure you deal with a lot of that as well. So, and then those require an extra level of protection. So, we've got two levels, of protection, if you will. And then we look at, okay, what information do we absolutely need? Start binning a lot of stuff that we're like, actually, we don't need it to achieve the purpose. It's what are we doing versus can we achieve the objective without it? If you can, get rid of it. So, a total data cleansing exercise. And then you look at okay, who needs access to it and how long are we keeping the information? and how are we keeping it safe? So, we follow an entire life cycle. Then, we need to make sure we trigger these things. So, what's happened a lot, we've now entered the area era of data deletion, I think, because you know GDPR came in 2018. Nobody's looked at it. People like, oh, I don't care about it because I won't be here in 5 years time. And now people like, oh my god, we've had this data for so long. We must get rid of it. We must look into the future and we can't just say, "Oh, we forget about it because we won't need to do anything for 2 years or 3 years." Well, in your area, where are all those consultants with all of these private laptops, with all of this information that I have downloaded onto their computers?

Exactly. All over the world. Yes. And I would say there's probably a gap in the market for systems that trigger deletion that do it safely and securely, but this is something really to focus on. So, it's the entire life cycle from start to finish with special measures for ensuring that it is deleted when it's no longer needed. And that's something that you've said, it's just there forever. So you could have all the sensitive information in the world and you could have obtained it legally, ethically, but delete it when you no longer need it. And that's how you minimize the risks to the individuals. Yeah, we've talked about how challenging that is to find that cut off or that deadline where that information is no longer needed because often these project finish these studies and then there's deliberation there's changes in the design and anytime a complaint could come like even 5 years down the road. So there is no like cookie cutter solution as to like what is the number of years that's appropriate to keep this data and I think the other thing we recognized working together is the need for like more training and upskilling of people.

I know in practice a lot of social specialists are sensitive to these some of this information being in the reports and they try to find ways to anonymize. But the biggest gap I think is the governance like how the data is handled down the supply chain from one consultancy to the subcontractor to the next subcontractor to the survey agency and I think that's why we came up with a training program that offers not only these practical questions and observations but also this very clear data governance structure.

Yeah, absolutely. And I think that's what's important. We have to educate people. We have to educate people on how to protect stakeholder data, but also how to protect themselves, how to protect the organization. And as I said, it's about making relatable. And I think that's that's where we can really stand out in making it relatable. It's not just watching a video of here is GDPR and this is what you must do. It's translating it into the language of the person doing that training. Why does it matter to me? why does it matter to the organization? And showing people that they can be part of something really really good. You know, people think of being as a DPO or working in an organization as a DPO of somebody that's not welcome. Make yourself welcome. Ask all the questions. Be awkward, but also show them how you can everybody can be part of a real change. And this is about involving everybody in the business and not just making it a side thing, a tickbox exercise. is involve everybody in the business in data protection and then it becomes part of your culture and what you do every day.

Yeah, I think that's the fantastic way to end this episode. Thank you so much. I'm particularly happy that we went through some of these practical examples because I think this will resonate with so many of our listeners who are on the field struggling between requirements for transparency and disclosure versus protecting the people. So, thank you for being here today.

Thank you so much for having me. I've really enjoyed it, Arma. I really hope we have inspired you with practical examples to protect people's data, whether they're your employees, your customers, or the people affected by the projects. We'll be back with more next time.

Comments


bottom of page