How to Extend GDPR Compliance to Digital Assets

TL;DR
GDPR compliance must cover the actual behavior of enterprise websites and mobile apps, including every third party whose code collects data, drops cookies, captures device IDs, profiles users, or enables tracking. Organizations should map these activities, obtain appropriate consent, align their privacy policies with observed behavior, apply vendor risk management, establish breach-reporting processes, and assign clear cross-functional ownership.
Transcript
Uh, just quickly, um, I'm Evan Wolf. I'm a partner at Crowell & Moring, and I head the Privacy and Cybersecurity practice. We're a global law firm with about seven hundred lawyers. I'm based in Washington, DC, and have spent the last twelve years advising companies on cybersecurity and privacy issues. And then the ten years before that, I worked at... Read More
Key Insights
- GDPR compliance begins as an ongoing operational responsibility rather than ending on May 25. The presenters argue that organizations must continually understand and govern how their websites, applications, internal code, and invited third parties collect, process, track, and share consumer data.
- GDPR scope includes both US and non-US companies when they collect or process data from EU citizens or residents. Organizations therefore cannot treat the regulation as relevant only to enterprises physically established within Europe.
- Core GDPR obligations include privacy by design, data mapping, privacy assessments, appointing a data privacy officer, supporting challenges to automated decision-making, and implementing the right to be forgotten. These obligations must be connected to actual systems and operating practices.
- A digital asset is an enterprise website or mobile application that consumers use. Treating these properties as governed business assets is necessary because company code and third-party code can execute on a consumer's device and perform data collection or tracking.
- Third-party risk extends beyond an organization's directly identified vendors to further-removed parties operating through the digital environment. These parties may drop cookies, collect device IDs, profile consumers, or enable online tracking when a person visits a website.
- Consent must cover relevant data collection performed through the website, including collection by invited third parties. Organizations need to understand the parties and activities present before they can give consumers a meaningful opportunity to accept that collection.
- A privacy policy must match the website's actual behavior, including the conduct of third parties whose code runs on consumer devices. If an organization does not know what its digital asset and invited parties are doing, its stated policy may not reflect reality.
- Clear governance is essential because digital asset responsibility may span marketing, sales, revenue operations, security, legal, privacy, and risk. The presenters say coordinated ownership works better, while CISO participation adds security rigor and experience with vendor risk management.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How should companies extend GDPR compliance to websites and apps?
Companies should treat websites and mobile apps as governed digital assets. They need to identify first-party and third-party code, determine what data each party collects, document cookies and device identifiers, understand profiling and tracking, obtain consumer consent, apply vendor risk management, align privacy policies with observed behavior, and establish clear responsibility across security, legal, privacy, marketing, sales, and risk functions.
Q: Why are third parties a GDPR risk on enterprise websites?
Third parties are a risk because their source code can run on a consumer's device when the consumer visits an enterprise website. That code may drop cookies, collect device IDs, conduct profiling, or support online tracking. Further-removed parties can also participate, so knowing only major platforms or direct vendors does not provide a complete view of the digital environment.
Q: What data collection activity should a company assess on its website?
A company should assess data collection performed by its own code and by every third party operating through the website. The assessment should identify cookies, device ID collection, consumer profiling, online tracking, and data sharing activities. It should also determine whether consumers can provide consent and whether actual collection practices agree with the organization's published privacy policy.
Q: How does consumer consent apply to third-party website code?
Consumer consent must account for relevant collection occurring through the digital asset, not only collection performed directly by the company. Because invited third parties and further-removed parties may execute code on a consumer's device, the organization must understand those activities and provide an opportunity for the consumer to indicate whether the associated data collection is acceptable.
Q: Why should vendor risk management include digital assets?
Vendor risk management should include digital assets because websites and applications can host many companies and source-code components that traditional vendor inventories overlook. Those parties may directly interact with consumers and collect cookies, device IDs, or tracking information. Applying vendor risk processes helps the enterprise identify participants, assess their activities, and connect digital operations to GDPR and privacy obligations.
Q: How should a privacy policy reflect website activity?
A privacy policy should accurately reflect what the organization's website or application does, along with what invited third parties do when their code runs on consumer devices. The company therefore needs direct visibility into data collection, cookies, device identifiers, tracking, profiling, and sharing. A written policy alone is insufficient when actual digital behavior differs from its statements.
Q: Who should own GDPR governance for websites and mobile apps?
Ownership should be explicit and coordinated across the functions involved in the digital asset. Depending on the enterprise, these may include marketing, sales, revenue operations, a data privacy officer, a privacy officer, general counsel, risk, and security. The presenters emphasize that unclear responsibility can mean nobody is fully accountable or that relevant teams are not integrated into risk management.
Q: Why is security leadership useful in digital asset compliance?
Security leadership is useful because a CISO or another security-minded professional is accustomed to rigor and understands vendor risk management. Digital asset compliance depends heavily on identifying and controlling third-party code, so security experience complements the knowledge held by marketing, sales, media, privacy, legal, and revenue teams. The presenters report that CISO involvement usually makes the effort more successful.
Summary & Key Takeaways
-
GDPR applies to US and non-US organizations that collect or process data from EU citizens or residents. Core obligations discussed include privacy by design, data mapping, privacy assessments, appointing a data privacy officer, supporting challenges to automated decisions, and implementing the right to be forgotten across relevant business operations.
-
Compliance programs often overlook the digital environment where consumers interact with websites and mobile apps. Organizations must identify their own data collection as well as third-party and further-removed parties whose code tracks users, drops cookies, collects device IDs, conducts profiling, or shares information on consumer devices.
-
Effective digital governance requires coordinated participation from marketing, sales, revenue operations, security, legal, privacy, and risk teams. Clear responsibility is essential because digital assets often depend on third-party code. Security involvement can strengthen rigor and extend established vendor risk management practices to websites and applications.
Read in Other Languages (beta)
Share This Summary π
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity π






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator