1. Think about the data you collect from users 从用户收集了什么信息,这些信息是否是必须必要的。邮件,电话,地址。。。。
2. 分析如何处理这些信息。如何接受,如何传输,如何存储,什么时候删除。。。系统全过程有文档
3. 获得授权
4 加密数据,肯定不能明文存储
5 双重认证
6 教育通知用户 :
教育:让用户了解数据如何处理,如何保证安全的
You need to help them understand how data security works, where their personal information goes, how it is processed, and what they can do to ensure its safety
通知:例如数据泄漏72小时通知。
You should inform your users of any changes that may happen to the terms and conditions. Also, in case of a data breach, you must inform users within 72 hours. GDPR regulations make sure that companies can’t conceal the truth for months, like Uber did.
7 用户退出时要删除数据
8 检查服务,SDK是否合规。你的供应商,thirdpart是否合规也需要考虑进去
9 找个首席数据官