60 minute session
Protecting and working with sensitive data in Azure
In this session you learn how to work safely with privacy-sensitive data within Microsoft Azure. From both a legal and technical perspective, it explains what you need to take into account when you bring data to the cloud.
The session starts with the most important compliance aspects, such as the GDPR and Standard Contractual Clauses (SCCs), and emphasises that technology only becomes relevant once the legal foundation is in order. Next, it zooms in on concrete measures within Azure to protect sensitive data.
Attendees gain insight into various layers of security – from subscription- and service-level measures to general best practices such as data minimisation and anonymisation.
Learning goals
- Understanding which legal preconditions (such as the GDPR and SCCs) apply when working with data in the cloud
- Determining when and why processing privacy-sensitive data is permitted
- Gaining insight into security measures at various levels within Azure (subscription, service and general)
- Correctly applying access management and security (such as RBAC, MFA and identity management)
- Recognising specific Azure features for data protection (such as Always Encrypted and Key Vault)
- Applying data minimisation and monitoring of data access
- Understanding and deploying anonymisation as a strategy for working with data safely
- Finding the right balance between data protection and usability
Level
Beginner
Topics
Materials