{"id":24157,"date":"2017-02-27T08:45:46","date_gmt":"2017-02-27T14:45:46","guid":{"rendered":"https:\/\/wpengine.com\/?p=24157"},"modified":"2021-08-30T23:34:00","modified_gmt":"2021-08-31T04:34:00","slug":"interview-hosting-data-protection-danny-dagan-10up","status":"publish","type":"post","link":"https:\/\/wpengine.com\/resources\/interview-hosting-data-protection-danny-dagan-10up\/","title":{"rendered":"Interview: Hosting And Data Protection With Danny Dagan Of 10up"},"content":{"rendered":"<p>Our guest blog post today is by Danny Dagan (<a href=\"https:\/\/twitter.com\/e_d_dagan\" target=\"_blank\" rel=\"noopener\">@E_D_Dagan<\/a>), a Senior Web Strategist at a leading WordPress agency <a href=\"https:\/\/10up.com\/\" target=\"_blank\" rel=\"noopener\">10up<\/a>. Danny graduated from Birkbeck Law School, University of London, and has written a dissertation about the new EU data protection regime. As part of his role at 10up, he works with clients on large-scale, mission-critical digital projects, often having to consider how organisations can protect the personal details of their customers in a compliant way.<\/p>\n<p>WP Engine takes data protection seriously, both in our compliance efforts and the ways in which we secure all user data through encryption and other best practices in security. To that end, we\u2019ve recently established a governance, risk, and compliance team within our security organization to address compliance-related activities. Given the responsibility to secure the data of EU citizens and residents, we asked Danny to share his perspective on four data protection questions we hear frequently from customers.<\/p>\n<p><strong>Q: Your company hosts personal data of EU citizens and residents in your country. Do you have to store these in the country of those citizens and residents (for example, does data of Dutch citizens need to be stored in the Netherlands only)?<\/strong><\/p>\n<p>A: You do not have to store personal data of your users in their own country. As long as this data is stored with the EEA (that is, any European Union Country + Iceland, Liechtenstein and Norway), then you are compliant. The law on the protection of personal data in the EU has been harmonised for many years, and will become even more so when the new EU data protection regime comes into force in May 2018. The idea is that because the law is the same for all EU countries, it allows the free movement of personal data between these countries, protected by the same rules.<\/p>\n<p><strong>Q: Can you store the data of EU citizens and residents outside the EU?<\/strong><\/p>\n<p>A:\u00a0You can, but this is a complex area that requires you to do a little bit of homework because it depends on the country and the hosting company you work with. The underlying principle is that the data you store should be hosted and processed to a standard that, in the very least, conforms with EU legal requirements. There are several methods of achieving this, the most common of which are:<\/p>\n<p>a. By hosting customer details in one of the countries that the EU deems has \u2018adequate\u2019 protections for personal data. The list is fairly short, and currently includes: Andorra, Argentina, Canada, Faroe Islands, Guernsey, Israel, Isle of Man, Jersey, New Zealand, Switzerland and Uruguay.<\/p>\n<p>b. By using standard contractual terms approved by the EU that effectively mandate the hosting company you work with complies with EU data protection rules.<\/p>\n<p>c. In the USA &#8211; you need to ensure your hosting company is signed up to the Privacy Shield framework (the new system that replaced \u2018Safe Harbour\u2019). Note that there are currently some legal challenges to the Privacy Shield, but at the time of writing it is still your best method to ensure you can host customer data in the US.<\/p>\n<p>Overall, your best bet is actually to host your customer data in the EU. If you have mixed US and EU customer-base and would like to host your data in the US, check with your hosting provider that they have registered with the Privacy Shield programme.<\/p>\n<p>WP Engine says: WP Engine is registered under Privacy Shield and has data centre locations across Northern America, Europe and Asia. It also has a Governance, Risk and Compliance team who are able to provide guidance on specific client requests.<\/p>\n<p><strong>Q: I hear there is a new data protection law in the EU. How will it affect my company?<\/strong><\/p>\n<p>A:\u00a0The new EU Data Protection Regulation will come into effect across the EU on 25 May 2018. It will tighten standards and responsibilities of companies in how they treat the personal data of individuals. Some noteworthy aspects of the new law:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>It will allow the imposition of fines of up to EUR 20 million or 4% of annual worldwide revenue for breaches.<\/li>\n<li>You will have to inform your data protection authority within 72 hours of a data breach, and your customers if the breach is serious.<\/li>\n<li>Requirements will be tightened about the collection of personal data, and consent for such collection must be specific, informed and unambiguous (and pre-ticked boxes or inactivity will not constitute consent).<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>The best way for a company to prepare for the new law is by auditing the way it collects and handles personal data, and putting in place a compliance plan. If you are a smaller company, make sure you have read up on the new law and taken steps to comply. Larger organisations will likely wish to run a compliance project, hiring a specialist resource to help.<\/p>\n<p>For a more detailed explanation of key aspects of the new law and how to approach it, see my presentation <a href=\"https:\/\/wordpress.tv\/2016\/11\/11\/danny-dagan-privacy-by-design-7-things-you-cant-afford-to-ignore\/\" target=\"_blank\" rel=\"noopener\">here<\/a> (given in Holland, but relevant to any EU country).<\/p>\n<p><strong>Q:\u00a0Will this new law also apply in the UK, considering Brexit?<\/strong><\/p>\n<p>A: It is almost certain that the new law, or a similar set of rules will apply in the UK post-Brexit. This is because the new law will come into effect in May 2018 while the UK is still part of the European Union. The UK government has signalled that it will keep existing EU law upon Brexit, and only then start repealing legislation.<\/p>\n<p>The UK will also want to ensure British companies are able to store the personal data of EU nationals, so it is unlikely to water down standards. This view was reinforced by the UK\u2019s Data Protection Commissioner who said: \u201cThe fact is, no matter what the future legal relationship between the UK and Europe, personal information will need to flow.\u201d<\/p>\n<p><em>Please note that this blog post is made available by WP Engine for educational purposes only as well as to give you general information and a general understanding of the law but not to provide you with specific legal advice. By using this blog, you understand that the opinions expressed by Danny Dagan are his alone. This blog should not be used as a substitute for competent legal advice from a licensed professional attorney in your state or country, and WP Engine is not responsible for the accuracy of any of the information supplied by Danny Dagan.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Our guest blog post today is by Danny Dagan (@E_D_Dagan), a Senior Web Strategist at a leading WordPress agency 10up. Danny graduated from Birkbeck Law School, University of London, and has written a dissertation about the new EU data protection regime. As part of his role at 10up, he works with clients on large-scale, mission-critical<span class=\"tile__ellipses\">&hellip;<\/span><span class=\"tile__ellipses--animated\"><\/span><\/p>\n","protected":false},"author":164,"featured_media":24165,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[257,85],"tags":[355,920,470,13],"class_list":["post-24157","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-interviews","category-security-2","tag-10up","tag-danny-dagan","tag-interview","tag-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Interview: Hosting And Data Protection With Danny Dagan Of 10up<\/title>\n<meta name=\"description\" content=\"In this interview on hosting and data protection, we asked 10up&#039;s Danny Dagan to share his perspective on four data protection questions we hear...\" \/>\n<meta name=\"robots\" content=\"noindex, follow\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Interview: Hosting And Data Protection With Danny Dagan Of 10up\" \/>\n<meta property=\"og:description\" content=\"In this interview on hosting and data protection, we asked 10up&#039;s Danny Dagan to share his perspective on four data protection questions we hear...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/wpengine.com\/resources\/interview-hosting-data-protection-danny-dagan-10up\/\" \/>\n<meta property=\"og:site_name\" content=\"WP Engine\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/wpengine\" \/>\n<meta property=\"article:published_time\" content=\"2017-02-27T14:45:46+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-08-31T04:34:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/wpengine.com\/resources\/wp-content\/uploads\/2017\/02\/security-hero-10up-interview.png\" \/>\n\t<meta property=\"og:image:width\" content=\"824\" \/>\n\t<meta property=\"og:image:height\" content=\"342\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"James Dowell\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@wpengine\" \/>\n<meta name=\"twitter:site\" content=\"@wpengine\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"James Dowell\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/wpengine.com\/resources\/interview-hosting-data-protection-danny-dagan-10up\/\",\"url\":\"https:\/\/wpengine.com\/resources\/interview-hosting-data-protection-danny-dagan-10up\/\",\"name\":\"Interview: Hosting And Data Protection With Danny Dagan Of 10up\",\"isPartOf\":{\"@id\":\"https:\/\/wpengine.com\/resources\/#website\"},\"datePublished\":\"2017-02-27T14:45:46+00:00\",\"dateModified\":\"2021-08-31T04:34:00+00:00\",\"author\":{\"@id\":\"https:\/\/wpengine.com\/resources\/#\/schema\/person\/9c62fe03c1f8bfffe2915a141f5db3da\"},\"description\":\"In this interview on hosting and data protection, we asked 10up's Danny Dagan to share his perspective on four data protection questions we hear...\",\"breadcrumb\":{\"@id\":\"https:\/\/wpengine.com\/resources\/interview-hosting-data-protection-danny-dagan-10up\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/wpengine.com\/resources\/interview-hosting-data-protection-danny-dagan-10up\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/wpengine.com\/resources\/interview-hosting-data-protection-danny-dagan-10up\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/wpengine.com\/resources\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Interview: Hosting And Data Protection With Danny Dagan Of 10up\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/wpengine.com\/resources\/#website\",\"url\":\"https:\/\/wpengine.com\/resources\/\",\"name\":\"WP Engine\",\"description\":\"Managed Hosting for WordPress\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/wpengine.com\/resources\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/wpengine.com\/resources\/#\/schema\/person\/9c62fe03c1f8bfffe2915a141f5db3da\",\"name\":\"James Dowell\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/wpengine.com\/resources\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/3a30796619bc4e8b209f382f5a603ba6b7b84fdf82bdda3e7ac01252dabbe6d6?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/3a30796619bc4e8b209f382f5a603ba6b7b84fdf82bdda3e7ac01252dabbe6d6?s=96&d=mm&r=g\",\"caption\":\"James Dowell\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Interview: Hosting And Data Protection With Danny Dagan Of 10up","description":"In this interview on hosting and data protection, we asked 10up's Danny Dagan to share his perspective on four data protection questions we hear...","robots":{"index":"noindex","follow":"follow"},"og_locale":"en_US","og_type":"article","og_title":"Interview: Hosting And Data Protection With Danny Dagan Of 10up","og_description":"In this interview on hosting and data protection, we asked 10up's Danny Dagan to share his perspective on four data protection questions we hear...","og_url":"https:\/\/wpengine.com\/resources\/interview-hosting-data-protection-danny-dagan-10up\/","og_site_name":"WP Engine","article_publisher":"https:\/\/www.facebook.com\/wpengine","article_published_time":"2017-02-27T14:45:46+00:00","article_modified_time":"2021-08-31T04:34:00+00:00","og_image":[{"width":824,"height":342,"url":"https:\/\/wpengine.com\/resources\/wp-content\/uploads\/2017\/02\/security-hero-10up-interview.png","type":"image\/png"}],"author":"James Dowell","twitter_card":"summary_large_image","twitter_creator":"@wpengine","twitter_site":"@wpengine","twitter_misc":{"Written by":"James Dowell","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/wpengine.com\/resources\/interview-hosting-data-protection-danny-dagan-10up\/","url":"https:\/\/wpengine.com\/resources\/interview-hosting-data-protection-danny-dagan-10up\/","name":"Interview: Hosting And Data Protection With Danny Dagan Of 10up","isPartOf":{"@id":"https:\/\/wpengine.com\/resources\/#website"},"datePublished":"2017-02-27T14:45:46+00:00","dateModified":"2021-08-31T04:34:00+00:00","author":{"@id":"https:\/\/wpengine.com\/resources\/#\/schema\/person\/9c62fe03c1f8bfffe2915a141f5db3da"},"description":"In this interview on hosting and data protection, we asked 10up's Danny Dagan to share his perspective on four data protection questions we hear...","breadcrumb":{"@id":"https:\/\/wpengine.com\/resources\/interview-hosting-data-protection-danny-dagan-10up\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/wpengine.com\/resources\/interview-hosting-data-protection-danny-dagan-10up\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/wpengine.com\/resources\/interview-hosting-data-protection-danny-dagan-10up\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/wpengine.com\/resources\/"},{"@type":"ListItem","position":2,"name":"Interview: Hosting And Data Protection With Danny Dagan Of 10up"}]},{"@type":"WebSite","@id":"https:\/\/wpengine.com\/resources\/#website","url":"https:\/\/wpengine.com\/resources\/","name":"WP Engine","description":"Managed Hosting for WordPress","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/wpengine.com\/resources\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/wpengine.com\/resources\/#\/schema\/person\/9c62fe03c1f8bfffe2915a141f5db3da","name":"James Dowell","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/wpengine.com\/resources\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/3a30796619bc4e8b209f382f5a603ba6b7b84fdf82bdda3e7ac01252dabbe6d6?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/3a30796619bc4e8b209f382f5a603ba6b7b84fdf82bdda3e7ac01252dabbe6d6?s=96&d=mm&r=g","caption":"James Dowell"}}]}},"acf":[],"_links":{"self":[{"href":"https:\/\/wpengine.com\/resources\/wp-json\/wp\/v2\/posts\/24157","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wpengine.com\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wpengine.com\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wpengine.com\/resources\/wp-json\/wp\/v2\/users\/164"}],"replies":[{"embeddable":true,"href":"https:\/\/wpengine.com\/resources\/wp-json\/wp\/v2\/comments?post=24157"}],"version-history":[{"count":0,"href":"https:\/\/wpengine.com\/resources\/wp-json\/wp\/v2\/posts\/24157\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wpengine.com\/resources\/wp-json\/wp\/v2\/media\/24165"}],"wp:attachment":[{"href":"https:\/\/wpengine.com\/resources\/wp-json\/wp\/v2\/media?parent=24157"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wpengine.com\/resources\/wp-json\/wp\/v2\/categories?post=24157"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wpengine.com\/resources\/wp-json\/wp\/v2\/tags?post=24157"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}