Skip to main content

Does Vertica is GDPR (General Data Protection Regulation) complied?

  • February 13, 2018
  • 4 replies
  • 12 views

mosheg
Forum|alt.badge.img+2
  • Participating Frequently

The EU General Data Protection Regulation (GDPR) is set to take effect on May 25, 2018. This new regulation broadly affects all organizations, government agencies, and companies throughout the world that collect or use personal data tied to EU residents.

What should we answer customers who ask if V is GDPR complied?

Other vendors dive deeper into the regulation and how it can help customers to accelerate their response to GDPR, however, they do not state if they are complied or not.
Maybe Vertica should do the same?
Micro Focus does it but not Vertica. (see below)

References:
A. SPARK
http://www.sparkcompliance.com/gdpr-readiness/

B. MSSQL
https://docs.microsoft.com/en-us/sql/relational-databases/security/microsoft-sql-and-the-gdpr-requirements

C. AWS
https://aws.amazon.com/blogs/security/aws-and-the-general-data-protection-regulation/

D. MongoDB
https://www.mongodb.com/blog/post/gdpr-impact-to-your-data-management-landscape-part-1

E. Oracle
https://www.oracle.com/applications/gdpr/index.html

F. Vertica doc:
"Vertica itself is not FIPS compliant but it is compatible with running on a FIPS-enabled system using FIPS resources."
https://my.vertica.com/docs/9.0.x/HTML/index.htm#Authoring/Security/FIPS/FIPSOverview.htm

G. Micro Focus solutions help manage and protect your data in accordance with GDPR enabling you to grow your business with confidence.
https://software.microfocus.com/en-us/marketing/gdpr

4 replies

Ben_Vandiver
Forum|alt.badge.img
  • Participating Frequently
  • February 13, 2018

This is a great question - we should have a good answer. I think it could be a selling point of Vertica compared to piles of parquet somewhere.

Vertica's FIPS mode will be FIPS compliant on a FIPS system. We aren't certified as FIPS, however.

Does anyone have a good resource for what it means to be GDPR compliant?


viganog
Forum|alt.badge.img+1
  • Participating Frequently
  • February 13, 2018

Be compliant with GDPR is a mandatory option to discuss with EU Telcos.
GDPR covers from data lineage to the data governance, security and data encryption.

We were dealing with Intracom (System Integrator) last year about a possible adoption of Vertica for their applications. We submitted Vertica features to their requests on GDPR compliance about: Data Masking, Authentication, RBAC, Row and Column access policies, User privileges and access, communication Encryption, auditing, data encryption at rest and in motion (with Voltage and Red Hat FS encryption)
.
Most of the Vertica features were accepted for GDPR.
Their comments were about data encryption at rest:

  • Voltage is fine, but it is an expensive product
  • Red Hat File System encryption limits the Linux distribution choice
  • do you plan to integrate an OpenSource Tool ?

GDPR also requires 'data lineage', covered by 3rd parties product


mosheg
Forum|alt.badge.img+2
  • Author
  • Participating Frequently
  • February 13, 2018

To get GDPR compliant is a long procedure. GDPR contains 99 articles that define its requirements and rights granted to EU citizens, GDPR operations and structure, and penalties. However, the exact security measures are not always defined. Presumably, if data is lost or stolen, a company could be considered not in compliance.
https://www.csoonline.com/article/3203264/compliance/what-are-the-gdpr-requirements.html?upd=1518507955336

Until Vertica will be compliant, is it possible to publish recommendations or white paper for organizations who wish to get GDPR compliance, as other ISVs do?


Forum|alt.badge.img+2
  • Participating Frequently
  • March 29, 2018

One way to get started is to translate GDPR (business) requirements in technical requirements demonstrate that they fully/partially fulfilled by Vertica.