Homepage Knowledge RPA and Data Protection: Essential Information for Businesses

Intelligent Automation and AI

RPA and Data Protection: Essential Information for Businesses

@mindbox

Zespół Mindbox

6 minutes

As Forrest Gump said, “shit happens.” Unpredictable events govern our lives, as described in The Black Swan[i]. The book gives enough examples to convince even the greatest skeptics that low-probability events with major consequences occur relatively often. Data can therefore be lost or leak uncontrollably even from the best-protected systems. Real organizations have experienced this[ii], with painful consequences. Data security and continuous improvements to protection should always remain under consideration.    

Why is data protection so important in RPA projects?

  The key to understanding data protection in business-process robotization (RPA—Robotic Process Automation) is that robots are not independent. They always operate in close connection with people, usually as digital assistants. Even autonomous robots[iii] require human interaction from time to time. Unfortunately, people are the least reliable element of the digital world: wherever a person is involved, the risk of error or negligence rises. When people process confidential information, every additional person with access increases the probability of a security breach. Business-process robots very often process either sensitive business data or legally protected personal data. In either case, an extreme leak can threaten the continuity of the whole company. Correct data protection and processing are also fundamental requirements of business processes. An unattended robot must not alter database tables it should not access merely because someone with excessive privileges granted it permission. Finding errors and breaches requires time, resources, and skills, all of which cost money. Every security-policy violation in an RPA process threatens the organization’s entire IT infrastructure. Cybercriminals wait for precisely such opportunities: a vulnerability may be exploited by ransomware and cause chaos and enormous financial losses[iv]. RPA tools should unquestionably be used only by properly trained employees who understand compliance requirements and secure data processing.    

How much does RPA data protection cost?

  A lot or a little? It depends. A properly conducted RPA implementation and rational policy for protecting data, processes, and IT infrastructure improve organizational security and constitute a sound investment. Business data is generally priceless, and the threat of severe penalties for personal-data leaks means no amount spent on security is excessive. Robotization also removes the human factor from many processes, substantially reducing the likelihood of leaks or information-security violations. A reasonable level of RPA data security requires several basic but important rules:
  1. access to bots must always require a secure authentication mechanism,
  2. the central repository of bot passwords and credentials must be encrypted and stored in secure, protected storage,
  3. every bot must require an individual set of login credentials,
  4. unused or retired bots must not remain associated with confidential credentials,
  5. administrator accounts must use at least two-factor authentication,
  6. confidential data must be accessible only to those who need it,
  7. the group of people holding the highest privileges must always be minimized,
  8. RPA-system access must be restricted to authorized users authenticated with multiple factors.
Data-protection costs in business-process robotization consist primarily of conceptual work on security rules, implementation, bot-code modifications, and resilience tests against every possible threat. Hiring Red Teams is expensive and may represent a noticeable part of an RPA implementation, but it generally costs less than data loss or encryption by cybercriminals. Intangible reputational damage and the price of lost customer trust must also be counted. Potential losses will therefore outweigh the cost of securing robotized processes.    

RPA and the GDPR

  The General Data Protection Regulation took effect in May 2018. Companies have learned to live with its restrictions and remember the penalties for failing to follow personal-data rules covering collection, storage, deletion, processing, and disclosure: EUR 20 million or 4% of the preceding year’s annual turnover. The law is clear, but compliance requires organizational effort and suitable IT solutions. Two mandatory documents help: the security policy and instructions for using IT systems. The latter, which also governs every RPA bot, specifies procedures for granting and recording data-processing permissions and identifies responsible people. It must describe authentication methods and safeguards and the procedures for managing and using them, as well as starting, suspending, and terminating work for system users and robots. It also covers backups of datasets, programs, and processing tools; how, where, and for how long electronic media and backups containing personal data are stored; and how systems and bots are protected against viruses, malware, ransomware, and similar threats. Data security in robotized RPA processes is therefore inseparable from GDPR requirements. Formal legal requirements and numerous good practices[v] help create an individual, comprehensive data-security policy. RPA is attractive because it automates laborious, error-prone work. If a former employee requests deletion of personal data, a robot can search databases containing millions of records and perform the required operations faster and more accurately. Bots can automatically report breaches, perform pseudonymization, answer customer questions about data use, or prove that personal data has been removed from business systems. They can identify errors and irregularities in storage and processing, supporting statutory GDPR duties. RPA bots that automate GDPR procedures[vi] accelerate them, reduce errors, and materially help meet legal requirements.    

Data processing by robots under Polish law

  Personal-data protection and processing are regulated by the Polish Personal Data Protection Act of May 10, 2018[vii]. Supervisory duties are performed by the Personal Data Protection Office. RPA robots have no distinct statutory status and are not treated differently. If they process personal data, their operation is subject to the Act and their owner is responsible as for its own actions. Robots must operate lawfully. The GDPR is not the only relevant law: handling employee and customer matters must also comply with legislation on electronic services, the company social-benefits fund, the Labor Code, telecommunications law, and protection of personal data processed for preventing and combating crime. All requirements must be incorporated at the design stage and tested thoroughly during implementation to prevent violations.    

What should you do if an RPA error causes a data breach?

  A robot, like a person, can make a mistake; it is ultimately a product of human hands and intellect. What should be done when a robot causes a leak? The answer is simple: follow the normal procedure. First notify the organization’s Data Protection Officer and, importantly, the data controller. The controller has two principal duties: notify the people concerned and the supervisory authority, within 72 hours. The procedure is well documented and publicly available. If an RPA robot caused the leak, notify the relevant system administrator and security team as well. Log analysis should establish the incident’s nature and severity and the measures needed to restore correct data and robot operation. Notification of individuals is important when an incident threatens their rights or freedoms, for example by enabling fraud with stolen data. Finally, not every business error in implementing or applying GDPR rules is a reportable security incident. Wording a consent inconsistently with GDPR guidance or incorrectly telling a data subject that deletion is impossible, for example, does not itself constitute a security incident. [i] Nassim Nicholas Taleb, The Black Swan, Zysk i S-ka, Poznań, 2020 [ii] https://www.ibm.com/security/data-breach [iii] https://mindboxgroup.com/pl/rpa-z-nadzorem-a-nienadzorowane-jakie-sa-glowne-roznice/ [iv] https://www.cloudwards.net/ransomware-statistics/ [v] https://poradnikprzedsiebiorcy.pl/-jak-uniknac-kar-czyli-dobre-praktyki-rodo [vi] https://prnews.pl/bank-ratuje-sie-robotami-pieklem-rodo-435558 [vii] https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU20180001000/U/D20181000Lj.pdf

@mindbox

Zespół Mindbox

Newsletter

Subscribe to our Newsletter

Newsletter (EN)