Wikimedia Technology/Annual Plans/FY2019/CDP1: Privacy, Security, and Data Management

Teams contributing to the program
Analytics, Legal, Security, SuSa

Annual Plan priorities

 * 1) 3) Knowledge as a Service - evolve our systems and structures

How does your program affect annual plan priority?
We will contribute to the evolution of our systems and structures by supporting and strengthening privacy and security-related systems, structures and services within the Wikimedia Foundation and projects.

Program Goal
Develop, maintain and mature our privacy, security, and data management practices in order to protect Wikimedia community member and donor information, comply with applicable privacy and data protection regulations, and  ensure safe and secure connection to Wikimedia projects and sites in accordance with the values of the movement.

Outcome 1

 * Ensure the high-quality protection and security of our infrastructure and data.

Outcome 2

 * Continue compliance with applicable legislation and best practices for  privacy and data management, and provide information about our privacy practices to internal and external audience

Outcome 3

 * Be compliant with best practices for data management  while upholding the values of our movement represented in the privacy policy

Outcome 4

 * Continue efforts in litigation on NSA case in collaboration with outside counsel.

CDP Budget Segment 1

 * Team:Legal

Outcome 1

 * Ensure the high-quality protection and security of our infrastructure and data.

Output 1
 * Support improvements to current practices based on FY17-18 security audit or other assessments (Q1-Q2)

Output 2
 * Support completion of security audit or other assessments in order to assess current practices and plan improvements (Q3-Q4)

Outcome 2

 * Continue compliance with applicable legislation and best practices for  privacy and data management, and provide information about our privacy practices to internal and external audiences

Output 3
 * As appropriate, ensure full or approximate compliance with applicable privacy, security, and data protection law, including data breach notification laws and comprehensive regimes such as the GDPR

Output 4
 * Conduct bi-annual compliance assessment relating to the EU GDPR

Output 5
 * Draft and update public-facing and internal privacy-related policies and procedures, and provide training as necessary

Output 6
 * Work with relevant teams to address privacy-related questions and requests from users, donors, and regulators

Output 7
 * Conduct privacy by design check-ins or provide other privacy counseling to teams as needed

Outcome 3

 * Be compliant with best practices for data management  while upholding the values of our movement represented in the privacy policy

Output 8
 * Complete the data mapping project (if not yet complete by the end of FY17-18), and support Tech in the creation of the data access guidelines

Outcome 4

 * Continue efforts in litigation on NSA case in collaboration with outside counsel.

Output 9
 * Needs for lawsuit that involve WMF legal team are promptly resolved.

CDP Budget Segment 2
Team: Security

Outcome 1

 * Ensure the high-quality protection and security of our infrastructure and data.

Output 1 Output 2
 * 1) Review and update current security policies, standards and procedures
 * 2) Review and mature security awareness functions
 * 3) Create Risk Taxonomy for evaluating IT Risk.

Reduce risk, improve application security practices, improve code quality, reduce vulnerabilities and attack surface and encourage a secure by design approach.

Output 3
 * Increase maturity and capabilities in the event of a security incident.

CDP Budget Segment 3

 * Team: Analytics

Outcome 2

 * Continue compliance with applicable legislation and best practices for  privacy and data management, and provide information about our privacy practices to internal and external audiences

Output 1
 * Make systems compliant with Legal’s GDPR recommendation

Outcome 3

 * Ensure that our data management practices uphold our movement’s values, as represented in the privacy policy.

Output 2
 * Implement data retention guidelines in new data storage and newer datasets.

Outcome 4

 * Continue efforts in litigation on NSA case in collaboration with outside counsel.

Output 3
 * Data needs for lawsuit that involve technology teams are promptly resolved.

CDP Budget Segment 4

 * Team: SuSa

Outcome 2

 * Continue compliance with applicable legislation and best practices for  privacy and data management, and provide information about our privacy practices to internal and external audiences

Output 1
 * Make systems compliant with Legal’s GDPR recommendation
 * Review and provide feedback on applicable policy material from a
 * community-supporting perspective in support of segment 1 outcome 2.
 * Prepare community-facing draft material in support of segment 1 outcome 2 as applicable.

Outcome 1

 * Ensure the high-quality protection and security of our infrastructure and data.


 * Target
 * Assess our current security practices and make adjustments and improvements as necessary

Assess the current security maturity level of the organization against the NIST CyberSecurity Framework and the SANS CIS controls and perform routine penetration testing.
 * Measurement method

Outcome 2
Continue compliance with applicable legislation and best practices for  privacy and data management, and provide information about our privacy practices to internal and external audiences
 * Target 2
 * WMF is in compliance with applicable privacy and data protection laws
 * WMF responds appropriately to privacy-related questions or requests, and provides information about our privacy practices to to users, donors, regulators, and the public

Measurement method
 * Constantly monitor relevant legal developments around the world
 * Conduct bi-annual assessment relating to the EU GDPR
 * Ensure compliance with applicable laws and best practices through training and changes to policies and procedures
 * Timely and accurate responses to user, donor, and regulator questions or requests regarding privacy-related issues, with a targeted initial response time of 7 business days for simple inquiries
 * Draft, edit, or update public-facing privacy policies and processes, as appropriate

Outcome 3

 * Ensure that our data management practices uphold our movement’s values, as represented in the privacy policy.


 * Target
 * New and older data has compliance policy executed. No data out of compliance.

Data management infrastructure retention keeps up with newer data sources.
 * Measurement method

Outcome 4

 * Continue efforts in litigation on NSA case in collaboration with outside counsel.


 * Target
 * No pending data needs by outside counsel.

Needs from outside counsel in relation of data to support the lawsuit are promptly attended to.
 * Measurement method