How to Build a Practical GDPR Readiness Program

221 views
β€’
May 2, 2018
by
RSAC Cybersecurity
YouTube video player
How to Build a Practical GDPR Readiness Program

TL;DR

Start GDPR readiness by locating personal data, identifying compliance gaps, prioritizing action, and documenting every decision. Build a cross-functional team that includes privacy, security, IT, marketing, and HR, then design sustainable controls for data subject requests, consent, policies, security, and incident response rather than relying on a one-time spreadsheet exercise.

Transcript

Okay, welcome everyone to the session Get Cooking with GDPR: Practical Techniques and Recipes for Success. I'd like to introduce our speaker, Cindy Comfort. She's a cybersecurity leader of the US public sector markets and CTO, uh, Data Privacy and Security at IBM Security. So welcome, Cindy. Thank you, Kevin, and good afternoon everyone. So we are ... Read More

Key Insights

  • GDPR applies to living individuals on European soil, including employees, consumers, and contractors, rather than only to European citizens. Organizations around the world may fall within scope when they actively market to or collect information from those individuals in Europe.
  • The enforcement date was not expected to be extended, but regulators indicated that active progress could influence how leniently an organization was treated. Evidence of ongoing work therefore mattered, especially when a program was incomplete as enforcement approached.
  • GDPR readiness varies according to organizational maturity and risk tolerance. Mature organizations may need only incremental improvements, while slower organizations must determine their next steps, and organizations that wait for enforcement risk fines, processing restrictions, or limits on data transfers.
  • The IBM GDPR framework contains five phases: assess, identify, design, transform, and conform. The journey begins with current-state assessment and gap identification, then moves through control design and organizational change toward operations and documented evidence of compliance.
  • A cross-functional GDPR team is essential because privacy staff cannot implement security and privacy by design alone. Security, IT, marketing, HR, and other relevant functions need a seat at the table when systems, policies, controls, and public-facing applications are reviewed.
  • Personal data discovery is one of the largest implementation challenges because organizational information is rarely stored in one place. Automation helps locate and track that data continuously, while a one-time spreadsheet inventory is unlikely to provide a sustainable operating process.
  • Data subject rights require secure and timely procedures for accessing, correcting, deleting, or transferring personal information. Requests must be handled within one month, and identity checks are necessary to prevent an attacker from impersonating someone and obtaining their collected data.
  • Documentation is a core element of GDPR conformance because organizations must show their work. An effective audit trail records obligations, decisions, controls, activities, outcomes, and deliverables, providing evidence that the organization has taken deliberate steps toward compliance.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How do you build a practical GDPR readiness program?

Build the program in five phases: assess the current state, identify compliance gaps, design controls across people, processes, and data, transform affected operations, and establish conformance through documentation. Begin with high-priority activities such as a data inventory, gap analysis, prioritized action plan, policy review, security assessment, and formation of a cross-functional team that can implement sustainable practices.

Q: Who does GDPR apply to according to the session?

GDPR applies to living individuals on European soil, not only to European citizens. Those individuals may be employees, consumers, or contractors. Organizations outside Europe may also be affected when they actively do business in Europe, market to individuals there, or collect their information. The session distinguishes this active engagement from incidental contact that may not place an organization within scope.

Q: What are the five phases of the IBM GDPR framework?

The framework consists of assessing the organization’s current position, identifying gaps, designing appropriate controls, transforming the organization, and reaching conformance. Control design covers people, processes, and data, while transformation is especially important for handling data subject rights. Conformance requires organizations to document their obligations and demonstrate the actions taken to meet them.

Q: What GDPR readiness activities should organizations prioritize?

Priority activities include appointing a data protection officer when appropriate, creating a cross-functional GDPR team, inventorying personal data, completing a gap analysis, and producing a prioritized action plan. Organizations should also review security policies and practices, document their work, identify a lawful basis for processing, update privacy statements, and examine consent and other choice mechanisms.

Q: Why is personal data mapping important for GDPR?

Personal data mapping establishes what information the organization holds and where it is stored. Without that knowledge, the organization cannot reliably secure the data or respond when an individual asks to access, correct, delete, or transfer it. Because data is typically distributed across many systems and locations, the session presents automation as critical to creating a sustainable inventory.

Q: Why should GDPR planning involve multiple business functions?

GDPR planning should involve multiple functions because the required changes extend beyond the privacy office. Security and IT contribute technical controls and support security and privacy by design, while marketing, HR, and other teams manage systems and processes involving individuals. Their participation helps ensure that policies, consent mechanisms, applications, data practices, and operational procedures are reviewed together.

Q: How should organizations handle GDPR data subject requests?

Organizations need a process that enables an individual to access personal information and request its correction, deletion, or transfer within one month. That process depends on an accurate understanding of where the person’s data is stored. It must also verify the requester securely so that a hacker cannot impersonate an individual and use the procedure to steal collected personal information.

Q: Why is documentation necessary for GDPR conformance?

Documentation allows an organization to show its work. The audit trail should demonstrate which obligations were identified, what gaps were found, which controls were designed, and what actions were completed across the program. It also records activities, outcomes, and deliverables, helping establish that compliance work is deliberate, structured, and operational rather than an undocumented or one-time exercise.

Summary & Key Takeaways

  • A practical GDPR program follows five phases: assess the current state, identify gaps, design appropriate controls, transform the organization, and reach operational conformance. Each phase should produce documented activities, outcomes, and deliverables across people, processes, data, security, and privacy, with an audit trail demonstrating how obligations are being addressed.

  • High-priority readiness work includes appointing a data protection officer when appropriate, creating a cross-functional team, inventorying personal data, conducting a gap analysis, and developing a prioritized action plan. Organizations should also review privacy statements, consent and choice mechanisms, security practices, processing grounds, and procedures for exercising individual data rights.

  • Sustainable compliance depends on knowing what personal data exists and where it is stored. Organizations need secure processes to locate, access, correct, delete, or transfer an individual’s information within one month. Automation is critical because data is distributed across many locations, and a static spreadsheet cannot maintain an accurate inventory over time.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š