{"id":4398,"date":"2017-02-06T16:33:02","date_gmt":"2017-02-06T16:33:02","guid":{"rendered":"http:\/\/www.chaordicsolutions.co.uk\/blog\/?p=4398"},"modified":"2017-02-07T12:09:50","modified_gmt":"2017-02-07T12:09:50","slug":"now-that-the-fog-is-clearing-on-gdpr-its-time-to-speed-things-up","status":"publish","type":"post","link":"https:\/\/www.chaordicsolutions.co.uk\/blog\/gdpr\/now-that-the-fog-is-clearing-on-gdpr-its-time-to-speed-things-up\/","title":{"rendered":"Now that the fog is clearing on GDPR, it\u2019s time to speed things up"},"content":{"rendered":"<p><a href=\"http:\/\/www.chaordicsolutions.co.uk\/blog\/news\/benefit-from-quick-access-to-world-class-management-consultancy-expertise-as-and-when-you-need-it\/attachment\/image-1-option-3-small\/\" rel=\"attachment wp-att-3251\"><img loading=\"lazy\" class=\"alignleft size-full wp-image-3251\" src=\"http:\/\/www.chaordicsolutions.co.uk\/blog\/wp-content\/uploads\/2013\/07\/image-1-option-3-small.jpg\" alt=\"\" width=\"97\" height=\"64\" \/><\/a>When did you first hear about the\u00a0General Data Protection Regulation (GDPR) legislation and the need to comply with it by May 2018?<\/p>\n<p>&nbsp;<\/p>\n<p><!--more-->Was it recently or possibly many months ago, when the legislation was <a href=\"http:\/\/europa.eu\/rapid\/press-release_STATEMENT-16-1403_en.htm\"><u>formally adopted<\/u><\/a> by the European Parliament in April 2016? On the other hand, GDPR compliance activities might have been on your organisation&#8217;s radar even earlier than that.<\/p>\n<p>There is a good chance you have\u00a0already heard something about GDPR although\u00a0maybe you have become overwhelmed with it all, hoping that the inconvenience of having to comply\u00a0would conveniently and quietly go away.<\/p>\n<p>But then\u00a0you might\u00a0be reading this article as someone who is working for one of the few organisations that have already started their GDPR implementation activities and are on track to achieving compliance by May 2018.<\/p>\n<p>It is now clear that the legal requirement for your organisation to comply with GDPR is not going to go away and\u00a0the associated end date is not going to\u00a0change either.<\/p>\n<p>If you have still not started your implementation activities yet, the risk of non-compliance is therefore significantly increasing for your organisation and its investors.<\/p>\n<p><strong>Opportunities<\/strong><\/p>\n<p>GDPR is not something to fear.<\/p>\n<p>It presents many\u00a0opportunities to add value to and protect your business, provided you open your mind to the important point that it\u00a0<strong>is not just another piece of technical compliance work<\/strong> you give to your IT people,\u00a0as discussed in an <a href=\"https:\/\/www.linkedin.com\/pulse\/article\/12-reasons-gdpr-impact-whole-your-business-just-robert-j-toogood\"><u>earlier post<\/u><\/a>&#8230;\u00a0it is a fundamental change to the way we handle data within our organisations.<\/p>\n<p>We must also remember that this is the first major revision of data protection and privacy legislation for over twenty years so, if properly implemented, will present many opportunities for better protecting both individuals and organisations in our ever-increasing digital and interconnected world.<\/p>\n<p>As the UK Information Commissioner, Elizabeth Denham, emphasised in a <a href=\"https:\/\/ico.org.uk\/about-the-ico\/news-and-events\/news-and-blogs\/2017\/01\/information-commissioner-talks-gdpr-and-accountability-in-latest-speech\/\"><u>recent speech<\/u><\/a>, accountability is a key change under GDPR. She went onto to add \u201cIt\u2019s about <strong>moving away from seeing the law as a box ticking exercise<\/strong>, and instead to work on a framework that can be used to build a culture of privacy that pervades an entire organisation.\u201d<\/p>\n<p><strong>Approach<\/strong><\/p>\n<p>If you haven\u2019t done so already, the time has now come to face into reality and accept the <a href=\"https:\/\/iapp.org\/resources\/article\/top-10-operational-impacts-of-the-gdpr\/\"><u>complexity<\/u><\/a> of what is needed within your organisation to comply with this incredibly challenging but exciting piece of legislation<\/p>\n<p>The complexity needs to be managed with care since the implications of non-compliance by May 2018 are significant with those accountable in the boardroom in scope for potential criminal prosecution, as well as the already widely publicised potential\u00a04% of turnover fine and associated reputational damage.<\/p>\n<p>However, it is still not clear that this accountability is truly understood by many boards\u2026 as reflected by the number of GDPR programmes that have still yet to start or are woefully underfunded.<\/p>\n<p>So what is needed?<\/p>\n<p>The first step is to <strong>setup up a programme\u2026<\/strong> on an enterprise-wide basis to manage your implementation activities, with strong boardroom sponsorship involving all key stakeholder groups within your organisation.<\/p>\n<p>The second step is to <strong>structure your programme<\/strong>\u2026 by deciding whether to use an already implemented methodology or by selecting a more appropriate one to help direct your critical privacy related activities.<\/p>\n<p>The third step to then <strong>tailor your selected methodology<\/strong>\u2026 to reflect the realities of the organisational environment in which it is being used, and to integrate any associated privacy related frameworks and <a href=\"https:\/\/www.linkedin.com\/pulse\/2017-watershed-year-deployment-data-inventory-mapping-toogood?\"><u>supporting tools<\/u><\/a> which\u00a0are also needed for your organisation.<\/p>\n<p>The fourth step is to <strong>plan your programme\u2026<\/strong> involving all key stakeholders and the way in which you have decided to organise your programme activities.<\/p>\n<p>The fifth step is to <strong>launch your programme and support it<\/strong> with an appropriate level of resource (and funding) given the challenges that the programme faces within your organisation.<\/p>\n<p><strong>Challenges<\/strong><\/p>\n<p>The challenges each organisation will face will be unique, reflecting a rich and varied mix of different factors including:<\/p>\n<ul>\n<li>gaps with existing legislation;<\/li>\n<li>existing and planned system landscape;<\/li>\n<li>technical infrastructure;<\/li>\n<li>implemented methodologies, frameworks\u00a0and standards;<\/li>\n<li>sector regulatory requirements;<\/li>\n<li>governance, risk and compliance maturity;<\/li>\n<li>external certifications.<\/li>\n<\/ul>\n<p>A further\u00a0requirements for achieving GDPR compliance is to adopt a <a href=\"https:\/\/iapp.org\/resources\/article\/the-risk-based-approach-in-the-gdpr-interpretation-and-implications\/\"><u>risk based approach<\/u><\/a>. This is actively encouraged by the legislation but requires other things to be in place for this to work effectively.\u00a0 What is best for your organisation will depend on many factors.<\/p>\n<p><strong>Next Steps<\/strong><\/p>\n<p>What does of all this mean for you?<\/p>\n<p>It means that it is important to include within your GDPR programme people who have the depth and breadth of expertise, both within IT and the business, that can work across the total organisation, building bridges if required between different functional groups and siloes that haven\u2019t traditionally work together.<\/p>\n<p>These people need to be able to see the bigger picture of what is needed based on their\u00a0experiences in the real-world dealing with similar project, systems and risk challenges.\u00a0 They need to understand and simplify complexity,\u00a0addressing the inevitable\u00a0ambiguity that will be present amongst these implementation activities\u2026 <strong>helping you connect the proverbial dots<\/strong> to ensure you meet your legal obligations in the most appropriate and efficient way for your organisation.<\/p>\n<p>In the final analysis, it is people who\u00a0will determine whether a GDPR implementation is successful or not.<\/p>\n<p>Only by recognising this fundamental point, will an organisation move beyond GDPR as a box ticking compliance activity to something that will really add value to the organisation by changing its data culture, enabling it to more effectively compete in the new and exciting digital age.<\/p>\n<p>Where are you on your GDPR implementation journey?<\/p>\n<p><em>To discuss\u00a0these challenges further and their relevance to your own organisation, please contact Robert direct at robert.toogood@data-tight.com to schedule a completely confidential and no-obligation discussion<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>When did you first hear about the\u00a0General Data Protection Regulation (GDPR) legislation and the need to comply with it by May 2018? &nbsp;<\/p>\n","protected":false},"author":1,"featured_media":3251,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[354],"tags":[343,342,320,161,360,286,288,291,292,290,289,293,294,295,296,297,200,201,202,203,204,205,206,207,299,361,356,355,347,348,333,345,346,83,208,209,86,84,85,285,114,115,340,339,338,269,270,29,210,211,27,28,30,116,117,312,337,323,314,92,298,322,326,328,325,327,319,321,318,324,139,142,138,141,180,316,334,137,140,275,276,277,282,280,281,251,278,279,36,170,183,39,37,38,101,102,335,310,332,249,250,315,283,284,301,329],"_links":{"self":[{"href":"https:\/\/www.chaordicsolutions.co.uk\/blog\/wp-json\/wp\/v2\/posts\/4398"}],"collection":[{"href":"https:\/\/www.chaordicsolutions.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.chaordicsolutions.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.chaordicsolutions.co.uk\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.chaordicsolutions.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=4398"}],"version-history":[{"count":5,"href":"https:\/\/www.chaordicsolutions.co.uk\/blog\/wp-json\/wp\/v2\/posts\/4398\/revisions"}],"predecessor-version":[{"id":4405,"href":"https:\/\/www.chaordicsolutions.co.uk\/blog\/wp-json\/wp\/v2\/posts\/4398\/revisions\/4405"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.chaordicsolutions.co.uk\/blog\/wp-json\/wp\/v2\/media\/3251"}],"wp:attachment":[{"href":"https:\/\/www.chaordicsolutions.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=4398"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.chaordicsolutions.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=4398"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.chaordicsolutions.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=4398"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}