IBM Global Privacy Assessment · Creating a global privacy impact assessment process in Barclays 1....

12

Transcript of IBM Global Privacy Assessment · Creating a global privacy impact assessment process in Barclays 1....

Page 1: IBM Global Privacy Assessment · Creating a global privacy impact assessment process in Barclays 1. Why develop a single, global approach to privacy impact assessment? 2. The process
Page 2: IBM Global Privacy Assessment · Creating a global privacy impact assessment process in Barclays 1. Why develop a single, global approach to privacy impact assessment? 2. The process

IBM Global Privacy Assessment

1. IBM’s Global Privacy Assessment (GPA) - background

2. Considerations in designing the latest version of the GPA

3. The structure of GPA self assessment – 5 stage process

4. Designing & developing the GPA

5. Making it mandatory

6. What went well / further evolution

Page 3: IBM Global Privacy Assessment · Creating a global privacy impact assessment process in Barclays 1. Why develop a single, global approach to privacy impact assessment? 2. The process

5 stage self-assessment

Page 4: IBM Global Privacy Assessment · Creating a global privacy impact assessment process in Barclays 1. Why develop a single, global approach to privacy impact assessment? 2. The process

Visual progress / status

Page 5: IBM Global Privacy Assessment · Creating a global privacy impact assessment process in Barclays 1. Why develop a single, global approach to privacy impact assessment? 2. The process

Creating a global privacy impact assessment process in Barclays

1. Why develop a single, global approach to privacy impact

assessment?

2. The process of development - recognising different

business requirements and jurisdictional differences

3. The risk assessment process

4. Next steps – automation and fully global role out

Page 6: IBM Global Privacy Assessment · Creating a global privacy impact assessment process in Barclays 1. Why develop a single, global approach to privacy impact assessment? 2. The process

Barclays – screening questions

Page 7: IBM Global Privacy Assessment · Creating a global privacy impact assessment process in Barclays 1. Why develop a single, global approach to privacy impact assessment? 2. The process

Barclays – the assessment

Page 8: IBM Global Privacy Assessment · Creating a global privacy impact assessment process in Barclays 1. Why develop a single, global approach to privacy impact assessment? 2. The process

LexisNexis – two different approaches

• Risk Solutions: PIA for new product

• Legal: online compliance questions

Page 9: IBM Global Privacy Assessment · Creating a global privacy impact assessment process in Barclays 1. Why develop a single, global approach to privacy impact assessment? 2. The process

LexisNexis Risk Solutions small-scale local PIA process

What are the risks?

What are the solutions?

Privacy issue Individual risk Corporate risk Compliance risk (DPA)

Risk Solution(s) Risk eliminated, reduced or accepted Evaluation: is the final impact on

individuals after implementing

each solution a justified,

compliant and proportionate

response to the aims of the

project?

Page 10: IBM Global Privacy Assessment · Creating a global privacy impact assessment process in Barclays 1. Why develop a single, global approach to privacy impact assessment? 2. The process

LexisNexis Risk Solutions small-scale local PIA process

Sign off and record the outcomes

Integrate outcomes into action plan

Risk Approved solution Approved by

Action point Date for completion and progress Responsibility

Page 11: IBM Global Privacy Assessment · Creating a global privacy impact assessment process in Barclays 1. Why develop a single, global approach to privacy impact assessment? 2. The process

LexisNexis Legal online compliance questions

Page 12: IBM Global Privacy Assessment · Creating a global privacy impact assessment process in Barclays 1. Why develop a single, global approach to privacy impact assessment? 2. The process

Links and resources

• ICO PIA guidance: https://ico.org.uk/media/for-organisations/documents/1595/pia-code-of-practice.pdf

• NIST privacy harms: http://www.nist.gov/itl/csd/privacy-engineering-workshop-september-15-16-2014.cfm