SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR...

32
SIX STEP APPROACH TO GDPR COMPLIANCE

Transcript of SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR...

Page 1: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

SIX STEPAPPROACH

TO GDPRCOMPLIANCE

Page 2: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

Agile Solutions make your data work harder for you, across every area of your business. We help you to monetise it, leverage it, make better use of it – and derive more value from it. Once your data assets are beingmanaged effectively this will:

• Reduce the time needed to be spent on compliance, risk management• Reduce wasted costs from rework, failed mailing, enhanced customer experience• Improve profitability from trusted reporting and the enhanced ability to do bespoke analytics• Single version of the truth encourages collaboration across the organisation, prevents silo thinking. We are committed to providing our clients and partners with innovative data strategies, privacy, security and governance solutions, leveraging best of breed technologies that will derive the most business value from your data.

DATA IS THE NEW CURRENCY FOR MOST ORGANISATIONS AS MORE INFORMATION IS COLLECTED AND ANALYSED AT AN UNPRECEDENTED RATE.

Internal corporate governance, regulation and laws are demanding responsibility in protecting and securing sensitive data. Information and the systems that handle it are critical to the operation of virtually all organisations. Your company’s information and the knowledge based on it must be adequately protected regardless how it is handled, processed, transported or stored.

Page 3: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

4 Can GDPR be pain free?

6 How to approach GDPR readiness

8 What we offer

10 Preparing for success

11 Delivering success

12 Our Approach

14 Step 1 Assessment

15 Step 2 Planning

16 Step 3 Technology Architecture

17 Step 4 Delivery

18 Step 5 Legal Ratification

19 Step 6 Support

20 Case Study 1 UK Government Body GDPR Awareness Workshops

22 Case Study 2 Electrical and Telecommunications Retailer GDPR Consent and Notices Program Delivery

24 Case Study 3 Microsoft Talent Solutions Leader GDPR Review and Readiness Awareness

26 Case Study 4 Global Specialist Insurance Provider GDPR Awareness Workshops and Consultancy Support

28 Case Study 5 UK Government Body Supporting a GDPR Compliance Program

30 Data Governance Training Paths

31 Useful links and contact

CONTENTS

Page 4: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

CAN GDPR BE PAIN FREE?

Agile Solutions4

However, GDPR can be part of a strategy to become more data-driven as they require data governance across all areas: both business-led and IT-led.

This makes agile methodologies ideally suited to tackling GDPR. Identify where you are now and where you need to be on 25 May 2018. Then break it up into manageable steps.

GETTING READY FOR GDPR CAN FEEL OVERWHELMING.THE TEMPTATION TO BURY ONE’S HEAD IN THE SAND PROBABLY NEVER HAD SUCH APPEAL.

Page 5: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

Figure 1: Data Governance Domains

The advantages are:

• Even if you are already on your GDPR journey, you can apply agile methodologies to take stock and ensure you are on track to meet compliance.

• Agile methodologies allow you to change, adapt and evolve your Data management practices to meet your organisational needs.

• You can combine agile methodologies with other methods. If you’re using agile at the outset, you create a data governance framework and roadmap to follow. But to deliver you can switch to waterfall or hybrid.

• Agile is results-driven. By working in sprints, you see results fast. This helps ensure you get the full support of key stakeholders in your organisation and that your results meet best practice.

• You can scale an agile approach to focus on:

- a particular data governance issue (such as data quality)

- an entire organisation to develop an Enterprise approach, or

- a specific business, department or region

The success to any approach is to engage the key people.

A comprehensive Data Governance Framework encompasses all the following data governance domains (as identified by DAMA, Data Management Association International). We use the DAMA Governance model and the Gartner Maturity Model to analyse your data governance and data maturity. The principles of DAMA DMBOK provide a data quality assessment framework to use as a starting point to understand where you are on your data governance journey.

5Agile Solutions six step approach to GDPR compliance

DataGovernance

Strategy

DataSecurity

Management

MetadataManagement

DataDevelopment

Data Quality

Management

Data ArchitectureManagement

Data Warehousingand BusinessIntelligence

Development and Content Management

Data Operations

Management

Referenceand

Master Data Management

Page 6: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

HOW TO APPROACH GDPR READINESS We show you how to address GDPR

compliance within existing or planned business and IT projects as well as embedding it into new projects.

Compliance with GDPR has to be a cross functional initiative. It involves input from all parts of the organisation and requires investment in people, data and technology. There is no one widget or commercial-off-the-shelf (COTS) application you can purchase to become compliant, and if you were to request funding outside of BAU activities for a standalone GDPR program, the investment involved could be eye watering.

Your data governance framework has to have the ability to evolve and respond to changes in your organisation (specifically movement of key stakeholders and sponsors), development in technology (big data, cloud, IoT) and changes in your business model (e.g. new strategic initiatives, acquisitions, divestitures). Our pragmatic approach when developing a data management strategy focuses on the short to medium term priorities and plans accordingly.

We recommend a phased approach to implementation. This involves prioritising domains, process and technology to operationalise the data stewardship model. This needs to be accompanied by a strong change management plan to sustain your GDPR compliance program.

Agile Solutions6

FUNDAMENTALLY GDPR SIMPLY SEEKS TO ENFORCE RESPONSIBLE DATA MANAGEMENT PRACTICES.

Page 7: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

Figure 2: Example of evolving from tactical GDPR risk mitigations to a strategic data governance based toolset

An example of this approach is shown below:

7Agile Solutions six step approach to GDPR compliance

Personal Data

Consent

Privacy Model

Privacy Officers

Data Access

Data Breaches

Suppression

Data Profiling

Data Portability

People

Data Design

Technology

Level 1

InformalProcess

Level 2

EmergingProcess

Level 3

EngineeredProcess

Level 4

ControlledProcess

Level 5

OptimisedProcess

INFORMATION MANAGEMENT MATURITYAND GDPR

100%GDPR applies to all

companies worldwide that process personal data

of European Union (EU) citizens.

Page 8: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

WHAT WE OFFER

Agile Solutions8

SYSTEMS

•We assess the systems landscape

and document system owners

•We identify any significant IT projects that a data governance program could leverage

•We look at the escalation structure

for systems-related issues

•Where required for understanding,

we deep dive into the current systems associated with data management

DATA

•We identify the data to be governed

•We document the ownership

for each data set •

We document the administrators,stewards and end users of the data

•We seek to understand the nature and

utility of data (frequency of data transfer, rate of change, number of downstream

consumers, etc.)

1001

0001

1100

0101

To support you in your GDPR journey, we can hit the ground running by providing you with our proven templates and GDPR-enhanced Agile toolkit. These assets have been produced by our team to help many Tier 1 organisations implement robust and scalable Data Management practices over the last 16 years.

Page 9: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

9Agile Solutions six step approach to GDPR compliance

PEOPLE

•We identify key stakeholders

•We document the various roles in GDPR:

data controller, data processor, data steward, etc, and identify who currently occupies these roles

•We analyse whether the systems and

processes in place ensure people are carrying out their roles without unknowingly contravening GDPR

•We assess current and future

training requirements

PROCESSES

•We examine existing standard operating procedures (to determine to what extent documentation related to business rules

and data management rules exist)

•We seek to understand how

the business rule is formalised

•We document any best practice as a template for consolidation

of business rules

•We seek to understand business

processes driving data management

•For key data processes, we walk

through the Create, Read, Update, De-activate/Delete (CRUD) cycle

Page 10: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

For further information please download our AIM ebook

Agile Solutions10

PREPARING FOR SUCCESS THE AGILE INFORMATION MANAGEMENT (AIM) FRAMEWORK HAS BEEN DEVELOPED BY AGILE SOLUTIONS.

An innovative structured methodtowards achieving the goals of Business Agility through applying a strategic approach to data management solutions and services delivery.

The framework selectively overlays a number of proven management methods, system design techniques and technology types over a data centric architecture, design and delivery capability, in order to allow companies to evolve, capturing opportunities and reacting to market threats quickly.

44%incorrectly believe

GDPR will not apply to UK business

after Brexit

Page 11: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

11Agile Solutions six step approach to GDPR compliance

This means the data governance roadmap and strategy can be scaled in a numberof ways:

• focused to address a particular data governance issue (such as data quality)

• employed across an entire organisation to develop an Enterprise approach

• applied within a line of business, department or region

Multiple business and functional areas will be impacted by GDPR and early engagement with key stakeholders to solicit their input is vital.

Our initial exercise (in the form ofworkshops) with the program sponsors, focuses on the following objectives:

1. Prioritise data governance domains

2. Prioritise business areas

3. Prioritise data management processes

4. Prioritise systems landscape

Fundamental to this is to agree with our clients a backlog that forms a program of work that we can organise into sprint cycles.

Whether true agile or a hybrid or waterfall approach is used for the delivery of the program of work, agreeing priorities up front and setting limits on scope to avoid creep in delivery is key to success.

DELIVERING SUCCESS

EVERYTHING WE DO IS AGILE

Page 12: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

OUR APPROACH

Agile Solutions12

STEP1 STEP 2 STEP 3Assessment

- Stakeholder Awareness Workshops

- GDPR Readiness Assessment

- Data Maturity Assessment

- Backlog development

- Enterprise readiness assessment

- Remediation plan

How we help....How we help....How we help....

Expected outcomes...Expected outcomes...Expected outcomes...

Planning, Analysis & Design

- Detailed backlog development and programme plan

- Data flow prioritisation

- Critical path analysis

- Delivery approach definition

- Detailed projection plans

- Agile approach

- Resource schedule

- Budget preparation

TechnologyArchitecture

- Assessment of existing stack

- Recommendations for fit for purpose tooling

- Strategic technology selection

- Technology selection

- On-boarding plan

- Training plan

- Budget preparation

AIM Framework

SIX STEP GDPR JOURNEY

Page 13: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

13Agile Solutions six step approach to GDPR compliance

STEP 4 STEP 5 STEP 6

How we help.... How we help....

Expected outcomes... Expected outcomes...

Delivery

- Resource identification, scheduling and on-boarding

- Skills assessment

- Team construct development

- Delivery Assurance

- Resource plan

- Team leadership

- Agile delivery approach

- Regional Delivery Director Leadership

AIM Framework

Legal Ratification

To be completedby the client

ManagedServices and Support

- Definition of data governance / maturity standards

- Remediation of lesser priority data

- Support of change items

- Continuous data governance / improvement optimisation

- Data maturity progression

Page 14: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

Agile Solutions14

Step 1ASSESSMENT

AWARENESS, ANALYSISAND BACKLOG PLANNING ”

Rationale

Understanding the scope of GDPR.Bring awareness to senior stakeholders.Meets ICO Step 1 for GDPR Awareness.

Assess the organisation’s compliance position and readiness for GDPR.

Materialise and identify gaps in processes, data and technology. Understand the quality of data held within the organisation.

Position data governance methodology for risk mitigation and demo supporting technologies.

Deepen understanding of the risk(s)/data issue(s) and their impacts.

Identify the desired state agreed by all stakeholders.

Identify the tactical and strategic approach for risk mitigation.

Specify the mitigating activities.

Initial view of project backlog.

Scope

Awareness

Assessment

Planning, Analysis and Design

Page 15: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

15Agile Solutions six step approach to GDPR compliance

Step 2PLANNING

DETAILED BACKLOG DEVELOPMENTAND PROGRAMME PLAN ”

Rationale

Help key stakeholders to understand obligations, current position and risk profile with regards to GDPR and Data Governance.

Take Epics from the P.A.D. workshop, translate them into individual projects within JIRA and align as a programme of works.

Engage further with the next chain of business / technical stakeholders to bring awareness and catalyse action.

Ratify at a detailed level any assumptions made during the P.A.D. workshop or by the client plans to date.

Understand business processes to analyse and highlight key impacts in delivering the plan.

Understand system architecture and enterprise technology to analyse and highlight key impacts in delivering the plan.

Work with senior management, risk, compliance, IT and data security specialists to gain clarity on the regulation and be able to determine the scale and scope of their responsibilities in complying with GDPR.

Scope

Business Consultancy

Programme Management

Stakeholder Engagement

Planning & Assumption Ratification

Business Process Analysis

Impact Analysis

Interoperability Analysis for People, Process & Technology

Page 16: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

Step 3TECHNOLOGYARCHITECTURERECOMMENDING YOUR STRATEGICTECHNOLOGY SELECTION ”

Rationale

Review existing in-house technology / licenses, considering buy vs build / configure vs code to build a comprehensive understanding of the existing landscape.

Consider systems landscape, integration requirements and design high level solution architecture that is scalable and meets current and future requirements.

Consider market appraisal, commercial and licensing, perform tool comparison, analyse Analyst and Industry Benchmark reports.

Recognise the future vision, consider the programme and group operating model and make sure that the selected design meet the organisation’s strategic path.

Scope

Assessment of existing stack

Software and Infrastructure appraisal

Vendor identification and recommendation for fit for purpose tooling

Strategic technology selection

Agile Solutions16

Page 17: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

Step 4DELIVERY

AGILE INFORMATIONMANAGEMENT FRAMEWORK ”

Rationale

Matching people to an organisation’s required way of working. Offering the flexibility of our versatile, business-facing consultants to adapt to changing requirements and ensuring the project is delivered to the defined timescale and budget, to achieve the required business outcomes.

Evaluate the data and requirements to decide the best possible design for data repositories, logical and physical data models, to enable the best, solid base for development.

Build dev, test, pre-prod and production environments to define a smooth delivery pipeline that can shorten release cycle, enabling changes to be deployed more rapidly so that end users realise the benefit sooner.

Define and build system access model, application rules, workflow, user interface, integration and migration based on design using agile methodology to deliver greatest customer value in the shortest possible time.

Scope

Resource identification, scheduling and on-boarding, Team construct

Design Repository and Data model

Commission Environment

Integration and Configuration

17Agile Solutions six step approach to GDPR compliance

Page 18: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

Step 5LEGALRATIFICATIONCLIENT TO COMPLETETHIS STEP INDEPENDENTLY ”

Rationale

We have expertise in all areas of the development cycle from gathering requirements to delivery and support — but we are not lawyers and cannot help with legal ratification.

Scope

To be completed by the Client

Agile Solutions18

Page 19: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

Step 6SUPPORT

CONTINUOUS DATA GOVERNANCE,OPTISATION AND IMPROVEMENT ”

Rationale

Deliver program marketing and messaging to drive adoption. Provide Standard Operating Procedures / work instructions / user guides and all training materials as per requirement to ensure a smooth running and delivery.

Provide governance framework, change management planning, change request process, review and approval to enable absorbing higher rates of change to systems whilst maintaining IT service quality through a unified, well understood and controlled release process.

Author support documentation, undertake defect analysis and remediation to ensure product usability and stability.

Provide required support services with service level agreement to derive customer satisfaction, quality improvement and process efficiency.

Scope

Communication and User Training

Change Management Process

Maintenance and Support

Helpdesk Services

19Agile Solutions six step approach to GDPR compliance

Page 20: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

ClientOfficial UK government body responsible for Intellectual Property (IP) rights including Patents, Trade Marks, Designs and Copyright.

HighlightsOur consultants ran an initial series of workshops to raise the awareness of the EU GDPR, targeting senior managers and staff involved directly in Data Management and Information Security roles. Directorate specific workshops were then held, focused on the Article 30 requirement for creation of a Record of Processing - providing a technique to follow to complete this across the organisation.

PROBLEM

• The client needed to understand which activities are required as part of preparation for the enforcement of the EU GDPR on 25th of May 2018.

• The Board would like to take a risk based compliance approach, but also wants to be seen as a leader within its division of Government.

• The Information Commissioner’s Office (ICO) in the UK has issued guidance to companies to help them to assess their ability to comply with the new legislation, but this is open to interpretation.

• IT would like the Record of Processing to serve a wider purpose as a strategic Business Process Map asset, as part of the Enterprise Architecture design.

GDPR AWARNESS WORKSHOPS

Agile Solutions20

CASE STUDYUK GOVERNMENT BODY

Page 21: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

SOLUTION

• Agile Solutions consultants ran an initial series of workshops to raise the awareness of the EU GDPR, targeting key stakeholders.

• Directorate specific workshops focused on the Article 30 requirement for creation of a Record of Processing targeting:

- Creating at least one Record of Processing for each functional area

- Identifying all the in-scope processes that need to be mapped

- Showing how a Record of Processing can be used to identify more general areas of concern with respect to data governance

- Compliance gaps were captured in the format of a risk, which we helped the client prioritise to inform their compliance roadmap

BENEFIT

• By running awareness workshops the first step of the GDPR journey has been completed: staff have had training in the new regulation.

• Focused workshops provided a technique for the participants enabling them to perform further analysis on their internal processes, identifying areas of concern and high risk.

• A complete list of in-scope processes has been identified, helping towards forming a project plan for creating the Enterprise wide Record of Processing.

• Using a BPM approach to identify requirements and to document the Record of Processing was endorsed by IT as the strategic way forward.

Agile Solutions six step approach to GDPR compliance 21

Page 22: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

Agile Solutions22

Client

Europe’s leading specialist electrical and telecommunications retailer and services company, employing over 40,000 people and operating in 9 countries.

Highlights

Agile Solutions provided an IT GDPR Programme Manager to lead the technical planning and analysis phase of the GDPR Consents & Notices Solution on behalf the IT Transformation Team.

PROBLEM

• The introduction of the EU General Data Protection Regulation places further compliance requirements on our client’s retail operations including the Single Customer View (SCV) programme.

• The Consent & Notices framework requires subsequent data model changes in the SCV to capture consent on customer facing applications. The solution requires proliferation of GDPR compliant consent to the relevant campaign management capabilities.

• Limited funding and awareness of the strategic solution required (for e.g. Master Data Management) meant solution constraints around the ability to deliver Customer Preference Centre capability.

GDPR CONSENT AND NOTICES PROGRAM DELIVERY

CASE STUDYELECTRICAL AND TELECOMMUNICATIONS RETAILER

Page 23: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

Agile Solutions six step approach to GDPR compliance 23

SOLUTION

• Agile Solutions provided a Principal Data Governance consultant, onsite, to support the GDPR Technical Planning & Analysis.

• Agile’s SME input to the Consent & Notice management solution.

• We facilitated workshops with relevant key stakeholders, and multiple System Integrators, to identify the scale of change needed and to validate estimates for delivery.

• The following Consents & Notices artefacts were produced:

- Solution Blueprint & High Level Design

- Data Architecture

- Integration Design

• The resource model and roles were designed for IT GDPR delivery.

BENEFIT

• Helped identify the technology and capability requirements required to sustain a GDPR compliant Consent & Notices solution and understand the impact on the existing SCV master data management program.

• Increased the level of engagement of stakeholders with the Enterprise Architecture function, expanded to Data Management and Campaign Management Teams.

• Delivered a time boxed technical planning and analysis programme phase to time and within the available budget.

• Provided coordination between IT, Enterprise Architecture, Business Change, Data Management and Campaign Management functional areas.

Page 24: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

ClientA leader in Microsoft talent solutions for the intelligent cloud and intelligent edge; Since 2014, the UK ‘Smart Team Freelance Partner’ for Microsoft Consulting Services (MCS) and a trusted provider of expertise, research and Microsoft technology training services.

HighlightsAgile Solutions Consultants conducted an initial review of the GDPR compliance steps undertaken by the client, assessed against the recommended 12 steps advocated by the UK Information Commissioners Office (ICO). Advice in respect to best practice for the management of personal data was provided, alongside recommended activities to address identified gaps and where to seek specific guidance from the Recruitment & Employment Confederation (REC) as to how derogations provided for the UK Data Protection Bill will apply across the recruitment industry.

PROBLEM

• The client required validation of GDPR compliance steps undertaken to date, which were informed by the recommended 12 steps advocated by the UK Information Commissioners Office (ICO).

• The Recruitment & Employment Confederation (REC) are working to issue guidance to the recruitment industry to help with GDPR compliance but the UK Data Protection Bill (providing for specific derogations relating to employment) has not been finalised.

• The client had appointed a DPO who had created the policies, privacy notices and internal procedures to support GDPR compliance, but wanted external assurance that these were necessary and appropriate.

CASE STUDYMICROSOFT TALENT SOLUTIONS LEADER

Agile Solutions24

GDPR REVIEWAND READINESSAWARNESS

Page 25: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

SOLUTION

• Agile Solutions Consultants conducted an initial review of the GDPR compliance steps undertaken by the client, as a deep-dive.

• Best practice for the management of personal data was provided for: Need to appoint a DPO

- Working with and guidance from REC

- Requirement for a Record of Processing

- Data Processing agreements

- GDPR for internal HR processes

- Adequacy concerns in respect of data processing in India

- Documentation requirements and review of policies, procedures, training materials and notification and reporting processes

- Configuration of the candidate database

BENEFIT

• The GDPR Review and Readiness Assessment report has allowed the COO and CMO to have confidence that the activities required for compliance have been correctly interpreted and are well understood by the leadership, allowing them to focus on embedding the new and updated processes into business as usual.

• The client is now actively engaged with REC and well prepared for May 2018.

• A detailed analysis of roles and permissions in the candidate management database, system settings, physical security and ability to configure views and workflow is planned for the candidate management system – the primary data store containing personal and sensitive data.

Agile Solutions six step approach to GDPR compliance 25

Page 26: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

ClientGlobal specialty Insurance provider, whose core business encompasses one of the largest property and casualty insurance groups in the Japanese domestic market. Through its operating subsidiaries, writes agriculture, professional lines, property, marine and energy, catastrophe and casualty and other specialty lines of insurance and reinsurance, trading in the London Market.

HighlightsOur consultants ran 3 workshops to raise the awareness of the EU General Data Protection Regulation, targeting senior managers and staff involved directly in Data Management and Information Security roles. We further profiled 11 datasets in 3 days, highlighting potential hot spots relating to GDPR and identifying issues with poor data quality. This assessment activity was completed as part of the overall GDPR compliance program.

PROBLEM

• The client required validation of an initial GDPR compliance plan drafted by their appointed project manager – who also required support to understand which areas of their business and data capture presented potential GDPR risks.

• The overall quality of the data is not understood and the client doesn’t have any experience with data profiling technologies.

• The LMA (Lloyd’s Market Association) and ABI (Association for British Insurers) are lobbying and working to issue guidance to the insurance industry to help with GDPR compliance, but this was not ready.

• Very few of the employees were aware of data privacy and data protection or the effect of GDPR on their business.

Agile Solutions26

GDPR AWARENESS WORKSHOPS AND CONSULTANCY SUPPORT

CASE STUDYGLOBAL SPECIALITY INSURANCE PROVIDER

Page 27: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

SOLUTION

• Agile Solutions ran 3 awareness workshops for different functional areas to increase staff awareness of the GDPR changes.

• Agile Solutions Data Analysts carried out a data profiling exercise on multiple datasets, provided by the client, during 3 days, onsite. The database tables contained vast volumes of records – up to 360 columns.

• Data Profiling provided statistics and metadata relating to the data, supporting analysis and creation of a summary report.

• Our GDPR consultants reviewed the draft project plan and analysis completed to date, updating actions based on findings from the workshops and profiling, creating a risk register and injecting a data governance best practice based approach.

BENEFIT

• The client gained valuable insight into their data, to help them assess their GDPR risk and identify mitigations and staff were able to inform the project lead of high risk processes and compliance concern.

• The high level GDPR gap analysis report provided was included in the project plan.

• Recommendations for tracking and reporting progress were provided to the GDPR project manager.

• The client is now actively engaged with the LMA GDPR working group and well prepared for May 2018.

• Agile Solutions helped identify a possible technology and capability required to support the need for business-as-usual data quality management and governance.

Agile Solutions six step approach to GDPR compliance 27

Page 28: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

ClientOfficial UK government body responsible for planning appeals, national infrastructure planning applications, examinations of local plans and other planning-related and specialist casework in England and Wales.

HighlightsOur specialist GDPR consultants, working alongside the client’s project manager, created a strategic approach for GDPR compliance, sustained through a data governance organisation. A project board review process was instigated and key decisions brought to that forum for resolution. Agile Solutions also ran GDPR awareness sessions for key stakeholders, authored the Record of Processing and provided advice, guidance and resourcing across all aspects of the GDPR program.

PROBLEM

• The client is not accustomed to heavy regulation and needed assistance in:

- Direction - Scoping - Project set up - Resourcing

• Limited expert knowledge of GDPR in-house

• A formal control function existed but the remit is narrow, with limited resources for controls

• The organisational structure is siloed in nature

• Paper heavy processes and lack of process discipline between the departments have led to lack of controls

• Tight budgets have meant a minimum investment in technology to assist users, resulting in mainly manual process controls

SUPPORTING A GDPRCOMPLIANCE PROGRAM

Agile Solutions28

CASE STUDYUK GOVERNMENT BODY

Page 29: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

SOLUTION

• Agile Solutions provided specialist GDPR consulting resources to assist with benchmarking the current state and to perform a gap analysis against requirements to the needed state for compliance

• Scoped and set up project management processes:

- GDPR project plan and risk register - Escalation paths - Board meetings

• Delivered general awareness and tailored training to key stakeholders

• Provided a structure for completion of the Record of processing across the organisation

• Offered advice and potential solutions to process inefficiencies and control gaps.

• Provided end to end project support

BENEFIT

• Through the collaborative approach, taken with the project manager, we have raised GDPR awareness across the organisation

• The client is able to tackle GDPR in a pragmatic fashion, focussed on high risk areas

• Expertise provided by Agile Solutions allowed accelerated progress of the program

• The organisation will be able to demonstrate compliance to GDPR

• Raised awareness of organisational inefficiencies that can be addressed as part of their upcoming transformation program

• The Project manager has been able to complete tasks that would have been impossible without the added resourcing

• Board level awareness of control gaps and planning for immediate and long term action.

Agile Solutions six step approach to GDPR compliance 29

Page 30: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

Agile Solutions30

DATA GOVERNANCETRAINING PATHS

MANAGE YOUR DATA HOLISTICALLY ACROSS THE ORGANISATIONAL, ARCHITECTURAL, AND POLITICAL SILOS IN YOUR COMPANY RECOMMENDED TRAINING, THAT WILL ALLOW A USER TO DEVELOP A SPECIFIC SKILLSET AND KNOWLEDGE AS IT RELATES TO AN INFORMATICA PRODUCT OR SOLUTION

To find out more about Agile Solutions training, [email protected]

DataSteward

Informatica Analyst

Data Discovery and Advanced Profiling

Metadata Manager

BusinessGlossary

Informatica DataGovernance, Specialist

Data QualityAnalyst

Informatica Analyst

Data Discovery and Advanced Profiling

Informatica Analyst,Specialist (Coming Soon)

Page 31: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled

USEFUL LINKS AND CONTACTS

THE INFORMATION COMMISSIONER’S OFFICE IS THE UK’S INDEPENDENT AUTHORITY SET UP TO UPHOLD INFORMATION RIGHTS IN THE PUBLIC INTEREST, PROMOTING OPENNESS BY PUBLIC BODIES AND DATA PRIVACY FOR INDIVIDUALS.

ICO: Information Commissioner’s Officewww.ico.org.uk

To find out more about Agile Solutions and our approach to making GDPR a positive experience, get in touch.

Agile Solutions GB Ltd454 Midsummer BlvdMilton KeynesMK9 2EA

0203 587 7831

[email protected]

www.agilesolutions.co.uk

Agile Solutions six step approach to GDPR compliance 31

Page 32: SIX STEP APPROACH TO GDPR COMPLIANCE - Agile Solutions · Agile Solutions six step approach to GDPR compliance 11 This means the data governance roadmap and strategy can be scaled