In order to effectively implement the GDPR, a proven methodology is required.

07 grudnia 2017

The time for contemplating whether to implement the provisions of the European General Data Protection Regulation (GDPR) or how to approach it has long passed, especially in large organizations. In such entities, the implementation of GDPR requirements, provided they are well planned and supported by decisive actions (with backing from top management), will take from several months to a few years.

Personal Data Protection System Compliant with GDPR

Reading the provisions and the preamble of the regulation, even upon repeated readings, does not provide a clear recipe for building a personal data protection system. From the perspective of an entrepreneur, one concludes that the main message of this modern legal act is: data controller (entrepreneur, decision-maker), protect personal data as you see fit, but do so effectively, because if you fail to fulfill this obligation, we will be able to impose severe penalties on you.

Important
GDPR imposes little, rather it provides guidelines, which ensures that the provisions will not quickly become outdated or lose their flexibility. Even in a few years, they will be suitable for a dental office as well as a large telecommunications company. Additionally, GDPR requires entities to genuinely engage in creating a personal data protection system that is adequate to the threats and tailored to their own organizational structure.

However, at the outset of the implementation process, a significant challenge seems to be the fact that the legislator does not specify exactly what policies and procedures should be created and what safeguards should be implemented. This does not mean, however, that our current policies, instructions, and procedures are only fit for the trash. It is up to us whether we will use the existing personal data protection system in our organization as the foundation for the new one or build it from scratch.

GDPR, like a lighthouse, points us in the right directions. Processes, risks, accountability…

Processes

GDPR Bulletin
Receive a package of free GDPR guides and micro-training sessions
Join the ranks of our newsletter readers, receive a free package, and stay informed.
RECEIVE PACKAGE
GDPR states: data controller (entrepreneur/decision-maker), look at your organization through the lens of the purposes for which you process personal data. These include recruitment, employment, accounting, marketing, sales, debt collection. Other example purposes are: complaints, service, archiving and/or destruction of documents, monitoring, access control, etc.

The team of actions aimed at achieving specific business objectives constitutes a process of personal data processing. By identifying processes, one can assess the compliance of data processing with GDPR and, for example, check whether the scope of processed data is not too broad in relation to the purpose for which it is processed.

Risk

We have processes, and within them, personal data, sometimes a lot, often an overwhelming amount of personal data, including special categories of personal data (sensitive data). The GDPR requires us to view processes through the lens of Murphy's laws; let us conduct an exercise and assume that things will go "as badly as possible."

Imagine that our valuable information, including personal data, is destroyed, made public (leaked), likely causing media uproar, and consequently, a loss of our organization's good reputation… or (horrifyingly) it is stolen by competitors, or we expose ourselves to severe legal consequences. Let us consider whether these threats are real? How can we protect ourselves against them? Is it possible to minimize the risk? If so, how?

Accountability

To ensure accountability, and thus be able to demonstrate compliance with the provisions of the GDPR, it is not enough to adjust data processing policies and procedures. It is also necessary to maintain various records and registers, among which it is worth mentioning the records of processing activities, the register of personal data breaches, and the record of requests regarding the exercise of rights of data subjects. In short, in the event of any complaint alleging a violation of the GDPR by our organization, we must be prepared to prove its unfoundedness. In this regard, the most challenging task for the data controller is to demonstrate the implementation of such technical and organizational measures that ensure a level of security appropriate to the risk of infringement of the rights or freedoms of natural persons (data subjects). For this reason, at the center of the interest of an organization wishing to comply with the GDPR should be the Data Protection Impact Assessment (DPIA) and risk analysis.

According to the principle of accountability, the data controller should decide what safeguards and policies need to be created based on the aforementioned analyses.

The Most Difficult First Step

In theory, the GDPR can be implemented solely with the help of in-house employees. This seems plausible if we have a security or compliance department; however, in practice, this is rarely the case. An alternative is to seek support from external experts who can provide specialization in personal data protection, objectivity in risk assessment and security design, and deliver a proven methodology for implementing this complex legal act. The proper methodology will guide like a bobsled track - straight to the goal. However, this will only happen if the organization builds such a track. The consultant (advisory firm) will propose a concept and methodology for implementation, specific solutions, and tools; upon their acceptance, they will prepare plans, including a detailed implementation schedule. The organization, in turn, will adapt the plans and tools to its individual conditions and capabilities, approve them, and begin execution. The advisory firm supports with knowledge and experience, analyzes, plans, verifies, reports, colloquially speaking, leads by the hand, but the requirements of the GDPR are implemented by the organization itself through its employees – there is no other way.

Important
Today, choosing a professional and cost-effective partner is quite a challenge. Currently, there is a surge in companies offering services related to GDPR implementation. The scope of these services and their pricing differ so drastically that they cannot be compared. What should be the main criteria for selection? Real experience, interdisciplinary team, logical concept, proven methodology, scope of support during implementation, time of execution, tools for building staff awareness, possible support or takeover of supervision over the personal data protection system after implementation.

Do you also prefer prevention over treatment?

Establishment of the Implementation Team

Implementing the GDPR is a complex and multidimensional process that engages practically the entire organization and requires the establishment of a structure responsible for its execution.

Important
The implementation team and the implementation process must be under the supervision of top management (regardless of whether in a small or large organization); otherwise, it is not worth starting. Without meeting this condition, the implementation process, which lasts at least several months, is often doomed to failure.

Members of the implementation team should include representatives from key structures processing personal data (e.g., departments such as HR, customer service, marketing, service, debt collection, logistics, etc.). It is mandatory for the team to include individuals such as the information security administrator (if appointed) and a representative from the IT department. The selection of members for the implementation team will largely depend on the profile of the business and the organizational structure of the entity.

Opening Audit

It is necessary to create a detailed schedule for the implementation work, in which we will specify all tasks and deadlines for their completion. This cannot be achieved without properly determining the initial situation, which involves a sort of inventory of the available informational resources and the methods of their processing and protection. With this knowledge, we will be able to adapt (remodel) the applicable regulations to the new provisions and create any missing ones, thereby developing the existing data protection system.

The opening audit can be divided into two main areas: examining formal and legal requirements (the content of consent clauses, policies, procedures, data processing agreements, etc.) and examining the compliance of the IT area (the security of information systems and the functionalities of information systems in terms of the ability to fulfill the rights of data subjects, i.e., the right to data portability, the right to be forgotten, data protection by default, etc.). In the context of the organization and the actual conduct of the audit, I recommend referring to the guidelines contained in ISO standards (27001, 19011).

Important
Only after establishing the factual state will we see the "start and finish." An initial outline of the implementation process will emerge, and we will learn which stage will be the most labor-intensive or costly.

What to take on "first" and what can be postponed. For example, in some organizations, the biggest challenge will be adapting information systems, while in others, it will be adjusting data processing processes for marketing purposes.

DPIA, the foundation of the new personal data protection system

Conducting a Data Protection Impact Assessment (DPIA) is mandatory, among other things, for profiling, processing sensitive data on a large scale, or systematically monitoring publicly accessible places on a large scale. To determine whether conducting a DPIA is mandatory in our organization, one must ask whether a given type of processing operation is likely to result in a high risk to the rights or freedoms of natural persons.

Important
The DPIA analysis should include a description of the anticipated processing, an assessment of necessity and proportionality, measures taken to ensure compliance, an assessment of the risk of infringement of rights and freedoms, measures taken to mitigate the risk, documentation, and monitoring and review.

If the risk appears to be too high, and the data controller still wishes to process the data, they must consult with the supervisory authority (so-called prior consultations). It should be noted that DPIA analyses must be conducted before processing begins and reviewed regularly, and updated when the conditions and environment of processing change.

Data controllers should refer to available guidelines (WP248 guidelines from the Article 29 Working Party - the future European Data Protection Board - regarding Data Protection Impact Assessments and determining whether processing "is likely to result in a high risk") and good practices, such as the ISO 29134 standard.

Risk Analysis

Another challenge is to conduct a detailed risk analysis for the resources involved in personal data processing operations. In this regard, data controllers can refer to international ISO standards (27005, 31000).

Since the organization will decide what security measures to implement and what procedures to create based on the DPIA and the associated risk analysis, it should keep this analysis in documented form.

Risk Management Plan

Risk Analysis
When was the last time
you conducted a risk analysis?
Risk and DPIA are fundamental elements in building a data protection system.
ORDER A QUOTE
After conducting the DPIA and risk analysis, the conclusions should be transformed into tasks. Where security gaps have been identified, the tasks should involve recommendations for their remediation. In this regard, the GDPR is technologically neutral and obliges the data controller to independently determine what security measures will be effective. As an example, the legislator mentions pseudonymization, encryption, implementation of business continuity principles, and principles of monitoring and reviewing the personal data protection system.

Documentation and Adjustment of Business Processes

We should not "reinvent the wheel," as often existing procedures can serve as a good starting point for new regulations. In this regard, the GDPR is an evolution, not a revolution. The new provisions do not explicitly indicate which policies and procedures should be implemented; however, this will often arise directly from the content of the regulations. For example, to meet the requirement of reporting an incident to the Polish Data Protection Authority no later than 72 hours after detecting a breach, an internal incident reporting procedure to senior management must be established. It is also advisable for the organization to maintain documented information regarding the analysis of the necessity to appoint a Data Protection Officer (DPO). Additionally, documents such as backup creation policies, data deletion policies, and the implementation of the right to be forgotten, the right to data portability, privacy by design policies, and default privacy settings, as well as procedures for applying the principle of transparency, should be developed and implemented.

Important
It is also necessary to establish standards that must be met by contracts with external data processors acting on our behalf, for example, external accounting, marketing agencies, hosting companies, or providers of IT systems or services.

In summary, when starting the adaptation process (if possible), we should strive to incorporate the new requirements into the existing personal data protection system. For instance, when entering into data processing agreements based on current regulations, we can already include provisions required by the GDPR. We only need to indicate that the relevant contractual provisions will bind the parties from May 25, 2018. By taking such action, we can reduce the workload in the process of amending contracts.

Adjustment of IT Systems

Due to the relatively short time remaining until the application of the GDPR provisions, many organizations will face significant challenges in adjusting their IT systems. During the opening audit, IT systems used for processing personal data and their potential non-compliance with the new regulations are identified. As a result of the DPIA and risk analysis, a risk management plan is developed. Based on this, a plan for adjusting the IT environment is created.

Important
It can be confidently assumed that IT systems will require changes to enable the realization of new rights of individuals, namely, the right to data portability, the right to be forgotten, default privacy protection, data minimization, and the deletion of data that is unnecessary for the purpose of processing.

Additionally, there remains the issue of IT system security – it will be necessary to ensure that systems detect security breaches; for example, investments in event analysis systems, updates of operating systems of data processing devices, or technical and physical security measures in the processing area, particularly in server rooms, may be required.

Training

For the new personal data protection system to function effectively, a one-time implementation of tasks aimed at adapting the principles and security measures for personal data processing is insufficient. All employees and collaborators authorized to process personal data in our organization must be prepared to comply with the new regulations. Just like business processes, the personal data protection system cannot remain static. Therefore, when determining the scope and frequency of training, potential challenges that employees may face should be taken into account. Among these are questions about what data we can collect, how to secure it, when to delete it, and how to respond in the event of an incident…

When considering the frequency of training, it is important to take into account changing legal regulations, technological advancements, and the fact that one of the most important attributes of effective knowledge expansion is repetition. We propose that training for all employees and collaborators in the area of personal data protection be conducted at least once a year. The group of individuals subject to mandatory training should also include those who may process personal data, such as graphic designers, warehouse workers, or cleaning staff.

The accredited DPO course will confirm your high competencies

Closure Audit

The closure audit, which is the verification of adaptive actions, along with a detailed implementation schedule, is necessary because during the opening audit, the development of the DPIA, and the risk analysis, several hundred recommendations and associated tasks may arise. The closure audit verifies and assesses the extent of the implementation of the planned actions. It should be remembered that only the proper implementation of recommendations following the closure audit allows for compliance with the requirements of the GDPR.

Summary

In order to uphold the fundamental right of citizens to privacy and the protection of personal data, the EU legislator created the General Data Protection Regulation. To ensure that the new regulations function effectively, the possibility of imposing high financial penalties was provided. As is often the case, when someone gains, another loses. What is a right for citizens becomes an obligation and a cost for entrepreneurs. Adaptation efforts, particularly in large organizations, can prove to be costly. It can be assumed that for many of them, these will be unanticipated expenses in the budget. Aware of this, the legislator granted us (all EU member states) a two-year adjustment period. This period expires on May 25, 2018.

Although entrepreneurs often view the new regulations through the lens of unnecessary cost-generating bureaucracy, it should be noted that compliance with them, especially in the long term, will prove beneficial for them. Our experience indicates that despite the current regulations being in force (for over 20 years), the area of personal data protection and information security in many industries remains untapped. Thanks to the new regulations, including the real threat of substantial financial penalties, we will be compelled to implement systematic, thoughtful, and effective protection of what is most valuable to many organizations, namely the protection of information. Among the valuable resources of every organization, which is the information resource, there are personal data, and by protecting personal data, a kind of "protective umbrella" also extends over other information that constitutes, for example, financial, technological secrets, or the know-how of the enterprise.

Additionally, the possibility of obtaining a certificate confirming that personal data processing is compliant with the regulations will serve as evidence of the organization meeting high standards in this area. This, in turn, should translate into building trust among employees, clients, potential clients, and contractors, as well as help gain a competitive advantage.

Quoting the title of a film, I encourage you to take the bull by the horns: "Better late than never."

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.