No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
    • On-Demand Webinars: Earn CEUs
  • Subscribe
  • Home
  • About
    • About CCI
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
    • On-Demand Webinars: Earn CEUs
  • Subscribe
No Result
View All Result
Corporate Compliance Insights
Home Data Privacy

Why a Structured Program Is the Only Way to Reach Your Data Privacy Potential

An effective data policy considers current regulatory regimes but doesn’t forget about the future

by Rachael Ormiston
July 10, 2023
in Data Privacy
data privacy cameras watching

In recent years, more companies have realized the importance of data privacy, and roles related to data protection have evolved from part-time gigs into full-time jobs. Though everyone organization-wide should prioritize data privacy, the responsibility of developing and maintaining a privacy program falls on your privacy lead and the rest of your privacy team. Osano’s Rachael Ormiston talks about what the smartest organizations have in common: They’ve implemented a strong and structured data privacy program that’s agile enough to evolve within the ever-changing data privacy landscape.

An organization’s privacy goals should revolve around protecting personal data. In some places, such as the EU and California (and a growing number of other U.S. states), legislation cements this goal as law; however, even if your region hasn’t passed data privacy legislation, you should still take every measure to protect customer data.

Data privacy isn’t just the compliant thing to do, it’s also popular — 85% of adults worldwide want to do more to protect their online privacy. In an increasingly digital-first world, people’s awareness of the risks of sharing personal data online has increased, and with awareness comes concern. Two-thirds of surveyed adults from around the world think tech companies have too much control over their data. And they’re not wrong to be worried. 2022 had the second-highest number of data breaches on record (1,802), impacting more than 422 million victims. The average data breach cost over $4.3 million in 2022. Implementing robust privacy policies protects your customers, reputation and bottom line.

Good privacy practices benefit your organization in other ways, too. According to a Cisco survey, over half of the respondents reported $1 million or more in benefits from investing in data privacy over the last year, including:

  • Fewer data breaches
  • Reduced reputational damage
  • Avoidance of noncompliance fines
  • Increased customer confidence

Robust data privacy can help keep your organization’s reputation untarnished and your online reviews positive. If 60% of consumers say negative reviews deter them from using an organization’s services, safeguarding data and remaining compliant can help garner good online reviews. Good reviews can also drive new customer acquisition, as 85% of consumers trust online reviews as much as personal recommendations.

minidata_b
Compliance

Honey, I Shrunk the Data: How to Keep Customer Info on a Need-to-Know Basis

by Parker Poe
November 30, 2022

It may be tempting to hoard the data you have gathered on your customers, but an increasing number of regulations and laws require businesses to do just the opposite. Sarah Hutchins and Robert Botkin from Parker Poe are here to tell you why that’s good news.

Read more

How to build a privacy program

If you’re starting from scratch, implementing a privacy program may seem intimidating. Use these basic steps to guide your strategy development.

Identify what drives your privacy program

Do you want to build trust with your customers or avoid a data breach? Being compliant with applicable laws is another critical driver. Organizations must understand what rules and regulations apply to them based on their location and number of customers. Research these drivers and consider their effects on your privacy program.

Construct a formal strategy

Even if you don’t have all the answers at this stage, the success of your program depends on determining the direction of your program, especially since organizations with robust data privacy practices are about half as likely to experience a data breach as those without.

Use your formal strategy to attract buy-in

When everyone organization-wide understands and accepts the importance of implementing a privacy program, you’ll improve the likelihood of success. In fact, organizations with full support of privacy and security initiatives increase that success by up to 39% versus organizations with weak support. By getting buy-in, and conveying those drivers (Step 1), you can find ways to embed privacy into organizational strategies.

Find and consolidate disparate data

Unearth all your data spread across your organization or stored in different silos. Conduct a record of processing activities (RoPA) to classify and record pertinent information.

Execute a privacy risk assessment

These assessments determine your vulnerable areas and establish fixes for the weak spots. When assessing, take a hard look at your third-party vendors and their privacy policies to ensure their standards meet your criteria.

Define your goals and execution plan to identify next steps

Since you’ll have multiple goals, prioritize them based on your organization’s gaps and any applicable laws. Take time now to create or update your privacy policy to reflect your organization’s big-picture data processing procedure.

Utilize technology to support policy

Implement and utilize  technical and organizational measures to protect personal data, including:

  • Encryption
  • Access controls
  • Consent management
  • Vendor onboarding processes
  • Incident response plans
  • Training the workforce in privacy and cyber awareness

Measure and monitor

Calculate your success by measuring and monitoring value-affirming data privacy metrics like:

  • Vendor onboarding time
  • Number of privacy rights exercised and response time SLAs
  •  How many risk assessments conducted
  • How many audits performed
  • Vendor review status and score
  • Influence on projects
  •  Influence on deals

Maintain and manage your program

As data privacy regulations and your organization evolve, your program must, too. New data processes may require evaluations like a data protection impact assessment (DPIA). This risk assessment audit helps organizations identify, analyze and minimize privacy risks associated with collecting, processing, using, storing and sharing user data necessary to comply with many privacy regulations like the GDPR and CCPA.

Mind the gaps

Once your data privacy program launches, there are some suggested next steps to keep it optimized. Here’s how to tighten some common gaps:

  • Data mapping: Prioritize data mapping to ensure you keep accurate records of your systems. Know who has access to the data and its storage location.
  • Device management: Secure devices via data encryption, anti-malware software and strong passwords.
  • Application development: Implement secure procedures for personal data starting in the development stage.
  • Breach notifications: Create protocols for handling breaches.
  • Privacy policies: Craft clear and accessible policies for all individuals sharing their data with you. Your team should regularly review these policies to ensure they meet regulatory requirements.
  • Security testing: Annually test your systems’ vulnerabilities and potential penetration points to determine the level of data security.  Run these tests whenever a major organizational change occurs, too.
  • Employee training: Hold (at least) yearly employee training sessions to share updates about privacy laws and refresh the privacy procedures they must follow.
  • Documentation: Champion accountability by implementing a process documenting each time someone handles an individual’s data.
  • Continuous monitoring: Leverage continuous monitoring for instant alerts about any risks or gaps in your processes requiring your attention.
  • Personal information retention and destruction: Implement policies specifying the storage and disposal of personal information.

Consider using a privacy maturity model to measure your level of success with each tenet of your privacy solutions. A privacy maturity model is a framework that helps organizations evaluate their status in specific areas of their privacy solutions, usually on a scale of 1 (immature) to 5 (optimized). A privacy maturity model offers a guide for ensuring an organization’s active, continuous compliance.

To grow in the continuously-evolving privacy environment requires companies to remain agile and honest about their privacy policies. Companies can maximize their data privacy potential by developing a robust and resilient privacy program that includes a privacy maturity model to continuously identify and remedy privacy gaps.


Tags: Data Governance
Previous Post

To Drive Due Diligence and Compliance, Don’t Overburden Your Suppliers

Next Post

Would Alito’s Defense Prevail Under the FCPA?

Rachael Ormiston

Rachael Ormiston

Rachael Ormiston is the head of privacy at Osano. With more than 15 years of professional experience, she has deep domain expertise in global privacy, cybersecurity, and crisis and incident response. Rachael is an IAPP FIP and has previously served on the IAPP CIPM exam development board. She has a personal interest in privacy risk issues associated with emerging technologies.

Related Posts

ceo speaking concept

Why Data Privacy and Cybersecurity Must Be at the Top of CEOs’ Communications Agendas

by FTI Consulting
September 26, 2023

The scope of a CEO’s job is wide, to be sure, but as data privacy and cybersecurity continue to come...

wall of filing cabinets holding private information

Wave of State Data Protection Laws Is a Gathering Compliance Nightmare

by Scott Allendevaux
September 26, 2023

In absence of a single national data privacy law, companies continue to face a multi-state balancing act. Data privacy practitioner...

people on train looking at phones

Analysis: Big Tech Falling Short on Consumers’ Digital Rights

by Staff and Wire Reports
August 31, 2023

Despite their advertising and marketing claims to the contrary, a new report reveals the extent to which major tech companies...

chief data officer

CDO Roles Are Becoming More Popular, But They Often Lack Staying Power

by Tomas Kratky
June 28, 2023

Increasingly, companies are hiring chief data officers and chief data analytics officers to oversee their data environment. But while the...

Next Post
alito

Would Alito’s Defense Prevail Under the FCPA?

Available SQ
New call-to-action

Jump to a Topic

AML Anti-Bribery Anti-Corruption Artificial Intelligence (AI) Automation Banking Board of Directors Board Risk Oversight Business Continuity Planning California Consumer Privacy Act (CCPA) Communications Management Corporate Culture COVID-19 Cryptocurrency Culture of Ethics Cybercrime Cyber Risk Data Analytics Data Breach Data Governance DOJ Download Due Diligence Enterprise Risk Management (ERM) ESG FCPA Enforcement Actions Financial Crime Financial Crimes Enforcement Network (FinCEN) GDPR HIPAA Know Your Customer (KYC) Machine Learning Monitoring RegTech Reputation Risk Risk Assessment Sanctions SEC Social Media Risk Supply Chain Technology Third Party Risk Management Tone at the Top Training Whistleblowing
No Result
View All Result

Privacy Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2023 Corporate Compliance Insights

No Result
View All Result
  • Home
  • About
    • About CCI
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
    • On-Demand Webinars: Earn CEUs
  • Subscribe

© 2023 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT