No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Career Connection
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Whitepapers & Reports
    • eBooks
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
  • Subscribe
  • Home
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Career Connection
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Whitepapers & Reports
    • eBooks
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
  • Subscribe
No Result
View All Result
Corporate Compliance Insights
Home Compliance

The Importance of BPM in GDPR Compliance

by Mark Holenstein
June 29, 2018
in Compliance, Featured
process workflow map

How Business Process Management Can Help Meet GDPR Requirements

Mark Holenstein of Signavio discusses how process optimization helps to better prepare companies for GDPR and other regulatory compliance through the internal processes. Process management is seen as one of the necessary organizational steps needed to ensure a business is most prepared, as well as documented in their procedures.

The General Data Protection Regulation (GDPR) is a popular topic of conversation among business professionals around the world. The law was originally introduced and implemented on April 27, 2016, and allowed a two-year post-adoption grace period for businesses to become compliant and introduce a new system. The formal enforcement date for fining noncompliant organizations took effect on May 25, 2018. A survey completed by BPTrends, a firm that follows process modeling trends, indicated that in some cases, European businesses surpassed U.S. businesses on GDPR compliance by up to 500 percent. The survey also found that European businesses were more prepared due to their sophisticated business processes. However, it should be noted that many European and U.S.-based businesses are adopting GDPR standards as good practice.

Business process management (BPM) involves how businesses study, identify, change and monitor business processes and modeling to ensure that they run efficiently while improving those processes over time. The data from the BPTrends report shows that no North American organization in 2017 had spent more than $10 million on business process work or improvements. In contrast, five European companies spent between $10 million and $50 million, with one organization investing over $50 million. Process management can assist both European and North American companies in their processes when they become GDPR compliant; however, the emphasis on processes in Europe explains why those businesses are much more prepared.

With any organization looking to become GDPR compliant, processes must change to better protect the organization and implement new workflows. New plans must be drawn up for each organization, as well as documented and communicated to internal stakeholders, thus creating new processes. Much of the focus around the GDPR has been on data and data protection, rather than on processes, which are equally as important for companies affected by the regulation. Keeping up with the tracking and reporting required to achieve regulatory compliance can cost organizations considerable time and resources. Without an efficient system, it’s no doubt that an organization could easily fail to maintain compliance or efficiently keep up with internal deadlines that may require consent under the GDPR. For example, some of these processes might include ways in which an organization deals with a data breach, documents that breach and secures their systems to prevent future problematic implications. The way a business handles consent and data management in compliance with GDPR is all through their internal processes.

Well-functioning process management is essential when it comes to avoiding monetary penalties, yet many organizations do not see this as self-evident. A BPM system gives businesses the tools they need for rapid reaction to regulatory change. Compliance management is thus made easier, and complex rule sets are replaced by compliant and functioning processes. A business process management system is able to identify regulatory violations and risks in daily processes, ensure employees are correctly carrying out critical decisions, incorporate compliance changes into processes and ensure seamless traceability of new processes.

For example, any company that conducts business in the EU or with EU citizens, otherwise known as “data subjects,” must be within compliance. For a company like Cola-Cola that does business internationally, the processes of compiling and storing their company data must be addressed. The GDPR states that any company posing a risk to EU data subjects can be fined up to 4 percent of their global revenue, or €20 million, whichever is greater.  If Coca-Cola was to experience a data breach of this information, they could potentially be fined up to $1.1 billion, based on their 2017 revenue of $35.41 billion.

Process optimization not only prepares these companies for GDPR, but also provides workflow acceleration and process intelligence. All are critical to successfully implementing new GPDR regulations within an organization. Some basic operations of a BPM system include defining framework based on legal and standardized requirements; identifying, documenting and prioritizing risks; and assessing controls with supporting processes, procedures and test activities. Implementing these workflow processes to manage risk and controls is of the highest importance, as it allows for a business to monitor and report while continuously improving.

Effectively translating strategy into action is the cornerstone of business transformation, and using a BPM system assists in creating positive behaviors and mitigating threats businesses will encounter as the organization embarks on their journey to GDPR compliance through process management.


Tags: GDPR
Previous Post

Penalties for Corporate Offenders in Australia Set for Significant Change

Next Post

90 Percent GDPR-Audit Failure Rates Ahead

Mark Holenstein

Mark Holenstein

Mark Holenstein is COO at Signavio, a leading provider of business process management solutions, where he is responsible for sales, customer service and marketing. For more information please visit www.signavio.com.

Related Posts

gdpr

UK Resurrects Data Protection Reforms, EU Court Rules on GDPR in Civil Cases

by Jonathan Armstrong and André Bywater
March 15, 2023

Recent courtroom and legislative action in Europe will likely have ripple effects around the world for companies subject to regulations...

eu flag

Preparing Your Company for the Latest GDPR Data Transfer Developments & Upcoming Deadlines

by Kevin L. Coy
November 30, 2022

An EU court decision and legislative moves in the U.S. and UK make compliance with privacy regulations increasingly difficult. Arnall...

minidata_b

Honey, I Shrunk the Data: How to Keep Customer Info on a Need-to-Know Basis

by Parker Poe
November 30, 2022

It may be tempting to hoard the data you have gathered on your customers, but an increasing number of regulations...

uk ico data access

UK’s Data Protection Regulator Signals Crackdown on Access Request Violations

by Jonathan Armstrong and André Bywater
October 5, 2022

Data privacy laws in the EU and UK established the right of individuals to find out what personal information organizations...

Next Post
rubber "fail" stamp

90 Percent GDPR-Audit Failure Rates Ahead

Compliance Job Interview Q&A

Jump to a Topic

AML Anti-Bribery Anti-Corruption Artificial Intelligence (AI) Automation Banking Board of Directors Board Risk Oversight Business Continuity Planning California Consumer Privacy Act (CCPA) Code of Conduct Communications Management Corporate Culture COVID-19 Cryptocurrency Culture of Ethics Cybercrime Cyber Risk Data Analytics Data Breach Data Governance DOJ Download Due Diligence Enterprise Risk Management (ERM) ESG FCPA Enforcement Actions Financial Crime Financial Crimes Enforcement Network (FinCEN) GDPR HIPAA Know Your Customer (KYC) Machine Learning Monitoring RegTech Reputation Risk Risk Assessment SEC Social Media Risk Supply Chain Technology Third Party Risk Management Tone at the Top Training Whistleblowing
No Result
View All Result

Privacy Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2022 Corporate Compliance Insights

No Result
View All Result
  • Home
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Career Connection
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Whitepapers & Reports
    • eBooks
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
  • Subscribe

© 2022 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT