No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Career Connection
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Whitepapers & Reports
    • eBooks
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
  • Subscribe
  • Home
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Career Connection
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Whitepapers & Reports
    • eBooks
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
  • Subscribe
No Result
View All Result
Corporate Compliance Insights
Home Data Privacy

The Evolving Relationship Between Privacy Pros and IT

by Chris Babel
September 21, 2018
in Data Privacy, Featured
man holding tablet with padlock icon

Tech Solutions Emerging to Meet Increasing Regulation

Privacy and data protection have challenged organizations for decades, but with companies’ increasing reliance on data to drive business, the old, manual processes and ad hoc program management tools no longer cut the mustard. Chris Babel of TrustArc discusses the recent progress made in the adoption of automated tools.

Historically, most companies have addressed data protection and privacy compliance through a combination of legal and consulting services. However, three factors are changing this approach: many organizations now increasingly rely on data to drive their business; organizations employ cross-border business activities; and, finally, regulatory requirements for demonstrating ongoing compliance have increased in number and scope (e.g., GDPR). These changes have necessitated the purchase of technology solutions to enable privacy management systems that can scale and be operationalized more efficiently.

The ePrivacy Directive mandates in the European Union in 2002 spurred the growth of privacy-dedicated solutions for monitoring website trackers and managing cookie consent. Still, many companies continue to rely on manual processes and ad hoc tools to manage their programs. Recently, however, in part due to the complexity of complying with the EU General Data Protection Regulation (GDPR), we have seen an increased demand for technology tools to automate and scale privacy assessments and data mapping.

To understand the factors driving the increased adoption of technology solutions to manage privacy compliance, TrustArc, along with the International Association of Privacy Professionals (IAPP), the world’s largest global information privacy community, surveyed hundreds of organizational leaders about their implementations. The survey results highlight the types of technologies firms consider important. The findings also shine a light on the evolving relationship between privacy and IT and infosec teams.

Privacy Tech Adoption Approaching the Tipping Point

As a result of privacy mandates, such as the GDPR, organizations are searching for tools that help them account for how personal data is entering the organization, how it is being used, the permissions that are attached to it and who has responsibility for managing it. Eight of the 10 categories of technology tools the survey addressed are projected to see increased adoption rates based on purchase plans and top 50 percent adoption.

Currently, decision-makers believe the following technologies will help them best achieve these goals; more than 60 percent of respondents have already purchased or are planning to purchase solutions in the following categories:

  • Network activity monitoring
  • Secure enterprise communications
  • Website scanning/cookie management
  • Privacy program assessment/management

There is also a forming wave of technology adoption for a new breed of privacy solutions. At least 30 percent of respondents plan to purchase or have purchased, but not yet implemented tools including:

  • Data mapping and flow
  • Personal data discovery
  • Privacy program assessment/management

The growth of these tools tells us that privacy-centric technology adoption is on the rise. Privacy program management tools that help operationalize new policies are in high demand today and in forward-looking product roadmaps. These facts underscore the mad scramble for solutions that can handle the rigors of GDPR and other regulatory requirements.

Purchase Decisions Don’t Always Align with Public Perception

While it appears companies more or less agree on the technologies that enable them to automate privacy assessment processes, there is not a consensus on who should pay for and manage those platforms.

The technologies organizations are evaluating fall under two primary categories. The first are privacy program management tools designed specifically for the needs of the privacy officer. These include assessment managers, consent managers and data mapping. An organization’s privacy department owns the purchase decision for these types of solutions. The second category of tools are enterprise privacy management solutions built with the needs of the entire organization in mind. These technologies include network activity monitoring, data discovery and enterprise communication. These purchase decisions typically fall under IT or infosec teams.

Though IT and infosec control the budgets for enterprise privacy management technologies, results from the survey show that privacy has influence and provides significant input on eight of the 10 categories of technology surveyed, including privacy program assessment, consent management and data mapping.

Privacy Has a Strong Influence on Purchase Decisions Across Most Product Categories

Regardless of which department’s budget covers a given technology solution, organizations’ privacy teams still have influence over many purchase decisions. For incident response solutions, 69 percent of respondents said privacy had input into the decision-making, even though IT budget was typically responsible for the purchase. Similarly, nearly three-quarters of respondents believe privacy teams have sway over the purchase of personal data discovery tools, despite the budget for such a purchase coming most often from IT. Part of this phenomenon is due to the increasing importance of privacy requirements. It’s also reflective of the size of the company. As an organization grows, the budget moves from IT and infosec into legal and privacy.

The Entire Organization Benefits from Privacy Technology

An organization is more likely to reap the benefits of a purchase if the entire organization can easily use the tool, no matter which department is responsible for the purchase. Organizations that plan to purchase and operationalize privacy technology solutions should prepare themselves for a widespread usership. More than three-quarters of respondents observe that privacy teams use data mapping and flow and personal data discovery tools. Forty-six and 41 percent, respectively, feel those tools are used by other teams within the organization. Privacy program assessment tools, which are both heavily used already and in future plans, are primarily used by the core privacy teams.

Forward-Looking Organizations Should Plan for Greater Privacy Focus

Second to lack of budget, respondents state that the largest barrier to purchase for any of these tools is inadequate internal resources for implementation. Organizations must develop processes and teams responsible for managing technology implementation even before devoting budget to those tools. Without the resources available to manage the purchase, implementation and usage process, the organization risks operationalizing technology that quickly falls out of use. Privacy standards are only proliferating and becoming stricter. Decision-makers should plan for the growth of privacy technology adoption ahead of time, lest their initiatives lead to missed compliance requirements.


Tags: GDPR
Previous Post

Protiviti Study: Data and Analytics Are Top Priorities for Finance Executives

Next Post

Treat Regulatory Compliance as an Opportunity, Not a Threat

Chris Babel

Chris Babel

Chris Babel is CEO of TrustArc. He has led the company through significant growth and transformation into a leading global privacy compliance and risk management company. Before joining TrustArc, Chris spent over a decade building online trust, most recently in the security industry as Senior Vice President and General Manager of VeriSign’s worldwide authentication services business. He holds a B.A. in Mathematical Methods in the Social Sciences and Economics with Highest Distinction from Northwestern University.  

Related Posts

gdpr

UK Resurrects Data Protection Reforms, EU Court Rules on GDPR in Civil Cases

by Jonathan Armstrong and André Bywater
March 15, 2023

Recent courtroom and legislative action in Europe will likely have ripple effects around the world for companies subject to regulations...

eu flag

Preparing Your Company for the Latest GDPR Data Transfer Developments & Upcoming Deadlines

by Kevin L. Coy
November 30, 2022

An EU court decision and legislative moves in the U.S. and UK make compliance with privacy regulations increasingly difficult. Arnall...

minidata_b

Honey, I Shrunk the Data: How to Keep Customer Info on a Need-to-Know Basis

by Parker Poe
November 30, 2022

It may be tempting to hoard the data you have gathered on your customers, but an increasing number of regulations...

uk ico data access

UK’s Data Protection Regulator Signals Crackdown on Access Request Violations

by Jonathan Armstrong and André Bywater
October 5, 2022

Data privacy laws in the EU and UK established the right of individuals to find out what personal information organizations...

Next Post
note with both options for "carrot" or "stick" checked

Treat Regulatory Compliance as an Opportunity, Not a Threat

Compliance Job Interview Q&A

Jump to a Topic

AML Anti-Bribery Anti-Corruption Artificial Intelligence (AI) Automation Banking Board of Directors Board Risk Oversight Business Continuity Planning California Consumer Privacy Act (CCPA) Code of Conduct Communications Management Corporate Culture COVID-19 Cryptocurrency Culture of Ethics Cybercrime Cyber Risk Data Analytics Data Breach Data Governance DOJ Download Due Diligence Enterprise Risk Management (ERM) ESG FCPA Enforcement Actions Financial Crime Financial Crimes Enforcement Network (FinCEN) GDPR HIPAA Know Your Customer (KYC) Machine Learning Monitoring RegTech Reputation Risk Risk Assessment SEC Social Media Risk Supply Chain Technology Third Party Risk Management Tone at the Top Training Whistleblowing
No Result
View All Result

Privacy Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2022 Corporate Compliance Insights

No Result
View All Result
  • Home
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Career Connection
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Whitepapers & Reports
    • eBooks
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
  • Subscribe

© 2022 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT