INFOCUS. Using Data Mapping to Manage Data Governance Risks. Data- Mapping Stakeholders BY SIMON MCDOUGALL AND SAMITA PATEL

Size: px
Start display at page:

Download "INFOCUS. Using Data Mapping to Manage Data Governance Risks. Data- Mapping Stakeholders BY SIMON MCDOUGALL AND SAMITA PATEL"

Transcription

1 promontory.com INFOCUS SEPTEMBER 8, 206 Using Data Mapping to Manage Data Governance Risks BY SIMON MCDOUGALL AND SAMITA PATEL The explosive growth in the use and transmission of data has made it more difficult than ever for organizations to understand how they collect and manage personal data at a time when intensifying regulatory rules and media attention have magnified the risks of failing to do so. Organizations are increasingly launching data-reliant digital initiatives to realize the full potential of customer information, which in turn requires data handling and privacy practices that comply with laws and regulations. An organization s size, complexity, and geography often compound that challenge. Simon McDougall is a managing director at Promontory, and leads its global privacy and data protection practice, advising firms on governance, risk, and regulatory issues related to their data and records. Data mapping provides a consistent way of analyzing, documenting, and graphically representing how information flows within an organization and among stakeholders (including third parties), systems, and jurisdictions, allowing the organization to identify the potential points at which that information may be vulnerable. The exercise provides companies a structured and efficient approach to identifying risks and addressing compliance gaps in data transfers and similar activities, while helping them balance business objectives and regulatory requirements. Developing data maps in alignment with the data lifecycle Collection Samita Patel is an associate at Promontory, and advises clients on data protection and privacy-related matters, including support in building data-mapping frameworks. Disposal, Destruction, and Retention Storage Privacy Records Management Information Technology Data- Mapping Stakeholders Information Security Marketing Human Resources Use Access and Transfer

2 starting with when personal data is collected and tracking its use, disclosure, retention, and eventual disposition can also help identify all the groups within an organization that may have an interest in, or benefit from, understanding its data flows. Data Mapping Promotes Stronger Governance, Risk Management, and Compliance Data mapping supports an organization s overall data-governance policy and procedures, allowing it to demonstrate compliance not only with legal requirements, but with corporate standards and risk appetites, for handling data. Maintaining a record of key practices for personal-data handling may be necessary to assure organizations, clients, employee representatives, business partners, auditors, and regulators that data handling is understood and managed in accordance with international standards, local requirements, and sound data-governance principles. For example, companies that adhere to the Payment Card Industry Data Security Standard are required to map the processing of payment-card details. Furthermore, the European Union s General Data Protection Regulation replaces the need to complete local administrative filing and registration requirements with specific requirements for data controllers and similar requirements for data processors to maintain a record of processing activities under their responsibility. Organizations are increasingly considering data mapping to demonstrate compliance with GDPR requirements. Data maps can also help demonstrate a multijurisdictional organization s commitment to complying with privacy and data protection principles underpinning the EU Binding Corporate Rules and U.S Privacy Shield schemes for EU-compliant cross-border data transfers. Data Mapping Supports Risk and Compliance Assessments Data-mapping exercises often serve as the foundation for privacy-related risk-assessment activities and allow organizations to identify vulnerabilities in key business processes and systems for personaldata handling. When combined with privacy-compliance assessments, data maps help organizations identify gaps in privacy controls to assess and mitigate risk, and improve their data-handling practices. Many organizations have undertaken some level of data mapping during the initial phases of largescale privacy-compliance initiatives to chart the use and flow of personal data across the enterprise. Common areas for data mapping include: Client and Customer Data HR Data Client contact and marketing lists Customer profiles and preferences Card payment and other financialrelated data Data on social media and customer interactions Vetting and employee monitoring HR records management Occupational health and medicalrelated data Compensation and benefits data PROMONTORY Sightlines InFocus SEPTEMBER 8, 206 2

3 Data maps are valuable tools in assessing risks arising from potential sources of data-handling incidents, highlighting high-risk areas and providing a means to identify and reduce the likelihood of future data breaches. Specific Business, Risk, and Compliance Benefits of Data Mapping Data mapping can benefit businesses by driving more efficient operations, while supporting stronger risk and compliance processes. Stronger vendor management Data-mapping outputs can provide a centralized record of both internal and external processes involving the sharing or transferring of data, including data shared with vendors. Several functions such as legal, information-security, and vendormanagement teams may be interested in data-mapping outputs. They may use data maps to support vendor risk management activities, including managing risk and compliance related to domestic and international transfer requirements and supporting the monitoring of vendors privacy and security obligations. The exercise may also help vendors demonstrate they are in compliance with privacy requirements. Better measurement of new technology and organizational change Maintaining a centralized record of company data flows can help reduce costs and efforts in assessing the impact of new technology and organizational change. It may be necessary to assess data flows before introducing a new business process, or integrating or decommissioning a system. Companies assessing a proposed merger, acquisition, or sale of an existing business can use a centralized data-flow inventory to minimize the time and effort in determining which data flows are affected, and in turn, support organizations in making thought decisions in managing personal data. Standardized reporting Certain business lines may also benefit from using data-mapping outputs as a standardized report in sharing data-handling practices with other business lines or senior management. They may also be helpful in providing examiners and internal or external audit with an understanding of the key activities for handling personal data. Increased data availability and responsiveness Maintaining centralized data-mapping records provides a snapshot of key data repositories, which supports efficient and timely responses to requests for information from customers, prospects, clients, investors, government bodies, law-enforcement agencies, and regulators. PROMONTORY Sightlines InFocus SEPTEMBER 8, 206 3

4 EMPLOYEE ONBOARDING MAPPING THE DATA LIFE CYCLE (EXCERPT) Collection Welcome letter; newhire forms Offer and disclosures sent 3 G6 G26 B B2 B30 B3 B B6 B2 B30 C2 C5 C8 Non-U.S. Job Candidate/New Employee Completes paper-based application Offer made Non-U.S. HR Manager Paper benefit forms are scanned and sent to U.S.file room B B2 C2 Offer letters stored Online application completed Signed form returned on first day Send to fileroom Extending offer transfers data to Workday Accesses selected new hire data B30 C U.S. Job Candidate/New Employee B3 C8 6 2 C2 C5 Server C8 Storage 4 U.S. HR Associate HR Server Communication of background check results Enters employee data in Workday MS Exchange A0 0 Background check obtained before offer is made B B30 B3 Archive/Retention Enters data B HR Shared Drive B6 C2 B2 C5 B30 C8 Key U.S. Candidate Application Process U.S. Background Check Process U.S. New Hire Administration Non-U.S. Candidate Application Process Non-U.S. Candidate Application Process 2 3 Process Number A (#) C (#) Internal External Reference to Sensitive Personal Data Reference to Data Category The above graphic is an excerpt of a larger data map. Map areas diagramming data usage and transfers are not shown. B (#) G (#) Reference to Special Data Identified Privacy Gap PROMONTORY Sightlines InFocus SEPTEMBER 8, 206 4

5 Identification of duplicate data sets and business processes Data-mapping exercises often identify duplication and storage of excess data, which is costly and risky. Exercise outputs can serve as a guide to evaluating and consolidating databases and processes. Increased awareness of data handling Gathering the information required to map the flow of personal data particularly when part of a privacy-compliance assessment helps to increase awareness of privacy considerations for personal data. Support for overall data-governance policies and procedures: Data mapping can be a more tangible way for employees to understand and apply data-governance policies and procedures, such as those pertaining to data classification and access management. Tips for Success in Data Mapping Consider taking the following steps to gain the most value from a data-mapping exercise: Define objectives and priorities Clearly defined objectives and priorities will guide decisions about desired outputs, including what those outputs should look like and how they will be used. If the objective is to monitor privacy compliance, ensure the mapping exercise identifies risk or assesses existing privacy controls related to data flows. While visual maps are useful snapshots of data handling for reporting or quick reference, the underlying information should provide necessary detail to make effective and informed decisions. Consider model sustainability A one-off data-mapping exercise captures a particular point in time. To gain the most value from the exercise, develop a model that allows for the periodic or ongoing update and maintenance of the data-flow information. The effort and cost of data-mapping activities correspond to the organization s complexity, the level of detail required in relation to data flows and process-level data handling, and the frequency of process, technology, and organizational change. Make the data-mapping methodology scalable The urgent priority may be mapping specific business areas or jurisdictions, but the chosen solution should be flexible enough to accommodate other areas in the future, along with specific requirements of those areas. Consider the time frame, effort, and budget to achieve the objectives These factors essentially determine the structure of a data-mapping exercise and whether to manage the effort internally or seek external resources, solutions, or tools. PROMONTORY Sightlines InFocus SEPTEMBER 8, 206 5

6 Assess existing data-mapping solutions and tools Data-mapping solutions are steadily increasing, from off-the-shelf software products to consultancy support, and vary in maturity, resources, and cost. Select the solution that supports your objectives and can be tailored to suit business requirements. Data mapping can support compliance with fast-changing domestic and international privacy requirements, particularly in the case of cross-border data flows and multijurisdictional data management. Organizations that have a strong grasp on how they handle personal information will have a head start in responding to these changes. A version of this article appeared in the August 206 issue of Privacy Laws & Business. Jim Gregoire contributed to this article. PROMONTORY Sightlines InFocus SEPTEMBER 8, 206 6

7 PROMONTORY Sightlines InFocus SEPTEMBER 8, 206 7

8 Contact Promontory For more information, please call or your usual Promontory contact or: Jim Gregoire Senior Principal, San Francisco Rob Grosvenor Director, London Marc Loewenthal Director, San Francisco Simon McDougall Managing Director, London Samita Patel Associate, London Michael Spadea Director, San Francisco To subscribe to Promontory s publications, please visit promontory.com/subscribe.aspx Follow Promontory on Promontory Financial Group helps companies and governments around the world manage complex risks and meet their greatest regulatory challenges. We are the world s foremost experts in financial risk, regulation, and compliance. Former U.S. Comptroller of the Currency Eugene A. Ludwig founded Promontory in 200. Promontory Financial Group, LLC 80 7th Street, NW, Suite 00, Washington, DC Telephone Fax promontory.com 206 Promontory Financial Group, LLC. All Rights Reserved. PROMONTORY Sightlines InFocus SEPTEMBER 8, 206 8

The table below compares to the 2009 Essential Elements and the 2018 Enhanced Data Stewardship Elements

The table below compares to the 2009 Essential Elements and the 2018 Enhanced Data Stewardship Elements October 8, 2018 The Essential Elements of Accountability were developed by a multi-stakeholder group that met in Dublin Ireland as the Global Accountability Dialogue. The Essential Elements provided granularity

More information

How to Stand Up a Privacy Program: Privacy in a Box

How to Stand Up a Privacy Program: Privacy in a Box How to Stand Up a Privacy Program: Privacy in a Box Part III of III: Maturing a Privacy Program Presented by the IT, Privacy, & ecommerce global committee of ACC Thanks to: Nick Holland, Fieldfisher (ITPEC

More information

General Data Protection Regulation

General Data Protection Regulation General Data Protection Regulation Caroline Budde Vice President, Compliance, Global Privacy Officer Walgreens Boots Alliance Agenda Overview of global data protection The General Data Protection Regulation

More information

Guidelines for Information Asset Management: Roles and Responsibilities

Guidelines for Information Asset Management: Roles and Responsibilities Guidelines for Information Asset Management: Roles and Responsibilities Document Version: 1.0 Document Classification: Public Published Date: April 2017 P a g e 1 Contents 1. Overview:... 3 2. Audience...

More information

INFOCUS. A Data-Based Taxonomy for Payment Instruments BY MARC LOEWENTHAL AND JIM GREGOIRE

INFOCUS. A Data-Based Taxonomy for Payment Instruments BY MARC LOEWENTHAL AND JIM GREGOIRE promontory.com INFOCUS MAY 2, 2013 A Data-Based Taxonomy for Payment Instruments BY MARC LOEWENTHAL AND JIM GREGOIRE A payment transaction is commonly characterized by the goods or services purchased and

More information

Presenting a live 90-minute webinar with interactive Q&A. Today s faculty features:

Presenting a live 90-minute webinar with interactive Q&A. Today s faculty features: Presenting a live 90-minute webinar with interactive Q&A Compliance With New EU GDPR: Steps Investment Funds, Banks, Advisers and Financial Intermediaries Should Take Now Revising Service Agreements and

More information

Ready for GDPR? Five steps to turn compliance into your advantage

Ready for GDPR? Five steps to turn compliance into your advantage Ready for GDPR? Five steps to turn compliance into your advantage 2017 KPMG LLP, a UK limited liability partnership and a member firm of the KPMG network of independent member firms affiliated with KPMG

More information

Data Protection Officer

Data Protection Officer Data Protection Officer External Vacancy Post Ref: 5985. Part Time. 15 hours per week. Permanent. 29,146.30 to 31,845.48 per annum, pro rata. Attractive benefits for this post include 35 days holiday per

More information

1.3. We will post any changes we may make to our Notice on this Website or communicate them to you by .

1.3. We will post any changes we may make to our Notice on this Website or communicate them to you by  . Privacy Notice 1. About this Privacy Notice 1.1. This is the privacy notice ( Notice ) of Swatch Ltd., Jakob-Stämpfli-Strasse 94, 2502 Biel/Bienne, Switzerland. ( Swatch, we", us, our ). Swatch is the

More information

October 30, Fortifying Internal Audit To Meet Regulatory Expectations. Internal Audit Under the Microscope

October 30, Fortifying Internal Audit To Meet Regulatory Expectations. Internal Audit Under the Microscope promontory.com InFocus October 30, 2013 Fortifying Internal Audit To Meet Regulatory Expectations By Thomas Loughlin and Stephen Mills Supervisory authorities have been sounding an increasingly loud drumbeat

More information

Roadmap to Reshape Supervision: A First Look

Roadmap to Reshape Supervision: A First Look promontory.com 14 SEPTEMBER 2012 BY CARLO COMPORTI and RAFFAELE COSIMO EUROPEAN REGULATORY DEVELOPMENTS Roadmap to Reshape Supervision: A First Look European policymakers continue to demonstrate collective

More information

Launching a hedge fund building the operational foundation for success

Launching a hedge fund building the operational foundation for success Financial services June 2014 Launching a hedge fund building the operational foundation for success By Samer Ojjeh, Koma Gandy Fischbein and Courtney Murray The alternative asset management industry is

More information

Applicant Privacy Notice Date: June 1, 2018

Applicant Privacy Notice Date: June 1, 2018 Applicant Privacy Notice Date: June 1, 2018 Facts Wyndham Hotels & Resorts, Inc. and its Affiliates ( we, our, us ) value your trust and are committed to the responsible management, use and protection

More information

GDPR Compliance Benchmarking: Measuring Accountability

GDPR Compliance Benchmarking: Measuring Accountability GDPR Compliance Benchmarking: Measuring Accountability Copyright 2017 by Nymity Inc. All rights reserved. All text, images, logos, trademarks and information contained in this document are the intellectual

More information

Information governance for the real world

Information governance for the real world Information governance for the real world 1 2 Information governance is the activities and technologies that organizations employ to maximize the value of their information while minimizing associated

More information

SOLUTION BRIEF EU GENERAL DATA PROTECTION REGULATION COMPLIANCE WITH RSA ARCHER

SOLUTION BRIEF EU GENERAL DATA PROTECTION REGULATION COMPLIANCE WITH RSA ARCHER EU GENERAL DATA PROTECTION REGULATION COMPLIANCE WITH RSA ARCHER ARRIVAL OF GDPR IN 2018 The European Union (EU) General Data Protection Regulation (GDPR), which takes effect in 2018, will bring changes

More information

CFPB Compliance Management Review

CFPB Compliance Management Review General Principles and Introduction Supervised entities within the scope of CFPB s supervision and enforcement authority include both depository institutions and non-depository consumer financial services

More information

A COMPANION DOCUMENT TO THE GDPR READINESS DECISION TREE QUESTIONS AND ANALYSIS. April 19, 2017

A COMPANION DOCUMENT TO THE GDPR READINESS DECISION TREE QUESTIONS AND ANALYSIS. April 19, 2017 A COMPANION DOCUMENT TO THE GDPR READINESS DECISION TREE QUESTIONS AND ANALYSIS April 19, 2017 The General Data Protection Regulation (GDPR) represents perhaps the most sweeping changes to the protection

More information

Easing the burden of data privacy compliance

Easing the burden of data privacy compliance Easing the burden of data privacy compliance EU General Data Protection Regulation (GDPR) managed services Introduction Companies should not underestimate the complexity of achieving and maintaining compliance

More information

Contents. NRTT Proprietary and Confidential - Reproduction and distribution without prior consent is prohibited. 2

Contents. NRTT Proprietary and Confidential - Reproduction and distribution without prior consent is prohibited. 2 Privacy Policy Contents INTRODUCTION... 4 PROCESSING PRINCIPALS... 5 FAIRNESS AND LAWFULNESS... 5 RESTRICTION TO A SPECIFIC PURPOSE... 5 DELETION... 5 CONFIDENTIALITY AND DATA SECURITY... 5 RELIABILITY

More information

SOLUTION BRIEF RSA ARCHER REGULATORY & CORPORATE COMPLIANCE MANAGEMENT

SOLUTION BRIEF RSA ARCHER REGULATORY & CORPORATE COMPLIANCE MANAGEMENT RSA ARCHER REGULATORY & CORPORATE COMPLIANCE MANAGEMENT INTRODUCTION Your organization s regulatory compliance landscape changes every day. In today s complex regulatory environment, governmental and industry

More information

2017 IBM Corporation. IBM s Journey to GDPR Readiness

2017 IBM Corporation. IBM s Journey to GDPR Readiness IBM s Journey to GDPR Readiness IBM s Journey to GDPR Readiness At IBM, we have a deep rooted understanding that privacy is foundational to trust. We are approaching the GDPR in the same spirit, both internally

More information

GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges

GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges Cyber Risk 1 GDPR and Canadian organizations: Addressing key challenges The regulation

More information

ISACA San Francisco Chapter

ISACA San Francisco Chapter ISACA San Francisco Chapter The 2007 Privacy Panel Rena Mears, CISSP, CIPP, CPA, CISA Partner, Deloitte & Touche LLP March 23, 2007 San Francisco 0 What is Privacy and Why Now? Definition of PII The definition

More information

Insightly, Inc. Data Processing Addendum

Insightly, Inc. Data Processing Addendum Insightly, Inc. Data Processing Addendum 1. Introduction 1 This Data Processing Addendum ( Addendum ) is an integral part of the Insightly Terms of Service, Privacy Policy and any Professional Services

More information

A questionnaire for senior management

A questionnaire for senior management Getting ready for GDPR Part 2: Accountability - A questionnaire for senior management Accountability is more than simple compliance with the rules - it implies a culture change organisations and not Data

More information

External Supplier Control Obligations. Records Management

External Supplier Control Obligations. Records Management External Supplier Control Obligations Records Management Page 1 Governance and Roles and The Supplier must define and communicate roles and responsibilities for Records Records Management requires high-level

More information

EU General Data Protection Regulation: Are you ready?

EU General Data Protection Regulation: Are you ready? EU General Data Protection Regulation: Are you ready? Powered by Global Markets EY Knowledge Contents What do you need to know about the new EU General Data Protection Regulation? Are organisations ready

More information

Securing the Future with Physical Identity and Access Management

Securing the Future with Physical Identity and Access Management Securing the Future with Physical Identity and Access Management 1 CONTENTS 03 04 05 06 07 08 10 Introduction Physical Identity and Access Management: Bridging the stakeholder gap Physical Identity and

More information

SOLUTION BRIEF HELPING PREPARE FOR RISK ASSESSMENT & COMPLIANCE CHALLENGES FOR GDPR WITH RSA SECURITY ADDRESSING THE TICKING CLOCK OF GDPR COMPLIANCE

SOLUTION BRIEF HELPING PREPARE FOR RISK ASSESSMENT & COMPLIANCE CHALLENGES FOR GDPR WITH RSA SECURITY ADDRESSING THE TICKING CLOCK OF GDPR COMPLIANCE HELPING PREPARE FOR RISK ASSESSMENT & COMPLIANCE CHALLENGES FOR GDPR WITH RSA SECURITY ADDRESSING THE TICKING CLOCK OF GDPR COMPLIANCE PREPARATION FOR GDPR IS ESSENTIAL The EU GDPR imposes interrelated

More information

GDPR. Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry

GDPR. Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry GDPR Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry Who are we? Dillistone Group Plc, a public company listed on the AIM market of the London stock

More information

October 18, 2017 Consumer Protection Principles: Consumer-Authorized Financial Data Sharing and Aggregation

October 18, 2017 Consumer Protection Principles: Consumer-Authorized Financial Data Sharing and Aggregation 1700 G Street, N.W., Washington, DC 20552 October 18, 2017 Consumer Protection Principles: Consumer-Authorized Financial Data Sharing and Aggregation In the Dodd-Frank Act, Congress instructed the Bureau

More information

A Guide to IT Risk Assessment for Financial Institutions. March 2, 2011

A Guide to IT Risk Assessment for Financial Institutions. March 2, 2011 A Guide to IT Risk Assessment for Financial Institutions March 2, 2011 Welcome! Housekeeping Control panel on the right side of your screen. Audio Telephone VoIP Submit Questions in the pane on the control

More information

Technology Landscape. 3 Types of Advisor-Client Texting Solutions for Financial Services

Technology Landscape. 3 Types of Advisor-Client Texting Solutions for Financial Services Technology Landscape 3 Types of Advisor-Client Texting Solutions for Financial Services INTRODUCTION Financial services firms text their customers for a number of different reasons, and many already have

More information

Risk Assessment - Balancing Risk While Enhancing Controls

Risk Assessment - Balancing Risk While Enhancing Controls Risk Assessment - Balancing Risk While Enhancing Controls cliftonlarsonallen.com Session Objectives Define risk and risk assessment. Execution of assessment and approach Impact on controls and future state

More information

The EU raises the bar on data privacy:

The EU raises the bar on data privacy: The EU raises the bar on data privacy: AIM for an integrated response Organizations can view the EU s General Data Protection Regulation (GDPR) as either a problem or an opportunity. Grant Thornton sees

More information

Will Your Company Pass a Privacy Audit?

Will Your Company Pass a Privacy Audit? Will Your Company Pass a Privacy Audit? by Tammi K. Franke The Issue - Companies that collect personal information are under increasing scrutiny by both consumers and governments in the United States and

More information

Questions which state 'This question does NOT use the case study' do not use the case study, and may be answered without reference to it.

Questions which state 'This question does NOT use the case study' do not use the case study, and may be answered without reference to it. ITIL Qualification: MANAGING ACROSS THE LIFECYCLE (MALC) CERTIFICATE Case Study 1, version 1.1 CASE STUDY BOOKLET This booklet contains the case study upon which at least 8 of the 10 examination questions

More information

AHIMA Information Governance & The Information Governance Adoption Model (IGAM )

AHIMA Information Governance & The Information Governance Adoption Model (IGAM ) AHIMA Information Governance & The Information Governance Adoption Model (IGAM ) Katherine Downing, MA, RHIA, CHPS, PMP Sr. Director AHIMA IG Advisors 2017 2017 Introductions and Welcome! Agenda Part Part

More information

A robust and systematic review.

A robust and systematic review. Principal risks and uncertainties A robust and systematic review. The Board considers these to be the most significant risks faced by the Group that may impact the achievement of our six strategic drivers.

More information

AVEPOINT RISK INTELLIGENCE SYSTEM

AVEPOINT RISK INTELLIGENCE SYSTEM Technical Overview AVEPOINT RISK INTELLIGENCE SYSTEM Keeping your data privacy protection practices on the right track. INVENTORY MANAGER Inventory Records To understand how the data is collected, maintained,

More information

EUROPEAN UNION PRIVACY NOTICE

EUROPEAN UNION PRIVACY NOTICE EUROPEAN UNION PRIVACY NOTICE ICONIQ Capital, LLC and our affiliates and subsidiaries (collectively, ICONIQ, we, our or us ) recognize the importance of protecting personal information. This European Union

More information

RECORDS MANAGEMENT FRAMEWORK

RECORDS MANAGEMENT FRAMEWORK Policies and Procedures University Organisation and Governance Policies & Procedures Records Management Framework Policy Number: 1.6.4.06 Responsible Officer: Vice-Chancellor and President Policy Editor/Contact:

More information

Privacy Policy. To invest significant resources in order to respect your rights in connection with Personal Data about you:

Privacy Policy. To invest significant resources in order to respect your rights in connection with Personal Data about you: Privacy Policy Last updated: May 17, 2018 This is the privacy policy (the Policy ) of the website www.experitest.com (the "Website") operated by Experitest Ltd., of 10 HaGavish St, 4250708 Poleg, Israel

More information

Improving Model Risk Management at Investment Advisers

Improving Model Risk Management at Investment Advisers Improving Model Risk Management at Investment Advisers Contents Improving Model-Risk Management At Investment Advisers... 1 How Promontory Can Help...2 Why Promontory?...3 About Promontory... 5 Quantitative

More information

CLAconnect.com/creditunions. Impact the Future of Credit Unions

CLAconnect.com/creditunions. Impact the Future of Credit Unions CLAconnect.com/creditunions Impact the Future of Credit Unions We Believe Enabling your success means a better world for all of us, but now, more than ever, a greater number of operational, regulatory,

More information

STRATEGIES FOR EFFECTIVELY WORKING WITH THIRD-PARTIES. September 2017

STRATEGIES FOR EFFECTIVELY WORKING WITH THIRD-PARTIES. September 2017 STRATEGIES FOR EFFECTIVELY WORKING WITH THIRD-PARTIES September 2017 Your presenters Nancy Aubrey Partner Boston, MA Nancy.aubrey@rsmus.com Rick Shriner Principal McLean, VA Rick.shriner@rsmus.com 2 Agenda

More information

NOT PROTECTIVELY MARKED

NOT PROTECTIVELY MARKED Meeting Audit Committee Public Session Date and Time Location Pacific Quay, Glasgow Title of Paper General Data Protection Regulation (GDPR) SPA Preparedness Item Number 9.4 Presented By Catherine Topley

More information

LSEG Recruitment Privacy Notice

LSEG Recruitment Privacy Notice LSEG Recruitment Privacy Notice Version 1.0 16 May 2018 RECRUITMENT PRIVACY NOTICE 1. INTRODUCTION 1.1 This Privacy Notice explains how the London Stock Exchange Group plc and the London Stock Exchange

More information

Standards for Internal Control in New York State Government 2016 Update

Standards for Internal Control in New York State Government 2016 Update Standards for Internal Control in New York State Government 2016 Update Presented to the New York State Internal Control Association John F. Buyce Audit Director April 28, 2016 1 Last Revised in 2007 A

More information

PERFORMANCE REVIEW THE PUBLIC COMPANY ACCOUNTING OVERSIGHT BOARD'S SUCCESSION PLANNING (IOPA )

PERFORMANCE REVIEW THE PUBLIC COMPANY ACCOUNTING OVERSIGHT BOARD'S SUCCESSION PLANNING (IOPA ) 1666 K Street, N.W. Washington, DC 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 www.pcaobus.org THE PUBLIC COMPANY ACCOUNTING OVERSIGHT BOARD'S SUCCESSION PLANNING (IOPA-2009-001) INTERNAL

More information

Heightened standards for compliance risk management. Lines of defense compliance s role

Heightened standards for compliance risk management. Lines of defense compliance s role Heightened standards for risk management Lines of defense s role Post-financial crisis, the Office of the Comptroller of the Currency (OCC) developed a set of heightened expectations to enhance the risk

More information

GDPR: The devil is in the data

GDPR: The devil is in the data GDPR: The devil is in the data A recent newspaper article chose a revealing headline: GDPR: the new data-protection law giving watchdogs a mega-bite. 1 Much of the coverage of the EU s new General Data

More information

EU General Data Protection Regulation in the digital age: Are you ready?

EU General Data Protection Regulation in the digital age: Are you ready? EU General Data Protection Regulation in the digital age: Are you ready? What do you need to know about the new EU General Data Protection Regulation? Data protection has entered a period of unprecedented

More information

IBM Collaboration Solutions Readiness for GDPR IBM Corporation

IBM Collaboration Solutions Readiness for GDPR IBM Corporation IBM Collaboration Solutions Readiness for GDPR Disclaimer Notice: Clients are responsible for ensuring their own compliance with various laws and regulations, including the European Union General Data

More information

Security and risk governance. An operational model

Security and risk governance. An operational model Security and risk governance An operational model Table of Contents Ecosystem not Enterprise Segregation of duties Operating model Organizational structure Governance The benefits Forward steps 2 3 4 5

More information

GDPR: what you need to know

GDPR: what you need to know GDPR: what you need to know Getting to grips with the EU General Data Protection Regulation (GDPR) Introduction In May 2018, the European Union s (EU) GDPR ushers in unprecedented data protection for EU

More information

Corporate Law Department Information Governance Survey SURVEY RESULTS. hbrconsulting.com

Corporate Law Department Information Governance Survey SURVEY RESULTS. hbrconsulting.com Corporate Law Department Information Governance Survey SURVEY RESULTS advisory managed services software solutions insights 2017 HBR Consulting LLC. All rights reserved. hbrconsulting.com info@hbrconsulting.com

More information

Privacy Management Programs. Ruth Marks and Stacey Pratt April 2018

Privacy Management Programs. Ruth Marks and Stacey Pratt April 2018 Privacy Management Programs Ruth Marks and Stacey Pratt April 2018 Agenda Quick overview of the ATIPPA, 2015. Public body responsibilities in ATIPPA, 2015 administration. Role of the Privacy Officer. Assessing

More information

Good Corporate Governance (GCG) Being a good corporate citizen is good risk management

Good Corporate Governance (GCG) Being a good corporate citizen is good risk management Good Corporate Governance (GCG) Being a good corporate citizen is good risk management Margaret Jackson Chairman Qantas Airlines, March 2004 Being a good corporate citizen is good risk management Margaret

More information

General Data Privacy Regulation: It s Coming Are You Ready?

General Data Privacy Regulation: It s Coming Are You Ready? General Data Privacy Regulation: It s Coming Are You Ready? Presenters Tristan North Worldwide ERC Government Affairs Adviser, Moderator William R. Tehan General Counsel, Graebel Companies, Inc. Hank A.

More information

A tool for assessing your agency s information and records management

A tool for assessing your agency s information and records management A tool for assessing your agency s information and records management Copyright Commonwealth of Australia 2010 Updated on 14 June 2012 Copyright of Check-up 2.0 rests with the Commonwealth of Australia.

More information

Boards and internal audit: Working together to strengthen risk management

Boards and internal audit: Working together to strengthen risk management Boards and internal audit: Working together to strengthen risk management Growing demands on boards The role of the board has always been an important and demanding one, but today s board members face

More information

Enterprise compliance Acting on today s risks to avoid tomorrow s crises

Enterprise compliance Acting on today s risks to avoid tomorrow s crises Enterprise compliance Acting on today s risks to avoid tomorrow s crises Enterprise compliance challenges cannot be ignored As many retailers know from recent history, compliance failures can lead to catastrophic

More information

Governance Guideline SEPTEMBER 2013 BC CREDIT UNIONS.

Governance Guideline SEPTEMBER 2013 BC CREDIT UNIONS. Governance Guideline SEPTEMBER 2013 BC CREDIT UNIONS www.fic.gov.bc.ca INTRODUCTION The Financial Institutions Commission 1 (FICOM) holds the Board of Directors 2 (board) accountable for the stewardship

More information

Ready for GDPR? Five steps to turn compliance into your advantage. KPMG International. kpmg.com

Ready for GDPR? Five steps to turn compliance into your advantage. KPMG International. kpmg.com Ready for GDPR? Five steps to turn compliance into your advantage KPMG International kpmg.com 2 Ready for GDPR? Ready for GDPR? The biggest change to rules governing data protection for more than 20 years

More information

EY Center for Board Matters Boards and internal audit

EY Center for Board Matters Boards and internal audit EY Center for Board Matters Boards and internal audit Working together to strengthen risk management Growing demands on boards The role of the board has always been an important and demanding one, but

More information

The Top Healthcare Compensation Issues for 2016

The Top Healthcare Compensation Issues for 2016 TRENDS & ISSUES The Top Healthcare Compensation Issues for 2016 AUTHORS Steve Sullivan Principal Transformation in healthcare is an extended journey over uncharted waters, featuring untested business strategies,

More information

Privacy Statement. Information We Collect

Privacy Statement. Information We Collect Privacy Statement Kelly Services, Inc. and its subsidiaries ("Kelly Services" or Kelly ) respects your privacy and we acknowledge that you have certain rights related to any personal information we collect

More information

Memorandum of understanding between the Competition and Markets Authority and NHS Improvement

Memorandum of understanding between the Competition and Markets Authority and NHS Improvement 1 April 2016 Memorandum of understanding between the Competition and Markets Authority and NHS Improvement Contents Page Foreword... 2 Summary points of the MoU... 3 Memorandum of understanding between

More information

These are the primary functions of the Board, and should be the main focus of the Board s attention and activities.

These are the primary functions of the Board, and should be the main focus of the Board s attention and activities. TERMS OF REFERENCE FOR THE BOARD OF DIRECTORS Introduction The Board of Directors is responsible under law for supervising the management of the Bank. This duty is codified in the Bank Act. The Board of

More information

Copyright 2018, Tech Mahindra. All rights reserved. WORKER PRIVACY NOTICE

Copyright 2018, Tech Mahindra. All rights reserved. WORKER PRIVACY NOTICE Copyright 2018, Tech Mahindra. All rights reserved. Table of Contents 1. SCOPE OF APPLICATION... 3 2. DETAILS OF THE NOTICE... 3 2.1 WHAT PERSONAL DATA WE COLLECT... 3 2.2 WHY WE COLLECT, USE AND STORE

More information

Protecting Your Personal Data Globally

Protecting Your Personal Data Globally Protecting Your Personal Data Globally How ADP s Adoption of Binding Corporate Rules Helps Your Company Comply with the General Data Protection Regulation We re passionate about protecting the privacy

More information

Robert Bond Partner 3/13/2015. EU Data Protection Officer: Roles and responsibilities

Robert Bond Partner 3/13/2015. EU Data Protection Officer: Roles and responsibilities EU Data Protection Officer: Roles and responsibilities Robert Bond, CCEP Head of Data Protection and Cyber Security Law and DPO charlesrussellspeechlys.com Robert Bond Partner Robert Bond has over 36 years'

More information

Privacy Policy EDCTP Association

Privacy Policy EDCTP Association Privacy Policy EDCTP Association Version number: V1.0 Date of approval: 25 May 2018 Approved by: EDCTP Executive Director 1 Introduction This Privacy Policy explains: the reasons for EDCTP collecting,

More information

EU General Data Protection Regulation: are you ready?

EU General Data Protection Regulation: are you ready? EU General Data Protection Regulation: are you ready? Contents What you need to know about the new EU General Data Protection Regulation Is your organization ready for the EU General Data Protection Regulation?

More information

WEWORK PRIVACY POLICY FOR PEOPLE DATA

WEWORK PRIVACY POLICY FOR PEOPLE DATA WEWORK PRIVACY POLICY FOR PEOPLE DATA OVERVIEW WeWork Companies Inc. and our affiliates and subsidiaries (referred to together as WeWork, we, our or us ) respect individual privacy and take the privacy

More information

Passit4Sure.OG Questions. TOGAF 9 Combined Part 1 and Part 2

Passit4Sure.OG Questions. TOGAF 9 Combined Part 1 and Part 2 Passit4Sure.OG0-093.221Questions Number: OG0-093 Passing Score: 800 Time Limit: 120 min File Version: 7.1 TOGAF 9 Combined Part 1 and Part 2 One of the great thing about pass4sure is that is saves our

More information

IT Audit Process. Michael Romeu-Lugo MBA, CISA March 27, IT Audit Process. Prof. Mike Romeu

IT Audit Process. Michael Romeu-Lugo MBA, CISA March 27, IT Audit Process. Prof. Mike Romeu Michael Romeu-Lugo MBA, CISA March 27, 2017 1 Agenda Audit Planning PS 1203 / PG 2203 Evidence PS 1205 / PG 2205 References: ITAF 3 rd Edition Information Systems Auditing: Tools and Techniques Creating

More information

Show notes for today's conversation are available at the podcast website.

Show notes for today's conversation are available at the podcast website. Information Compliance: A Growing Challenge for Business Leaders Transcript Part 1: Information Compliance Overload Julia Allen: Welcome to CERT's podcast series: Security for Business Leaders. The CERT

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Version: 4.0 Ratified by: NHS Bury Clinical Commissioning Group Information Governance Operational Group Date ratified: 19 th September 2017 Name of originator /author (s):

More information

Article from: CompAct. April 2013 Issue No. 47

Article from: CompAct. April 2013 Issue No. 47 Article from: CompAct April 2013 Issue No. 47 Overview of Programmatic Framework and Key Considerations Key elements Description Items to consider Definition and identification of EUCs The statement that

More information

EU General Data Protection Regulation, a new era in data protection

EU General Data Protection Regulation, a new era in data protection EU General Data Protection Regulation, a new era in data protection The European Union data privacy landscape is about to undergo dramatic change, with lasting enterprise wide implications for the way

More information

Experience Promontory.

Experience Promontory. Experience Promontory. WASHINGTON, DC ATLANTA BRUSSELS DUBAI HONG KONG LONDON MILAN NEW YORK PARIS SAN FRANCISCO SINGAPORE SYDNEY TOKYO TORONTO Promontory is a firm where you will be challenged from day

More information

MANAGE RISK IN THE LEGAL DEPARTMENT

MANAGE RISK IN THE LEGAL DEPARTMENT MANAGE RISK IN THE LEGAL DEPARTMENT Legal departments in financial institutions face a unique set of challenges in managing the risks associated with their use of outside counsel and other third-party

More information

BSA/AML Self-Assessment Tool. Overview and Instructions

BSA/AML Self-Assessment Tool. Overview and Instructions BSA/AML Self-Assessment Tool Overview and Instructions February 2018 1129 20 th Street, N.W. Ninth Floor Washington, DC 20036 www.csbs.org 202-296-2840 FAX 202-296-1928 2 Introduction and Overview The

More information

Privacy Policy RSL Ireland Ltd & Refrigeration Products (1999) Ltd

Privacy Policy RSL Ireland Ltd & Refrigeration Products (1999) Ltd Privacy Policy RSL Ireland Ltd & Refrigeration Products (1999) Ltd At RSL group we are very aware of the importance of managing the personal data that we hold, whether that is from a customer, a supplier

More information

Identity & Access Management Unlocking the Business Value

Identity & Access Management Unlocking the Business Value Identity & Management Unlocking the Business Value Accenture, its logo, and High Performance Delivered are trademarks of Accenture. Unlocking the Value of Identity and Management Defining the IAM challenge

More information

CORPORATE GOVERNANCE STATEMENT

CORPORATE GOVERNANCE STATEMENT CORPORATE GOVERNANCE STATEMENT In fulfilling its obligations and responsibilities to its various stakeholders, the Board is a strong advocate of corporate governance. This statement outlines the principal

More information

PERSONAL DATA SECURITY GUIDANCE FOR MICROENTERPRISES UNDER THE GDPR

PERSONAL DATA SECURITY GUIDANCE FOR MICROENTERPRISES UNDER THE GDPR PERSONAL DATA SECURITY GUIDANCE FOR MICROENTERPRISES UNDER THE GDPR The General Data Protection Regulation ( the GDPR ) significantly increases the obligations and responsibilities of organisations and

More information

Consulting Champions

Consulting Champions Consulting Champions Get GDPR Ready with SOLA Consulting A bespoke GDPR compliance offering covering people, process, technology and data www.solagroup.com SOLA Consulting is part of SOLA Group Ltd Contents

More information

General Data Protection Regulation and Episerver Learn how to leverage your organization s data to support GDPR compliance.

General Data Protection Regulation and Episerver Learn how to leverage your organization s data to support GDPR compliance. General Data Protection Regulation and Episerver Learn how to leverage your organization s data to support GDPR compliance. Page 2 What is General Data Protection Regulation? What The general data protection

More information

INTERNAL AUDIT OF PROCUREMENT AND CONTRACTING

INTERNAL AUDIT OF PROCUREMENT AND CONTRACTING OFFICE OF THE COMMISSIONNER OF LOBBYING OF CANADA INTERNAL AUDIT OF PROCUREMENT AND CONTRACTING AUDIT REPORT Presented by: Samson & Associates February 20, 2015 TABLE OF CONTENT EXECUTIVE SUMMARY... I

More information

Data Protection Management System for GDPR compliance - using COBIT. January 2018

Data Protection Management System for GDPR compliance - using COBIT. January 2018 Data Protection Management System for GDPR compliance - using COBIT January 2018 Contents Executive summary 2 Using COBIT to establish a Data Protection Management System for the GDPR 4 Tools for the

More information

Everything you always wanted to know about privacy impact assessments but where afraid to ask

Everything you always wanted to know about privacy impact assessments but where afraid to ask PON Congres 13 Oktober 2016 Everything you always wanted to know about privacy impact assessments but where afraid to ask Albert Holl Introduction Strategy, Governance, & People Digital security assessment

More information

Gearing up for GDPR Compliance - Practical steps to ensure compliance with the revised data protection regulation. Chris Bernau.

Gearing up for GDPR Compliance - Practical steps to ensure compliance with the revised data protection regulation. Chris Bernau. Gearing up for GDPR Compliance - Practical steps to ensure compliance with the revised data protection regulation. Chris Bernau October 2016 Agenda 1. What do we know about GDPR? 2. How should we approach

More information

Trusted KYC Data Sharing Standards Scope and Governance Oversight

Trusted KYC Data Sharing Standards Scope and Governance Oversight November 2017 Trusted KYC Data Sharing Standards Scope and Governance Oversight Handover Document Contents Preface... 3 Overview... 5 1 Sharing Capabilities and Interoperability... 7 1.1 Data Sharing Behaviour

More information

Corporate Governance Statement

Corporate Governance Statement - 2017 OVERVIEW The Board is responsible for the overall corporate governance of the Company, including establishing and monitoring key performance goals. It is committed to attaining standards of corporate

More information

General Data Protection Regulation (GDPR) Key considerations and implications for brokers

General Data Protection Regulation (GDPR) Key considerations and implications for brokers General Data Protection Regulation () Key and implications for brokers Contents at at 03 - did you know? 05 How to handle 07 Considerations for Broker Directors 08 General Data Protection Regulation ()

More information

Setting the Global HR Transformation Strategy

Setting the Global HR Transformation Strategy 2 Solution integration 3 Change analytics 1 What is truly meant by global Setting the Global HR Transformation Strategy 2 Solution Integration The days of a one size fits all HR service delivery model

More information