Mind the Gap: GDPR Ahead. Rakesh Sancheti. Author. July Vice President and Business Head - Analytics, Europe and Nordic

Similar documents
Salesforce Lightning Migration

Mosaic Decisions. LTI's Advanced Analytics Platform for Insurance

Improve Cash Flows and Drive Sharper Decision Making with Cognitive Accounts Receivable (AR) Analytics

Insurance Underwriting. in the age of Data Super-Abundance

Automating Data Intake Process in Commercial Underwriting Author : Amit Unde

Orchestrating an Effective Operating Model for RPA. Guidelines for CxOs

PERSPECTIVE. GDPR - An industry and geography agnostic regulation. Abstract

Packing Systems: A Critical part of OEM Supply Chain Authors: Anuradha Katti & Rehbar Rahman

Reimagining Fuel Retailing. with Customer 360 & Store 360

Enabling Agility in the Manufacturing Industry. Author Sulagna Roy

Internet of Things and Customer Relationship Management Dinesh Khedkar

Data protection in light of the GDPR

Automation Through Robots

Five Pillars for GDPR Compliance with Talend Talend

Predictive Analytics and Standardization in Testing of Insurance COTS Authors: Atul Kumar Jain & Sumit Karpate

SHARP (SharePoint Health Assessment and Recommendation Program) Author Harsh Gautam Singh

Accelerate GDPR compliance with the Microsoft Cloud Henrik Mønsted

GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges

Serverless Data Warehouse and Analytics Platform Authors : Himansu Sekhar Tripathy, Deep Sharma

Prepare for GDPR today with Microsoft 365

Ready for the GDPR, Ready for the Digital Economy Fast-Track Your Midsized Business for the Digital Economy While Addressing GDPR Requirements

4/26. Analytics Strategy

Dealing with the EU Data Protection Regulation in Practice. William Long, Partner Sidley Austin LLP February 11, 2016

Automated Tracking Solution Authors: Amit Mehetre & Nilesh Pawar

Accelerating Cloud Value through Analytics

SOLUTION BRIEF EU GENERAL DATA PROTECTION REGULATION COMPLIANCE WITH RSA ARCHER

EU General Data Protection Regulation: are you ready?

The new EU data protection Regulation: The business opportunity beyond legal compliance. Kalliopi Spyridaki Chief Privacy Strategist, Europe

SOLUTION BRIEF HELPING ADDRESS GDPR CHALLENGES WITH RSA SECURITY ADDRESSING THE TICKING CLOCK OF GDPR COMPLIANCE

IBM Collaboration Solutions Readiness for GDPR IBM Corporation

SOLUTION BRIEF HELPING PREPARE FOR RISK ASSESSMENT & COMPLIANCE CHALLENGES FOR GDPR WITH RSA SECURITY ADDRESSING THE TICKING CLOCK OF GDPR COMPLIANCE

GDPR and Microsoft 365: Streamline your path to compliance

EU General Data Protection Regulation: Are you ready?

Integrated Social and Enterprise Data = Enhanced Analytics

General Data Protection Regulation and Episerver Learn how to leverage your organization s data to support GDPR compliance.

The General Data Protection Regulation (GDPR): Getting in good shape for the deadline Copenhagen, 19 September 2017 Janus Friis Bindslev Partner,

5-Step Guide For GDPR Compliance

Strong Q4 leads to double digit revenue growth of 10% in FY17; Net profit for FY17 grows at 16% YoY

Turn Noise into Actionable Insight with TrueSight Intelligence to Meet GDPR Requirements

GDPR. Are you ready for the GDPR countdown?

Open Banking PSD2, GDPR and the American Merchant

Data rich and regulation wary

EU General Data Protection Regulation in the digital age: Are you ready?

A PATH TO GDPR READINESS WHITE PAPER

General Data Protection Regulation (GDPR)

PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER

EU General Data Protection Regulation, a new era in data protection

Ventana Research Marketing Research in 2017

Ensure GDPR Compliance with Avaali Solutions Avaali. All Rights Reserved 1

GDPR journey: from ready to compliant GDPR survey results

GDPR 7 questions you should ask technology vendors about GDPR

THE FIRST THREE STEPS TO GETTING GDPR READY

Working toward GDPR compliance. Insights from a SAS survey and an end-to-end approach

Consulting Champions

A PRACTICAL GUIDE FOR HOW AN ADVERTISER CAN PREPARE FOR GDPR JANUARY 2018

Preparing for the General Data Protection Regulation (GDPR)

EU General Data Protection Regulation

General Data Protection Regulation Philippe Roggeband. Business Development, Manager, GSSO EMEAR

Enterprise Collaboration in Hi-Tech Past, Present & Future Authors: Rahul Bansal & Dan Kidd

Master Data Management

Customer Data Protection. Temenos module for the General Data Protection Regulation (GDPR)

USTGlobal. Robotic process automation in retail sector: Unleash potential benefits

Welcome & Opening Lisa Oreland Murby Regional Sales Director, Informatica

A guide to GDPR the effect on all UK organisations

Capgemini Cloud Platform. Migrate, operate, and innovate every aspect of your business in the cloud

TIAA-CREF, Our Journey to Enhanced Data Quality

GDPR: what you need to know

Planning for the General Data Protection Regulation

Praticamente GDPR Spike Reply PART 1

More information at cventconnect.com/europe/mobileapp

PNC8.2. Transforming today, taking care of tomorrow

Digital Transformation Begins with Infrastructure Automation

2017 IBM Corporation. IBM s Journey to GDPR Readiness

Accelerate Your Response to the EU General Data Protection Regulation (GDPR) with Oracle Cloud Applications

Developing a data culture across the enterprise. Marc Mullan VP Data & Analytics 18 th October 2018

OneTrust takes strategic focus on global privacy management

Guidance on the General Data Protection Regulation: (1) Getting started

The Insight Driven Organization

GDPR: What Every MSP Needs to Know

The General Data Protection Regulation (GDPR)

Next Generation Services for Digital Transformation: An Enterprise Guide for Prioritization

What is GDPR and Should You Care?

GDPR in SAP. June, Igor Gregurec

Rapid Delivery Predictable Outcomes Your SAP Data Partner

The Next Level Industrial Revolution. Top 10 Business Opportunities in Manufacturing IoT

EU General Data Protection Regulation (GDPR) Point of View for ERP and HRMS Operations. For private circulation only.

The ecommerce Guide to GDPR. How to Ensure Compliance and a Competitive Edge

Accelerate GDPR compliance with the Microsoft Cloud Samuel Marín Sr. Sales Solutions Specialist

In search of the Holy Grail?

CAPTIFY S GDPR READY POSITION: + + EU REGULATION 25TH MAY 2018 UPDATE TO DPD PERSONAL DATA CONSENT

Digital and Technology. Providing solutions for a more connected sustainable world.

George Lawrie Vice President & Principal Analyst at Forrester Research Ltd

IT Strategic Plan Portland Community College 2017 Office of the CIO

General Data Protection Regulation (GDPR) New regulation for the protection of data

EU-GDPR and the cloud. Heike Fiedler-Phelps January 13, 2018

GDPR Compliance Checklist

What you need to know. about GDPR. as a Financial Broker. Sponsored by

GDPR: Centralize Unstructured Data Governance Across On-premises and Cloud

Cognitive IoT unlocking the data challenge

General Data Privacy Regulation: It s Coming Are You Ready?

Transcription:

Author Rakesh Sancheti Vice President and Business Head - Analytics, Europe and Nordic July 2017

The regulatory environment has become increasingly complex, with new regulations being introduced across the world. Lately, there has been renewed focus in strengthening regulations around data, reporting, and cyber security. One of the most significant regulations affecting all the organizations in possession of European citizens personal data, is the EU General Data Protection Regulation (GDPR) coming into effect on May 25, 2018. The GDPR, which was adopted in May 2016, imposes a radical, much tougher data protection regulatory framework across the EU, over the processing of personal data. It covers every processing operation that can be carried out on personal data, irrespective of whether it is undertaken by automated or non-automated means, or whether done actively or passively. It defines the increased rights of EU citizens (Data Subjects), around the privacy and protection of their personal data. The regulation also specifies the increased responsibility for any organisation or individual (Data Controller) that is responsible for storage and processing of EU citizens personal data, while hiring or surveying them, buying selling, or marketing a service / product, etc. Data controllers have to stick to the purpose for which the data has been acquired, minimize the amount of data held, keep it accurate, secure and confidential at all times. They then must delete or destroy it when the purpose for which the data was obtained or created has been fulfilled, or if the consent to use it has been withdrawn. Failure to comply with this regulation can result in fines of up to 4% of the global revenue.

The fundamental cornerstones of GDPR regulation Assess Personal Data Classify organisational data Identify compliant data Protect Personally Identifiable Information Protect data in use, in transit, and at rest Ensure Privacy by Design which will involve rethinking the way PII, PHI, ephi, and PCI data is handled Address the requirements of the GDPR compliance in a methodical and modular fashion Enable the Data Subject rights Erase the data once the purpose is complete and cease its dissemination Develop interoperable formats that enable Data Portability Notify breaches within 72 hours Carry out Data Protection Impact assessments Formulate measures to address any high risks that have been identified Appoint a Data Protection Officer Appoint a Data Protection Officer (DPO) at both Data Controller and Data Processor levels

GDPR Implementation: How Confident are the Organizations? According to a recent global survey, a staggering 90% of the organizations believe that the GDPR will impact the way they collect, use, and process personal data. Only 46% of the organizations are confident to be ready by the go-live date; and most importantly, 88% of the organizations accepted that the GDPR has exposed holes in their IT architecture, and hence, they consider this as an opportunity to overcome their technological challenges, thus contributing towards their IT transformation programs. Our conversations with European and Nordic customers have highlighted the challenges they are facing, to rightly fulfil the complex regulatory demands of the GDPR, and in parallel, manage the data deluge and technology disruption. They are looking out for help in driving efficient risk management across the value chain of their business landscape, and continue to move upwards in the technology maturity continuum. Route to the GDPR: The Key to Success To implement GDPR successfully, organizations need to follow a three step systematic approach that begins with a maturity assessment and finding the gaps, followed by any application and architecture related changes to bridge those gaps. In the later stage, it includes continuous execution of automated processes, to ensure continued improvement and prevention of breaches.

Find the Gap: in order to protect data, the organizations first need to know where it is, and determine its risk profile. It s easier said than done. Most organizations struggle to gain visibility into their data assets, and thus have to invest in data discovery and classification related initiatives. The first step toward the GDPR compliance is to conduct a Privacy Impact Assessment to understand the data landscape, and how data flows inside and outside the organization. This will enable to better assess information risk profile, classify data, and identify lineage. Additionally, this exercise will locate the gaps in an organization s processes, systems, oversight mechanisms, and skills. Once this has been done, the next step is to evaluate the current risk mitigation strategies. This includes, for example, reviewing the implementation of security controls. Firms must also use the gap analysis phase to estimate the approximate budget required to successfully implement the GDPR program. Bridge the Gap: Once the assessment has been completed, organizations must define data governance best practices, policies, data stewardship and establish a Data Governance Office. The current information architecture should also be looked at, with focus on bridging gaps around managing data subject consent, access & rights, Privacy by Design & Privacy by Default, and data pseudonymization & anonymization. Additionally, it is necessary to have insight into the physical location of data and where it is processed, including cross-border transfers. Therefore, organizations must assess master data residency, data storage management (backup and recovery policies), and the use of cloud Infrastructure as a Service (IaaS) & Platform as a Service (PaaS). In addition, organizations must deploy security controls compliant with the GDPR. For example, when encrypting data, privacy and security teams must pay attention to how the encryption keys are being managed. Prevent the Gap: GDPR is not a one-time regulation. It is a continuous process which requires defining a continuous feedback loop for ongoing compliance and improvement. Metrics that track the achievements of data privacy and security programs, along with self-service BI reports and real-time dashboards for KPI tracking need to be in place. With the deadline to become GDPR-compliant approaching fast, organizations need to act now. They need to know which IT applications and business processes possess personal data; why they have it; how they are using it; who is accessing it; how they are protecting it; if they have the right technology infrastructure to be able to demonstrate end-to-end data lineage to an external regulator, etc. To conclude, treating GDPR as merely a compliance is the first sign of non-compliance. The task at hand is surely overwhelming, but can be managed if we treat this as an embedded and holistic set of interventions across the applications and systems landscape.

This has been demonstrated below: 3 Step Route to GDPR Find the Gap Bridge the Gap Prevent the Gap GDPR Readiness Assessment Data Management Maturity Personal Data Inventory Data Breach Risk Assessment & Exposure Data Governance Policy (Re) architect Data Landscape Workflows & controls Data Masking Dissemination & Standards MDM Metadata hub Data Security Enablement Performance & Data Protection Rules Testing Intelligent Breach Assistance Prevent security breaches Advanced analytics GDPR Insight Data Breach Monitoring Real time Dashboards Self-service BI portal Data Subject Rights - queue / status Metrics & Threshold monitoring

About the Author Rakesh Sancheti Rakesh Sancheti is Area Vice President at LTI, and Business Head for Analytics & Information Management Practice for Europe and Nordic. He is a Data analytics practitioner with 11+ years of hands on experience in helping customers co-create Data-driven enterprise, by leveraging Data analytics as fuel in their digital transformation journey. He is well-versed in defining Data strategy, Information architecture and Business use cases for Big data analytics across industry value chain, to deliver meaningful business insights, and better business outcomes at speed and scale. He has worked with global clients to deliver projects across Data to Insight value chain - Data Integration, Data Management, Business Intelligence, Big Data, Data Science and Machine Learning. LTI (NSE: LTI) is a global technology consulting and digital solutions company, helping more than 250 clients succeed in a converging world. With operations in 27 countries, we go the extra mile for our clients and accelerate their digital transformation with LTI s Mosaic platform, enabling their mobile, social, analytics, IoT and cloud journeys. Founded 20 years ago as the information technology division of the Larsen & Toubro group, our unique heritage gives us unrivaled real-world expertise to solve the most complex challenges of enterprises across all industries. Each day, our team of more than 20,000 LTItes enable our clients to improve the effectiveness of their business and technology operations, and deliver value to their customers, employees and shareholders. Find more at www.lntinfotech.com or follow us at @LTI_Global info@lntinfotech.com www.lntinfotech.com