Get ready for your data privacy audits: Lessons learnt

Labs_Coloured_blocks
 


In this blog, data privacy expert James Watson shares his insights on which companies are more likely to face data privacy audits and compliance reviews, and how companies should address audits. He explains that businesses should engage with auditors, and assess their largest privacy compliance challenge realistically. He also highlights that PII may require a documented compliance statement, rather than simply defaulting to deleting information. James has a functional and business background of over 20 years, and is responsible for the global line of business for EPI-USE Labs' data privacy and SAP IS-* Solutions, supporting all regions for these complex requirements.

SUMMARY: In this blog, James Watson shares insights on which companies are more likely to face data privacy audits and compliance reviews, and how companies should address audits. He explains that businesses should engage with auditors, and assess their largest privacy compliance challenge realistically. He also highlights that Personally Identifiable Information may require a documented compliance statement, rather than simply defaulting to deleting information.

Our data privacy expert James Watson gives us his insights into data privacy audits, engaging with auditors, and assessing how to deal with Personally Identifiable Information (PII). 

James has a functional and business background of over 20 years, and is responsible for the global line of business for EPI-USE Labs' data privacy and SAP IS-* Solutions, supporting all regions for these complex requirements. His history includes SAP specialisms in non-production data management and anonymisation, Production data removal or redactions, System Landscape Optimisation (SLO) and SAP industry solutions.

 

Which companies are targets for data privacy audits and compliance reviews?

"The trend that we've seen is that the target for audits and compliance reviews has very much been in the business to customer markets, where there is a higher volume of personal data. So that's not to say that smaller companies and the B2Bs and the HCM-only companies wouldn't get audited and reviewed. But we quite often find that the initial focus is around the larger utility retailers and telecoms that do contain a huge amount of personal information."

How can we pass our data privacy audit?

"I'd suggest that it's important to not be afraid of an audit. Actually bring the auditors in and get the feedback from them on what is your largest privacy compliance challenge. It may not be a technical one. It may be a business process one, or a paper management process.

If you then invest a huge amount in a technical solution, but actually that's not where your largest risk and concern is, obviously you've not wasted money, but maybe invested in the wrong order for your compliance. So actually engage with the auditors, go to them and say, can we do data privacy impact assessments? Get their feedback and knowledge.

The large auditors all provide these services to be able to help inform your business on the challenges that they're going to face. And do that before it's the official auditors being promoted by the government central body, etc, that's actually enforcing those privacy laws."

The compromise: business needs versus data privacy compliance officer

"The other recommendation is very much around the priority of the business.

I've dealt with quite a few privacy officers that have faced a high challenge from their business compatriots. Where the business team is very nervous about removing anything, the privacy compliance officer is saying: we have to remove everything. We quite often find that we have to find the middle ground between those two. It's absolutely about a compromise."

Do the data privacy laws dictate what is considered PII?

"The data privacy laws don't actually dictate what is Personally Identifiable Information (PII).

We have a lot of conversations around salary data. There is a huge concern with payroll teams of not having the real salary information to be able to actually test the payroll. And in most instances, clients also want to make sure their payroll is running because if they can't pay their people, they're going to lose their people and then they're going to lose their business. So it is a pivotal process that is highly important.

And people are very, very concerned to be able to say, but what if it gets leaked? Or what if somebody internally in a test system can go and identify what the salary of the CEO is compared to what their salary is? Now, there is some risk around that, and it's an internal risk to the business. There isn't actually a privacy compliance risk in that. The salary by itself is not personally identifiable to the individual. You would need other information about the name, the address, telephone numbers to be able to actually connect that to a person, without the knowledge in between of knowing that that employee number happens to be the CEO.

So in those cases, it does have to become an internal decision that the business is going to make on their compliance statement."

Are there justifiable business reasons NOT to delete personal data?

"In terms of PII, there is sort of a rule of thumb that's been adapted to that if there are three points of personal data that you can identify back to an individual, that is potentially a breach if that information was to leak. But for example, in the utilities industry, the address is so closely linked to the metering that's associated, and therefore to all of the other parties that they interact with regularly, that if you were to scramble the addresses, you would actually present a real issue in industry testing or in Production; the address is static, and it will have multiple people that live at that address. So if we were to redact and delete that address, it's no longer there for the next person that's just moved in. So there can be industry and business reasons why certain personal data is not able to be processed."

Document your compliance logic

"That's not something to be afraid of. It needs to be something that you work into your compliance statement, that you document it, you recognise it and you audit it and say, we are aware this is personal data, but this is the reason why we're not removing it. And make sure that that is written into your privacy compliance documentation. And that will then allow you to meet the compliance laws without actually needing to remove the data. So don't always just default to delete. Actually do that review and say, there is a justification – legal or otherwise – that we can use as a compliance statement, rather than coming up with a very complex technical solution to what could be a simple business answer."

How can EPI-USE Labs help us to pass audits?

At EPI-USE Labs, we offer a SAP data privacy assessment service which can help you to understand and identify your PII, and feel equipped to address compliance audits.

 

Rosy Marchand

Rosy's role at EPI-USE Labs is Marketing/Proposals Consultant and Editor, working closely with marketing and sales leaders. With more than 25 years of experience in people and proposal leadership, communications, content management, events and social media, she believes that effective communication and collaborating with the right people is integral to project success.

Prev Home Back to top
Get ready for your data privacy audits: Lessons learnt
6:31

Tags:

Recommended: