JM adopta soluciones para cumplir con el RGPD

La empresa nórdica JM adopta Data Sync Manager y Data Privacy Suite de EPI-USE Labs para desarrollar un programa eficaz de codificación y redacción de datos sensibles en sus sistemas SAP, con el fin de cumplir la normativa GDPR.

Labs_Coloured_blocks
2025__JM-1
Procesos empresariales eficaces para cumplir el RGPD
2025__JM-2
Eliminación automática de datos sensibles fuera del periodo de conservación
2025__JM-3
Reducción del riesgo: los sistemas de prueba ya no tienen datos sensibles
Play video
So welcome, Richard. So this conversation between the two of us is about the GDPR because it has obviously meant a lot to everybody in the SAP community. So thanks for wanting to share your experience with us. Could you present yourself and your role at JM? My name is Richard Wenell. I'm managing the IT part of JM, which a part of our business development corporate function. It's a quite small unit where we work a lot with external partners for development. So partnership with APUs is one of them. And, JM, what kind of company is it, for those who come from outside Scandinavia? Yeah. We were only based in Scandinavia. So we were a house construction company. We're based in Norway and in Finland, and then mainly in Sweden. We build houses for people to live in. That's our main business. The business starts with acquiring property, which is a very important part to actually acquire the right and then we keep the property for sometimes quite a long period of time, about thirty, forty years. Which means when we look into profitability in our business, we need to look long way back and then look on how the products developed and how we sell. Last two years has been a lot focused on what we call the aftermarkets, taking care of the houses, and taking care of what the people living in during the lifecycle of the house. So now we have the very long time frame from acquiring property quite long time ago until people here live there and hopefully they buy a new property from buy new house trunks. So with that kind of organization building private homes for people, what kind of privacy are you then into? What kind of data do you store in your SAP system? In the SAP system, it's mainly about our employees. There are about two thousand five hundred employees at the company. So that's one part which has been the main focus. Then even though we're selling the house to an individual, still the main transaction is to an organization. So therefore, there's not that difficult to take care of customer data. It's more about employee data and the employee data in the financial part of the system. So when the GDPR came, I know you have been working with the GDPR preparations for a long time. So could you describe the first steps that happened at JAM? I believe it's about five years ago since you took the first steps. Yep. It's a smile on my lips. It was I think it was in other companies as well, but it was you know, my company was panic. Everyone was running around, and everyone talked about the possible penalties of four percent and how it will affect. There was a lot of people running around. The first action was or interpretation of GDPR was we need to be compliant on operating systems. And perhaps that was a quite big mistake for us. It took some period of time until we understood that GDPR is not about versions of operating systems is about something completely different. But it was raised as highest priority very, very early, and so we got a lot of focus and attention on it. To start to work on it in a proper way. Are you then saying that this was a priority from upper management and not just something that you were working in within IT? So there was a top priority. We had, what do you call it, business development council, more or less and then this project was given top priority and then I should say unlimited budget, but we were allowed to start to take actions without having will order all the necessary means more or less. So it was really a top priority put most things addressed in parallel. So it's your corporate initiative and the corporate budget. Yes. So when the corporate projects started, What was the journey from the corporate initiative to you guys in IT being able to do something? Somebody must have told you what it wanted. Yes. So we have we had a since we're part of a business development, we, of course, were in control of the project and started the initiative. What we did was to define a model where we went to our business model. The business model is process based. So we have process owners in the business taking care of a different part of how we do it in different things. What they have not focused on earlier is the kind of what information do they have in their process, and how do they deal with that? So that was the process so that the methodology, we went to the process owners. We asked them to describe each of the processes, what information objects do they have, and data do they contain and how is the sensitivity of that data? So that ended up in quite a lot of documentation thinking about several hundred processes about what information objects and the sensitivity of them. And from there, we started to take action. I would say most actions were about cleaning data, taking that was taking care of the business or defining processes, how we should do things that actually document how we should deal with the data, then later. It came to actual requirements on us, on IT because they needed help with cleaning. They needed help to work with the routines for retention, routines for searching to find information about individuals, etcetera. So I would say that initially it was an IT project. And then when we did a retake, it took almost a year of just setting the processes and analysis analyzing the information before it turned back to an IT project again. I know we think that was the right way to do it. We should probably have started that way from the beginning. But now we also have the attention from the process owners from the business about that they own information, that they need to take care of it, they need to have routines, and they need to understand that. That's good. Would you describe that as a pleasant side effect of a GDPR the increased process awareness and the increased awareness of what data do we have, and why do we have them? Yes. A lot and there was a lot of old data that we could remove. And I think that was quite beneficial, and also to introduce the routine is to actually take care of the time to be more thorough when we introduce new data that, well, why should we keep this data? Are we allowed to keep the data? And that it's actually that someone feels responsible for it. That was, I shouldn't say, completely new, but quite new for a lot of some parts of the organization. Richard, does this mean that we are actually now talking about data privacy by designing meaning that when you start a process or a new system, you think privacy from the very beginning. Yeah. I know if I talk a little bit, but what happened after GDPR was that we needed to focus on have focused a lot of information security in general. So in that part, we take took all the stuff done in GDPR, but we also introduced information security routines in general. So now when we're starting our projects, we have frameworks for how to do information, sensitivity analysis how to do risk analysis. And from there, actually, coming to requirements on the IT supporting the sensitivity from a complete information security perspective. So GDPR is now becoming I shouldn't say just a small part, but there's only one part of it. And look initially looking on personal data. We're now looking on all our business data. Yeah. So that's -- Mhmm. -- a difference. And it's so it becomes more of a privacy by design. Yes. So the governance that you have around GDPR, is that now -- is that a separate governance for the GDPR or is it a general governance around data security and information security? It's still both, I would say, where we introduced a new role as a part of GDPR, as a risk officer, works together in as a corporate function. And he's responsible for all the GDPR routines that they are in place and to monitor that and to or did that also internally at JM. In parallel, we've built up the information security model, and they are I would say merging right now. I would say the information security methodologies is broader, wider, and the more thorough which means the GDPR processes will become much easier, I would say. So the risk officer from a GDPR perspective we'll have a much easier job. But the rest of the organization are much more involved now, and we don't do anything without clicking on the information activity on the information and how it should be dealt, and the availability of it. So it's a lot of things. Going on. But in general, it's from a top management point of view. This isn't the word issue for us. I reported the word once or twice every year now, how we progress in these areas. Oh, interesting. Yes. Said that from the very beginning, it was mainly about employee data. But you also said a bit later that you are now looking at business data in general, have you defined all the areas, I mean, areas outside the employee data? Yes. Especially when it comes to production, we're working building houses. And if a construction site is not producing during a day or during an hour or even ten minutes, we know how much the cost is. Could be many people involved and a lot of equipment that doing nothing. And we have that measure, and we understand the delay there. So even though they think they construct houses with physical things. They're still depending on a lot of IT things. So when we ask them, what happens if this system is down for an hour, what happens if you can't order material for a day, then things start to become urgent and important and actually very business critical. Did this whole process give you any surprises as to the data you hold or the governance around data privacy? Perhaps not many more than that. We've stored a lot of data over time, a laptop of an of data. And the initial processes when we removed data with huge amount of data, especially if you look on employee data, that was like fifty percent of the data more or less, I think, we were removed. So the necessity of storing some data been probably one of the lessons learned that we don't need all the data we have or had. So I think that's important. And also perhaps a piece of quality of the data, of course, because when you start to introduce we did with the app just starting to use rubles, where you search for data and then trying to remove it or And then if you don't find it, then you see that the quality data is it's poor. You need to start to work with the quality data, which also is a good thing because now we can use the data for better things. So this is how things are now. What kind of initiatives do you see going forward that you're considering about security in general and data security and protection. For us, it's been a lot of methodology of politics, I would say. Still I'm responsible for IT. I want more security mechanisms on a night eleven right now. So that's what we're focusing on right now. We are taking care of our operation, and increasing the level of security matters. But it has been a journey to come there because we could have done it just on chance. But now we know what requirements are. There are. So we need to what level we need to understand what level we need to come to. And we know how to measure it. We know I get followed up by the board on every year on where I am on that matter. So This year is focused on the technology part to actually making sure we have a secure environment. But then, in parallel, it's training, of course, training of employees. That's where most things start with someone clicking on the link. Of course, as we, as everyone else, probably have had different threats and things happening. We've been cross my fingers, but we've been lucky. So far, no really, really dangerous things, but we will have the directed attack attacks to us, and if people clicked on the wrong links, and let them into the network, and then things happen. So training and training is also a very, very important part. We work with micro training with all employees. So would say, I don't know how often it is, but it's like every second week people get to go through a micro training in information security. Interesting. So now what do you No. No. That's that. I think those are the those two main areas right now is the technological protection, making sure our operation environment is really more secure than it has been, and training on employees. That's the focus for this year, and perhaps, in the next year as well. Mhmm. Thank you, Richard, for sharing all this with us. Much appreciated. Thank you. No problem. It's been a journey together with you, but then I think that the benefits for JEM has been the possibility to actually keep data. As I mentioned, we have these very long business transactions from acquiring property at thirty years back until aftermarket. And if we would have needed to remove data, that would have been not that good from business analysis point of view. The key thing here has been to keep data to be able to have all the data up and remove all the sensitive parts of it. Mhmm. That's basically a great benefit. Thank you. Thank you.

La clave aquí ha sido que podemos conservar todos nuestros datos, pero eliminando todas las partes sensibles de los mismos. Las soluciones de EPI-USE Labs nos han aportado grandes beneficios.

Richard Wenell, Jefe del departamento de informática, JM
cita-testimonio

Los retos de la protección de datos personales sensibles

En 2015, JM se enfrentaba al reto de proteger la integridad de los datos personales y evitar las sanciones del Reglamento General de Protección de Datos (RGPD), en los siguientes ámbitos:

  • Información y transacciones de los clientes
  • Servicio de atención al cliente
  • Información de los empleados
  • Relaciones y transacciones con proveedores
  • Marketing y comunicación

El equipo de JM decidió realizar algunos cambios positivos para cumplir el GDPR, en particular

  • centrarse en los propietarios de las empresas en lugar de en los sistemas informáticos
  • financiar mejoras en la seguridad de la información
  • proporcionar herramientas informáticas útiles
  • hacer del proyecto de mejora una prioridad para todos.

EPI-USE Labs participó desde el principio en el proyecto, desarrollando requisitos y especificaciones de forma interactiva.

Richard Wenell, Jefe del departamento de informática, JM
cita-testimonio

Soluciones para gestionar y redactar datos personales

JM seleccionó Object Sync™ y Data Secure™, parte de la suite Data Sync Manager™ (DSM), para copiar y codificar subconjuntos de datos con fines de prueba y formación. Al reducir su huella de datos en entornos que no son de producción, pueden eliminar los datos personales de sus entornos de prueba. Además, para el cumplimiento del GDPR es importante mostrar la protección de datos por diseño y por defecto. Mediante el uso de DSM para actualizar los datos en el sistema de no producción, JM puede demostrar este principio.

JM ahora también utiliza Data Disclose™, Data Redact™ y Data Retain™, parte de la suite Data Privacy. Data Disclose se utiliza para las solicitudes de acceso del sujeto (para cumplir con el artículo 15 del GDPR). El equipo de JM es capaz de buscar en sus sistemas SAP y proporcionar un documento PDF de marca que detalla los datos de la persona almacenados en sus sistemas. Data Redact, que se utiliza para suprimir los datos que identifican a una persona (de conformidad con el artículo 17 del RGPD y el derecho de supresión), permite a JM responder a cualquier solicitud de supresión. También permite a JM redactar cualquier dato personal en sus sistemas SAP que quede fuera de sus políticas de retención de datos, de forma regular y proactiva.

JM se asoció con EPI-USE Labs para ser un cliente de ampliación de Data Retain, que proporciona una interfaz de usuario visual para configurar y ejecutar reglas de retención, así como envíos a Data Redact para las claves que deben redactarse.

EPI-USE Labs también pudo ayudar con la limpieza masiva inicial de varios conjuntos de datos, incluidos clientes, proveedores, empleados y documentos contables, utilizando sus funciones de optimización del entorno del sistema.

Nuestras transacciones comerciales pueden durar mucho tiempo -algunas más de 30 años- y queríamos conservar los datos, eliminando al mismo tiempo las partes sensibles que no necesitábamos. La suite Data Privacy de EPI-USE Labs nos permitió hacerlo.

Richard Wenell, Jefe del departamento de informática, JM
cita-testimonio

Cumplimiento continuo del RGPD

JM ha podido utilizar las soluciones de EPI-USE Labs para respaldar sus procesos empresariales y cumplir con las exigencias del GDPR en áreas en las que los datos estaban en riesgo, y en un breve plazo de tiempo:

  • Un enfoque proactivo elimina los datos sensibles automáticamente, tan pronto como están fuera de su período de retención.
  • Los sistemas de prueba ya no contienen datos sensibles, lo que reduce el riesgo de infracciones por parte de usuarios internos o socios que acceden a entornos que no son de producción.

El siguiente paso de JM en su camino hacia el GDPR es implantar rutinas de seguridad de la información en las operaciones. En colaboración con EPI-USE Labs, tienen previsto establecer programas de retención en sus sistemas SAP.

Con el enfoque de EPI-USE Labs, podemos anonimizar y redactar datos sensibles en lugar de archivarlos, lo que significa que las transacciones comerciales pueden permanecer en el sistema sin estar relacionadas con una persona identificable. Ahora, al iniciar los proyectos, disponemos de marcos para realizar análisis de sensibilidad y riesgo de la información, y de ahí se derivan los requisitos del lado informático, incluida la sensibilidad de los datos: la perspectiva completa de la seguridad de la información.

Richard Wenell, Jefe del departamento de informática, JM
cita-testimonio

Industria: Ingeniería, construcción y operaciones

Solución: Data Sync Manager (DSM), Data Privacy Suite

Acerca de JM

JM es uno de los principales promotores de viviendas y zonas residenciales de la región nórdica. Sus operaciones abarcan la producción de viviendas nuevas, con especial atención a las áreas metropolitanas en expansión y las ciudades universitarias de Suecia, Noruega y Finlandia.