So welcome, Richard. So this conversation between the two of us is about the GDPR because it has obviously meant a lot to everybody in the SAP community. So thanks for wanting to share your experience with us. Could you present yourself and your role at JM? My name is Richard Wenell. I'm managing the IT part of JM, which a part of our business development corporate function. It's a quite small unit where we work a lot with external partners for development. So partnership with APUs is one of them. And, JM, what kind of company is it, for those who come from outside Scandinavia? Yeah. We were only based in Scandinavia. So we were a house construction company. We're based in Norway and in Finland, and then mainly in Sweden. We build houses for people to live in. That's our main business. The business starts with acquiring property, which is a very important part to actually acquire the right and then we keep the property for sometimes quite a long period of time, about thirty, forty years. Which means when we look into profitability in our business, we need to look long way back and then look on how the products developed and how we sell. Last two years has been a lot focused on what we call the aftermarkets, taking care of the houses, and taking care of what the people living in during the lifecycle of the house. So now we have the very long time frame from acquiring property quite long time ago until people here live there and hopefully they buy a new property from buy new house trunks. So with that kind of organization building private homes for people, what kind of privacy are you then into? What kind of data do you store in your SAP system? In the SAP system, it's mainly about our employees. There are about two thousand five hundred employees at the company. So that's one part which has been the main focus. Then even though we're selling the house to an individual, still the main transaction is to an organization. So therefore, there's not that difficult to take care of customer data. It's more about employee data and the employee data in the financial part of the system. So when the GDPR came, I know you have been working with the GDPR preparations for a long time. So could you describe the first steps that happened at JAM? I believe it's about five years ago since you took the first steps. Yep. It's a smile on my lips. It was I think it was in other companies as well, but it was you know, my company was panic. Everyone was running around, and everyone talked about the possible penalties of four percent and how it will affect. There was a lot of people running around. The first action was or interpretation of GDPR was we need to be compliant on operating systems. And perhaps that was a quite big mistake for us. It took some period of time until we understood that GDPR is not about versions of operating systems is about something completely different. But it was raised as highest priority very, very early, and so we got a lot of focus and attention on it. To start to work on it in a proper way. Are you then saying that this was a priority from upper management and not just something that you were working in within IT? So there was a top priority. We had, what do you call it, business development council, more or less and then this project was given top priority and then I should say unlimited budget, but we were allowed to start to take actions without having will order all the necessary means more or less. So it was really a top priority put most things addressed in parallel. So it's your corporate initiative and the corporate budget. Yes. So when the corporate projects started, What was the journey from the corporate initiative to you guys in IT being able to do something? Somebody must have told you what it wanted. Yes. So we have we had a since we're part of a business development, we, of course, were in control of the project and started the initiative. What we did was to define a model where we went to our business model. The business model is process based. So we have process owners in the business taking care of a different part of how we do it in different things. What they have not focused on earlier is the kind of what information do they have in their process, and how do they deal with that? So that was the process so that the methodology, we went to the process owners. We asked them to describe each of the processes, what information objects do they have, and data do they contain and how is the sensitivity of that data? So that ended up in quite a lot of documentation thinking about several hundred processes about what information objects and the sensitivity of them. And from there, we started to take action. I would say most actions were about cleaning data, taking that was taking care of the business or defining processes, how we should do things that actually document how we should deal with the data, then later. It came to actual requirements on us, on IT because they needed help with cleaning. They needed help to work with the routines for retention, routines for searching to find information about individuals, etcetera. So I would say that initially it was an IT project. And then when we did a retake, it took almost a year of just setting the processes and analysis analyzing the information before it turned back to an IT project again. I know we think that was the right way to do it. We should probably have started that way from the beginning. But now we also have the attention from the process owners from the business about that they own information, that they need to take care of it, they need to have routines, and they need to understand that. That's good. Would you describe that as a pleasant side effect of a GDPR the increased process awareness and the increased awareness of what data do we have, and why do we have them? Yes. A lot and there was a lot of old data that we could remove. And I think that was quite beneficial, and also to introduce the routine is to actually take care of the time to be more thorough when we introduce new data that, well, why should we keep this data? Are we allowed to keep the data? And that it's actually that someone feels responsible for it. That was, I shouldn't say, completely new, but quite new for a lot of some parts of the organization. Richard, does this mean that we are actually now talking about data privacy by designing meaning that when you start a process or a new system, you think privacy from the very beginning. Yeah. I know if I talk a little bit, but what happened after GDPR was that we needed to focus on have focused a lot of information security in general. So in that part, we take took all the stuff done in GDPR, but we also introduced information security routines in general. So now when we're starting our projects, we have frameworks for how to do information, sensitivity analysis how to do risk analysis. And from there, actually, coming to requirements on the IT supporting the sensitivity from a complete information security perspective. So GDPR is now becoming I shouldn't say just a small part, but there's only one part of it. And look initially looking on personal data. We're now looking on all our business data. Yeah. So that's -- Mhmm. -- a difference. And it's so it becomes more of a privacy by design. Yes. So the governance that you have around GDPR, is that now -- is that a separate governance for the GDPR or is it a general governance around data security and information security? It's still both, I would say, where we introduced a new role as a part of GDPR, as a risk officer, works together in as a corporate function. And he's responsible for all the GDPR routines that they are in place and to monitor that and to or did that also internally at JM. In parallel, we've built up the information security model, and they are I would say merging right now. I would say the information security methodologies is broader, wider, and the more thorough which means the GDPR processes will become much easier, I would say. So the risk officer from a GDPR perspective we'll have a much easier job. But the rest of the organization are much more involved now, and we don't do anything without clicking on the information activity on the information and how it should be dealt, and the availability of it. So it's a lot of things. Going on. But in general, it's from a top management point of view. This isn't the word issue for us. I reported the word once or twice every year now, how we progress in these areas. Oh, interesting. Yes. Said that from the very beginning, it was mainly about employee data. But you also said a bit later that you are now looking at business data in general, have you defined all the areas, I mean, areas outside the employee data? Yes. Especially when it comes to production, we're working building houses. And if a construction site is not producing during a day or during an hour or even ten minutes, we know how much the cost is. Could be many people involved and a lot of equipment that doing nothing. And we have that measure, and we understand the delay there. So even though they think they construct houses with physical things. They're still depending on a lot of IT things. So when we ask them, what happens if this system is down for an hour, what happens if you can't order material for a day, then things start to become urgent and important and actually very business critical. Did this whole process give you any surprises as to the data you hold or the governance around data privacy? Perhaps not many more than that. We've stored a lot of data over time, a laptop of an of data. And the initial processes when we removed data with huge amount of data, especially if you look on employee data, that was like fifty percent of the data more or less, I think, we were removed. So the necessity of storing some data been probably one of the lessons learned that we don't need all the data we have or had. So I think that's important. And also perhaps a piece of quality of the data, of course, because when you start to introduce we did with the app just starting to use rubles, where you search for data and then trying to remove it or And then if you don't find it, then you see that the quality data is it's poor. You need to start to work with the quality data, which also is a good thing because now we can use the data for better things. So this is how things are now. What kind of initiatives do you see going forward that you're considering about security in general and data security and protection. For us, it's been a lot of methodology of politics, I would say. Still I'm responsible for IT. I want more security mechanisms on a night eleven right now. So that's what we're focusing on right now. We are taking care of our operation, and increasing the level of security matters. But it has been a journey to come there because we could have done it just on chance. But now we know what requirements are. There are. So we need to what level we need to understand what level we need to come to. And we know how to measure it. We know I get followed up by the board on every year on where I am on that matter. So This year is focused on the technology part to actually making sure we have a secure environment. But then, in parallel, it's training, of course, training of employees. That's where most things start with someone clicking on the link. Of course, as we, as everyone else, probably have had different threats and things happening. We've been cross my fingers, but we've been lucky. So far, no really, really dangerous things, but we will have the directed attack attacks to us, and if people clicked on the wrong links, and let them into the network, and then things happen. So training and training is also a very, very important part. We work with micro training with all employees. So would say, I don't know how often it is, but it's like every second week people get to go through a micro training in information security. Interesting. So now what do you No. No. That's that. I think those are the those two main areas right now is the technological protection, making sure our operation environment is really more secure than it has been, and training on employees. That's the focus for this year, and perhaps, in the next year as well. Mhmm. Thank you, Richard, for sharing all this with us. Much appreciated. Thank you. No problem. It's been a journey together with you, but then I think that the benefits for JEM has been the possibility to actually keep data. As I mentioned, we have these very long business transactions from acquiring property at thirty years back until aftermarket. And if we would have needed to remove data, that would have been not that good from business analysis point of view. The key thing here has been to keep data to be able to have all the data up and remove all the sensitive parts of it. Mhmm. That's basically a great benefit. Thank you. Thank you.