JM, GDPR 준수를 위한 솔루션 채택

북유럽 기업 JM은 GDPR 규정을 준수하기 위해 EPI-USE Labs의 Data Sync Manager와 Data Privacy Suite를 도입하여, SAP 시스템 내 민감한 데이터를 스크램블링 및 마스킹하기 위한 효율적인 프로그램을 구축했습니다.

Labs_Coloured_blocks
2025__JM-1
GDPR 준수를 위한 효과적인 비즈니스 프로세스
2025__JM-2
보존 기간 외 민감한 데이터 자동 삭제
2025__JM-3
리스크 감소: 테스트 시스템상 데이터 민감성 제거
Play video
So welcome, Richard. So this conversation between the two of us is about the GDPR because it has obviously meant a lot to everybody in the SAP community. So thanks for wanting to share your experience with us. Could you present yourself and your role at JM? My name is Richard Wenell. I'm managing the IT part of JM, which a part of our business development corporate function. It's a quite small unit where we work a lot with external partners for development. So partnership with APUs is one of them. And, JM, what kind of company is it, for those who come from outside Scandinavia? Yeah. We were only based in Scandinavia. So we were a house construction company. We're based in Norway and in Finland, and then mainly in Sweden. We build houses for people to live in. That's our main business. The business starts with acquiring property, which is a very important part to actually acquire the right and then we keep the property for sometimes quite a long period of time, about thirty, forty years. Which means when we look into profitability in our business, we need to look long way back and then look on how the products developed and how we sell. Last two years has been a lot focused on what we call the aftermarkets, taking care of the houses, and taking care of what the people living in during the lifecycle of the house. So now we have the very long time frame from acquiring property quite long time ago until people here live there and hopefully they buy a new property from buy new house trunks. So with that kind of organization building private homes for people, what kind of privacy are you then into? What kind of data do you store in your SAP system? In the SAP system, it's mainly about our employees. There are about two thousand five hundred employees at the company. So that's one part which has been the main focus. Then even though we're selling the house to an individual, still the main transaction is to an organization. So therefore, there's not that difficult to take care of customer data. It's more about employee data and the employee data in the financial part of the system. So when the GDPR came, I know you have been working with the GDPR preparations for a long time. So could you describe the first steps that happened at JAM? I believe it's about five years ago since you took the first steps. Yep. It's a smile on my lips. It was I think it was in other companies as well, but it was you know, my company was panic. Everyone was running around, and everyone talked about the possible penalties of four percent and how it will affect. There was a lot of people running around. The first action was or interpretation of GDPR was we need to be compliant on operating systems. And perhaps that was a quite big mistake for us. It took some period of time until we understood that GDPR is not about versions of operating systems is about something completely different. But it was raised as highest priority very, very early, and so we got a lot of focus and attention on it. To start to work on it in a proper way. Are you then saying that this was a priority from upper management and not just something that you were working in within IT? So there was a top priority. We had, what do you call it, business development council, more or less and then this project was given top priority and then I should say unlimited budget, but we were allowed to start to take actions without having will order all the necessary means more or less. So it was really a top priority put most things addressed in parallel. So it's your corporate initiative and the corporate budget. Yes. So when the corporate projects started, What was the journey from the corporate initiative to you guys in IT being able to do something? Somebody must have told you what it wanted. Yes. So we have we had a since we're part of a business development, we, of course, were in control of the project and started the initiative. What we did was to define a model where we went to our business model. The business model is process based. So we have process owners in the business taking care of a different part of how we do it in different things. What they have not focused on earlier is the kind of what information do they have in their process, and how do they deal with that? So that was the process so that the methodology, we went to the process owners. We asked them to describe each of the processes, what information objects do they have, and data do they contain and how is the sensitivity of that data? So that ended up in quite a lot of documentation thinking about several hundred processes about what information objects and the sensitivity of them. And from there, we started to take action. I would say most actions were about cleaning data, taking that was taking care of the business or defining processes, how we should do things that actually document how we should deal with the data, then later. It came to actual requirements on us, on IT because they needed help with cleaning. They needed help to work with the routines for retention, routines for searching to find information about individuals, etcetera. So I would say that initially it was an IT project. And then when we did a retake, it took almost a year of just setting the processes and analysis analyzing the information before it turned back to an IT project again. I know we think that was the right way to do it. We should probably have started that way from the beginning. But now we also have the attention from the process owners from the business about that they own information, that they need to take care of it, they need to have routines, and they need to understand that. That's good. Would you describe that as a pleasant side effect of a GDPR the increased process awareness and the increased awareness of what data do we have, and why do we have them? Yes. A lot and there was a lot of old data that we could remove. And I think that was quite beneficial, and also to introduce the routine is to actually take care of the time to be more thorough when we introduce new data that, well, why should we keep this data? Are we allowed to keep the data? And that it's actually that someone feels responsible for it. That was, I shouldn't say, completely new, but quite new for a lot of some parts of the organization. Richard, does this mean that we are actually now talking about data privacy by designing meaning that when you start a process or a new system, you think privacy from the very beginning. Yeah. I know if I talk a little bit, but what happened after GDPR was that we needed to focus on have focused a lot of information security in general. So in that part, we take took all the stuff done in GDPR, but we also introduced information security routines in general. So now when we're starting our projects, we have frameworks for how to do information, sensitivity analysis how to do risk analysis. And from there, actually, coming to requirements on the IT supporting the sensitivity from a complete information security perspective. So GDPR is now becoming I shouldn't say just a small part, but there's only one part of it. And look initially looking on personal data. We're now looking on all our business data. Yeah. So that's -- Mhmm. -- a difference. And it's so it becomes more of a privacy by design. Yes. So the governance that you have around GDPR, is that now -- is that a separate governance for the GDPR or is it a general governance around data security and information security? It's still both, I would say, where we introduced a new role as a part of GDPR, as a risk officer, works together in as a corporate function. And he's responsible for all the GDPR routines that they are in place and to monitor that and to or did that also internally at JM. In parallel, we've built up the information security model, and they are I would say merging right now. I would say the information security methodologies is broader, wider, and the more thorough which means the GDPR processes will become much easier, I would say. So the risk officer from a GDPR perspective we'll have a much easier job. But the rest of the organization are much more involved now, and we don't do anything without clicking on the information activity on the information and how it should be dealt, and the availability of it. So it's a lot of things. Going on. But in general, it's from a top management point of view. This isn't the word issue for us. I reported the word once or twice every year now, how we progress in these areas. Oh, interesting. Yes. Said that from the very beginning, it was mainly about employee data. But you also said a bit later that you are now looking at business data in general, have you defined all the areas, I mean, areas outside the employee data? Yes. Especially when it comes to production, we're working building houses. And if a construction site is not producing during a day or during an hour or even ten minutes, we know how much the cost is. Could be many people involved and a lot of equipment that doing nothing. And we have that measure, and we understand the delay there. So even though they think they construct houses with physical things. They're still depending on a lot of IT things. So when we ask them, what happens if this system is down for an hour, what happens if you can't order material for a day, then things start to become urgent and important and actually very business critical. Did this whole process give you any surprises as to the data you hold or the governance around data privacy? Perhaps not many more than that. We've stored a lot of data over time, a laptop of an of data. And the initial processes when we removed data with huge amount of data, especially if you look on employee data, that was like fifty percent of the data more or less, I think, we were removed. So the necessity of storing some data been probably one of the lessons learned that we don't need all the data we have or had. So I think that's important. And also perhaps a piece of quality of the data, of course, because when you start to introduce we did with the app just starting to use rubles, where you search for data and then trying to remove it or And then if you don't find it, then you see that the quality data is it's poor. You need to start to work with the quality data, which also is a good thing because now we can use the data for better things. So this is how things are now. What kind of initiatives do you see going forward that you're considering about security in general and data security and protection. For us, it's been a lot of methodology of politics, I would say. Still I'm responsible for IT. I want more security mechanisms on a night eleven right now. So that's what we're focusing on right now. We are taking care of our operation, and increasing the level of security matters. But it has been a journey to come there because we could have done it just on chance. But now we know what requirements are. There are. So we need to what level we need to understand what level we need to come to. And we know how to measure it. We know I get followed up by the board on every year on where I am on that matter. So This year is focused on the technology part to actually making sure we have a secure environment. But then, in parallel, it's training, of course, training of employees. That's where most things start with someone clicking on the link. Of course, as we, as everyone else, probably have had different threats and things happening. We've been cross my fingers, but we've been lucky. So far, no really, really dangerous things, but we will have the directed attack attacks to us, and if people clicked on the wrong links, and let them into the network, and then things happen. So training and training is also a very, very important part. We work with micro training with all employees. So would say, I don't know how often it is, but it's like every second week people get to go through a micro training in information security. Interesting. So now what do you No. No. That's that. I think those are the those two main areas right now is the technological protection, making sure our operation environment is really more secure than it has been, and training on employees. That's the focus for this year, and perhaps, in the next year as well. Mhmm. Thank you, Richard, for sharing all this with us. Much appreciated. Thank you. No problem. It's been a journey together with you, but then I think that the benefits for JEM has been the possibility to actually keep data. As I mentioned, we have these very long business transactions from acquiring property at thirty years back until aftermarket. And if we would have needed to remove data, that would have been not that good from business analysis point of view. The key thing here has been to keep data to be able to have all the data up and remove all the sensitive parts of it. Mhmm. That's basically a great benefit. Thank you. Thank you.
이 비디오에는 한국어 자막이 있습니다

핵심은 모든 데이터를 유지하면서 민감한 부분만 제거할 수 있다는 점이었습니다. EPI-USE Labs의 솔루션 덕분에 큰 이점을 얻었습니다.

Richard Wenell, IT 부서 책임자, JM
testimonial-quote

 

민감한 개인 데이터 보호의 도전 과제

2015년, JM은 개인 데이터의 무결성을 보호하고 GDPR 벌금을 피하는 과제에 직면했습니다. 이 도전 과제는 다음과 같은 분야에서 발생했습니다:

  • 고객 정보 및 거래
  • 고객 서비스
  • 직원 정보
  • 공급 업체 관계 및 거래
  • 마케팅 및 커뮤니케이션

JM 팀은 GDPR을 준수하기 위한 긍정적인 변화를 시작하기로 결정했으며, 특히 다음을 중점적으로 다뤘습니다:

  • IT 시스템이 아닌 현업실무자에 집중
  • 정보 보안을 위한 개선 사항 자금 지원
  • 유용한 소프트웨어 도구 제공
  • 개선 프로젝트를 모든 사람에게 최우선 과제로 설정

우리는 프로젝트 초기에 EPI-USE Labs와 협력하여 요구 사항과 사양을 상호작용적으로 개발했습니다.

Richard Wenell, IT 부서 책임자, JM
testimonial-quote

개인정보 관리 및 보호 솔루션

JM은 Object Sync™와 Data Secure™를 선택하여 Data Sync Manager™(DSM) 제품군의 일부로 데이터를 테스트 및 교육 목적으로 복사하고 스크램블했습니다. 비운영 환경에서 데이터 흔적을 줄여 민감한 데이터를 테스트 환경에서 제거할 수 있었습니다. 또한, GDPR 준수를 위해서는 시스템 설계 단계부터 기본 설정에 이르기까지 데이터 보호가 반영되어 있음을 보여주는 것이 중요합니다. DSM을 사용하여 비운영 시스템에서 데이터를 새로 고침함으로써 JM은 이 원칙을 입증할 수 있었습니다.

JM은 이제 Data Disclose™, Data Redact™ 및 Data Retain™을 사용하고 있습니다. Data Disclose는 GDPR 제15조에 따른 Subject Access Requests를 처리하는 데 사용됩니다. JM 팀은 SAP 시스템을 검색하여 시스템에 저장된 개인 데이터에 대한 브랜드화된 PDF 문서를 제공할 수 있습니다. Data Redact, 즉, 개인을 식별하는 데이터를 수정하는 데 사용되는 기능(GDPR 제17조 및 삭제 권리를 준수)은 JM이 삭제 요청에 대응할 수 있게 해줍니다. 또한, SAP 시스템에서 데이터 보존 정책 외의 민감한 데이터를 정기적, 능동적으로 수정할 수 있습니다.

JM은 Data Retain의 ramp-up 클라이언트로 EPI-USE Labs와 협력하여, Data Retain을 사용하여 보존 규칙을 설정하고 수정이 필요한 키를 Data Redact에 제출할 수 있는 시각적 UI를 제공받았습니다.

EPI-USE Labs는 고객, 공급업체, 직원 및 회계 문서 등 여러 데이터 세트에 대한 초기 대규모 정리 작업을 시스템 환경 최적화 기능을 사용하여 도왔습니다.

우리의 비즈니스 거래는 길게는 30년 이상 지속될 수 있으며, 우리는 데이터를 유지하면서 불필요한 민감한 정보만 제거하고 싶었습니다. EPI-USE Labs의 Data Privacy Suite 덕분에 이를 실현할 수 있었습니다.

Richard Wenell, IT 부서 책임자, JM
testimonial-quote

GDPR 지속적 준수

JM은 EPI-USE Labs의 솔루션을 사용하여 비즈니스 프로세스를 지원하고 데이터가 위험에 처한 분야에서 GDPR 요구 사항을 준수할 수 있었습니다. 또한, 짧은 시간 내에 이를 달성할 수 있었습니다:

  • 능동적인 접근 방식으로 민감한 데이터를 보존 기간을 초과하면 자동으로 삭제
  • 테스트 시스템에서 더 이상 민감한 데이터가 포함되지 않으며, 비생산 환경에 접근하는 내부 사용자나 파트너의 리스크가 낮아졌습니다.

JM의 GDPR 여정에서 다음 단계는 운영에서 정보 보안 루틴을 구현하는 것입니다. EPI-USE Labs와 협력하여 SAP 시스템에서 보존 프로그램을 설정할 계획입니다.

 

EPI-USE Labs의 접근 방식은 민감 데이터를 보관하는 대신 익명화 및 수정할 수 있도록 합니다. 이를 통해 비즈니스 트랜잭션은 시스템에 그대로 유지되면서도, 특정 개인을 식별할 수 있는 정보와는 연결되지 않도록 할 수 있습니다. 또한 프로젝트를 시작할 때 정보 민감도와 위험 분석을 수행하기 위한 체계를 갖추고 있으며, 그 결과를 바탕으로 데이터의 민감도를 포함한 IT 측면의 요구사항을 도출합니다. 이는 정보 보안을 전반적으로 고려한 접근 방식입니다.

Richard Wenell, IT 부서 책임자, JM
testimonial-quote

산업: 엔지니어링, 건설 및 운영

솔루션: Data Sync Manager (DSM), Data Privacy Suite

JM 소개

JM은 북유럽 지역의 주택 및 주거 단지 개발을 선도하는 기업 중 하나입니다. 사업은 신규 주택 건설을 중심으로 하며, 스웨덴·노르웨이·핀란드의 대도시 확장 지역과 대학 도시를 주요 대상으로 합니다.