Maintaining Compliance Over Time Print

  • 0

Preventing drift.

WHAT DRIFT LOOKS LIKE

New systems nobody added to the inventory Fields added to forms New third parties engaged Retention never applied Access accumulating

WHY IT HAPPENS

Compliance is treated as a project rather than a practice.

WHAT PREVENTS IT

Embedding checks into existing processes.

WHERE TO EMBED THEM

  • Procurement: a data question before engaging any supplier
  • Product: a privacy question in design review
  • Joining and leaving: access granted and removed
  • Change management: does this affect personal data

WHY THAT IS MORE EFFECTIVE THAN AUDITS

It catches things at the moment they happen.

WHAT TO AUTOMATE

Retention Access reviews, prompted Reminders for registration and filings

WHAT TO SCHEDULE

An annual review of everything.

WHAT TO ASSIGN

Ownership of each element.

WHY

Shared ownership is none.

WHAT TO MEASURE

Whether new processing is assessed before launch Whether requests are handled within deadline Whether access reviews happen

WHAT TO REPORT

Those figures, and gaps.

WHAT TO DO AFTER ANY INCIDENT

Review what allowed it, and change the process.

WHAT TO ACCEPT

That this is ongoing work, not a completed task.

WHAT TO PROTECT

The habit of asking whether the data is needed.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot