Introduction and who needs a DPO?
The General Data Protection Regulation (GDPR) creates jobs. OK, one job: the GDPR mandates a new formal position of Data Protection Officer (DPO) to preside over 'privacy by design', strategy development, planning and operational resources.
In fact, the GDPR states that all companies over 249 employees must have a DPO, though it's not for certain yet that it must be a full-time role. "A DPO role is not a new one, but it is critical to help businesses comply with GDPR," says Stuart Clarke, CTO, Cyber Solutions at Nuix. "The purpose of this role is to bridge the gap between technology and legal departments as well as HR and PR."
There are also suggestions that DPOs will need to be independent of the hierarchy of the company. "The DPO must be independent and is responsible for not only managing compliance within the business, but also reporting non-compliance to the relevant regulator," explains Robert Bond, Partner at the law firm Charles Russell Speechlys. "The DPO is therefore the internal policeman and the whistle-blower at the same time."
This is about a lot more than IT.
Which companies need a DPO?
All public sector organisations and many private sector organisations. "The GDPR does not make it mandatory for all data controllers and data processors to have in place a DPO," explains Lucy Pegler, an associate in Technology, Media and Telecommunications at Burges Salmon. "Where it is mandatory, the targeted organisations are ones that process large volumes of data or particularly sensitive data."
So not all companies will need a DPO, though that doesn't mean they're off the hook. "Even in companies which do not require a DPO, the necessity for someone to take ownership of data is still there," says John Culkin, Director of Information Management at Crown Records Management, who offers an intriguing analogy. "No-one washes their hire car, and similarly without data ownership it is likely that data will not be well maintained."
It will also depend on what other staff are present within an organisation. "Where, in larger organisations, they would work alongside the Chief Data Officer (CDO) who has accountability for all the company's data, the DPO's primary focus with be ensuring personal data is kept private," according to Nigel Tozer, Solutions Marketing Director, EMEA, Commvault. In smaller organisations that do not have a CDO, a DPO becomes even more important.
Why do we need DPOs at all?
Basic compliance with the GDPR, that's why. "Any strategy for managing data privacy requires someone with a holistic view of the whole business who is independent from any one sector of the company," says Yves Le Roux, Technology Strategist for CA Technologies and co-chair of the (ISC)2 EMEA Advisory Council.
As a society we are more dependent than ever on data, and that goes double for business. "It's critical for businesses to get a handle of where their data is, how it is stored, and who has access to it," says Phil Bindley, CTO at The Bunker. "A failure to do this means running the risk of getting hauled in front of the Information Commissioner's Office and a hefty fine." 5% of global annual turnover, in fact. So it's about money?
"This role is critical in today's world more than ever," says Michael Aminzade, VP Global Compliance & Risk Services at Trustwave, who suggests that the current fear over the GDPR and its proposed fines is down to the fact that most businesses never actually complied with previous legislation. "Management teams will become more dependent on this role as regulation continues to tighten while impact and penalties continue to grow in magnitude," he adds.
Since it changes the data landscape in Europe, compliance with the GDPR is also about business success. "The new regulation means that any business that suffers a data breach will be forced to declare it, and they'll be put in the spotlight for all the wrong reasons – leading to a damaged reputation and loss of customers," says Jason Hart, CTO Data Protection, Gemalto. The solution? Appoint a DPO.
Privacy by design
What would a DPO do?
DPOs will need to know everything about the company's data, from where it's stored, what it is used for and by who, and who the data controller and custodian are. Add knowledge of privacy and security controls, retention timeframes, scheduling data housekeeping and management reporting, along with handling cyber-attacks, and being a DPO certainly sounds like a full-time job.
"Their role is to make sure their company is not the next TalkTalk or Ashley Madison, hit by a major security breach," says Stephen Love, Security Practise Lead EMEA at Insight, though he's not sold on a DPO necessarily being full-time. "These responsibilities could fall with an existing Chief Information Security Officer (CISO) as it is already part of their remit," he says, adding that such an approach could be beneficial for organisations that may not have the extra budget for the new position of DPO.
"While it may seem to have some overlap with the Chief Information Officer (CIO) role, the difference is that CIOs typically don't own the data – rather they focus on the IT assets," says Javvad Malik, Security Advocate at AlienVault.
What would a DPO not do?
A DPO is there to satisfy regulators, not understand and combat threats to data. "A DPO is a person who defines your processes around data protection," says Simon Kouttis, Head of Cybersecurity Practice at executive recruiter Stott and May. "They can often tell you what documentation you need and how to satisfy regulatory requirements [but] they would not have the breadth of knowledge to protect your data." That's the job of the CISO, or other security professionals.
What is 'privacy by design'?
It's a major theme of the GDPR – 'privacy by design' will become integral to all technology projects. "Privacy by design requires every company to put data privacy at the heart of everything from its procurement policies to its BYOD policy, its IT training and the info-security controls it deploys," says Le Roux.
Privacy by design will take such a central role because the IT industry has routinely ignored privacy. "Traditionally privacy and confidentiality have played a low priority role in the development of applications software," says Dave Levy, Associate Partner, Citihub Consulting, citing the slow adoption of DNSSEC and 'https everywhere' as indicators of the reticence of business solutions developers to adopt even standard infrastructure tools.
Will DPOs be successful?
Okay, so companies need to appoint a DPO to set policy on data protection, but will they actually have any power to do anything about it? "Possibly no," says Jes Breslaw, EMEA director of strategy, Delphix. "Data is sprawled throughout an organisation – hundreds or even thousands of production copies sit in development, testing, analytics, reporting and other business units, and data-related processes are defined at the project level with little consistency across the business." It's going to be difficult for most DPOs to enforce their policies.
"The DPO role will be strategic, and capable of building bridges between different organisational silos, such as the CIO, CISO, Chief Data Officer," says Bojana Bellamy, President of Hunton & Williams LLP's Centre for Information Policy Leadership.
When do DPOs need to start work?
The GDPR begins in two years, but the longer companies leave it, the more a DPO is likely to cost. "Salaries will rise the nearer we get to deadline and the suspicion is most companies will wait until the month before implementation to act," says Culkin, who thinks small companies could outsource the role.
"We may well see specialised Data Protection Officers covering several clients," he adds. "The International Association of Privacy Professionals (IAPP) has just published research that shows that 28,000 DPOs will be required to be appointed across Europe. There is going to be a shortage of skilled DPOs!" says Bellamy.
Some will see DPOs as an unnecessary burden on a business, but a more positive outlook is recommended. "Good information security and privacy can be used as a differentiator and help build reputation and grow a business," says Debbie Evens, the Global Legal and Commercial Director at Clearswift. "Regulations might be seen as a real pain, but treating them as an opportunity is the best way forwards to compliance."
As we move into an era of more and more IoT sensors and devices collecting data, more data breaches, and more regulation, the position of DPO will become as important as an accountant. One thing's for sure – the IT industry will be taking personal data privacy a whole lot more seriously by 2018.
No comments:
Post a Comment