- Organizations often tackle compliance efforts in an ad hoc manner, resulting in an ineffective use of resources.
- The alignment of business objectives, information security, and data privacy is new for many organizations, and it can seem overwhelming.
- GDPR is an EU regulation that has global implications; it likely applies to your organization more than you think.
Our Advice
Critical Insight
- Financial impact isn’t simply fines. A data controller fined for GDPR non-compliance may sue its data processor for damage.
- Even day-to-day activities may be considered processing. Screen-sharing from a remote location is considered processing if the data shown onscreen contains personal data!
- This is not simply an IT problem. Organizations that address GDPR in a siloed approach will not be as successful as organizations that take a cross-functional approach.
Impact and Result
- Follow a robust methodology that applies to any organization and aligns operational and situational GDPR scope. Info-Tech's framework allows organizations to tackle GDPR compliance in a right-sized, methodical approach.
- Adhere to a core, complex GDPR requirement through the use of our documentation templates.
- Understand how the risk of non-compliance is aligned to both your organization’s functions and data scope.
- This blueprint will guide you through projects and steps that will result in quick wins for near-term compliance.
Member Testimonials
After each Info-Tech experience, we ask our members to quantify the real-time savings, monetary impact, and project improvements our research helped them achieve. See our top member experiences for this blueprint and what our clients have to say.
10.0/10
Overall Impact
$25,779
Average $ Saved
30
Average Days Saved
Client
Experience
Impact
$ Saved
Days Saved
Leprino Foods Company
Guided Implementation
10/10
$2,339
2
Confirmed my thought process.
Experience Grand Rapids
Guided Implementation
10/10
$12,999
47
Alan gave me very valuable advice on how to approve our program of work. If I had this when I started, I truly believe I would have completed the w... Read More
Wiss, Janney, Elstner Associates, Inc.
Guided Implementation
10/10
N/A
20
Alan has a great understanding of the topic area.
Wiss, Janney, Elstner Associates, Inc.
Guided Implementation
10/10
$61,999
50
Aaron provided a great overview of the GDPR and CCPA landscape. He tailored the InfoTech standard approach to my company's specific size, industry... Read More
Helmerich & Payne, Inc.
Workshop
9/10
$30,999
110
Best: being able to tailor the workshop to where our privacy program was currently at and not deal with a general off the shelf option. Worst: on... Read More
The Task Force for Global Health
Guided Implementation
10/10
$12,742
5
Aaron was super knowledgeable. He walked me through the process and kept me abreast of new developments surrounding GDPR. He also pointed me to res... Read More
Citron Hygiene
Guided Implementation
10/10
$2,000
2
The American Institute of Architects
Workshop
9/10
$117K
44
Info-Tech analysts are the best. Aaron and Cassandra are both very professional in guiding AIA's team with step-by-step process, tools, the entire ... Read More
Werner Co.
Workshop
10/10
$63,667
20
Rita was a very knowledgeable, energetic facilitator. She worked it through and spent after hours time ensuring a successful workshop. Worst part ... Read More
ChoiceTel
Guided Implementation
10/10
$1.12M
20
Best parts were just being able to talk to someone who understands the issue around GDPR and help give some guidance. We will be planning on divi... Read More
ATS Automation Tooling Systems Inc
Guided Implementation
10/10
$10,000
10
The American Waterways Operators
Guided Implementation
10/10
$5,093
10
Packaging Machinery Manufacturers Institute
Guided Implementation
9/10
N/A
N/A
ABP Induction
Guided Implementation
6/10
N/A
N/A
Pita Pit Limited
Guided Implementation
10/10
$9,000
50
Rita is extremely knowledgeable and delivers content in a way that we can absorb and understand fully.
Starwood Capital Group
Guided Implementation
10/10
$127K
20
The session was very detailed.
Ecore International
Guided Implementation
7/10
N/A
N/A
Werner Co.
Guided Implementation
9/10
$70,034
23
Sodexo - Europe
Guided Implementation
8/10
N/A
N/A
Workshop: Fast Track Your GDPR Compliance Efforts
Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.
Module 1: Understand Your Compliance Requirements
The Purpose
- Kick-off the workshop; understand and define GDPR as it exists in your organizational context.
Key Benefits Achieved
- Prioritize your business units based on GDPR risk.
- Assign roles and responsibilities.
Activities
Outputs
Kick-off and introductions.
High-level overview of weekly activities and outcomes.
Identify and define GDPR initiative within your organization’s context.
Determine what actions have been done to prepare; how have regulations been handled in the past?
Identify key business units for GDPR committee.
Document business units and functions that are within scope.
Prioritize business units based on GDPR.
- Prioritized business units based on GDPR risk
Formalize stakeholder support.
- GDPR Compliance RACI Chart
Module 2: Define Your GDPR Scope
The Purpose
Know the rationale behind a record of processing.
Key Benefits Achieved
Determine who will own the record of processing.
Activities
Outputs
Understand the necessity for a record of processing.
Determine for each prioritized business unit: are you a controller or processor?
Develop a record of processing for most-critical business units.
- Initial record of processing: 1-2 activities
Perform legitimate interest assessments.
- Initial legitimate interest assessment: 1-2 activities
Document an iterative process for creating a record of processing.
- Determination of who will own the record of processing
Module 3: Satisfy Documentation Requirements and Align With Your Data Breach Requirements and Security Program
The Purpose
Review existing security controls and highlight potential requirements.
Key Benefits Achieved
Ensure the initiatives you’ll be working on align with existing controls and future goals.
Activities
Outputs
Determine the appetite to align the GDPR project to data classification and data discovery.
Discuss the benefits of data discovery and classification.
Review existing incident response plans and highlight gaps.
- Highlighted gaps in current incident response and security program controls
Review existing security controls and highlight potential requirements.
Review all initiatives highlighted during days 1-3.
- Documented all future initiatives
Module 4: Prioritize GDPR Initiatives
The Purpose
Review project plan and initiatives and prioritize.
Key Benefits Achieved
Finalize outputs of the workshop, with a strong understanding of next steps.
Activities
Outputs
Analyze the necessity for a data protection officer and document decision.
Review project plan and initiatives.
Prioritize all current initiatives based on regulatory compliance, cost, and ease to implement.
- GDPR framework and prioritized initiatives
Develop a data protection policy.
- Data Protection Policy
Finalize key deliverables created during the workshop.
- List of key tools
Present the GDPR project to key stakeholders.
- Communication plans
Workshop executive presentation and debrief.
- Workshop summary documentation