In our previous article, we shared our thoughts on the importance of baseline training and why it should be the first step in data privacy compliance. Along the same line, this week we look at the significance of establishing a governance framework for your privacy compliance program.
Why privacy governance?
a. Facilitating data protection compliance
b. Promoting brand reputation
An efficient privacy program also enhances your organisation’s reputation. If you misuse customer data you run the risk of severe backlash from your clients which in turn dents your corporate image. A case example is the 2016 data breach and subsequent cover-up at Uber Technologies Inc. which saw its customer perception rating drop by 141.3%. A large part of this market share was lost to rival company Lyft Inc. An elaborate privacy governance framework would shield your organisation against such risks.
c. Adopting a proactive approach to data protection
d. Improving operational efficiency
Key Considerations for your Privacy governance structure
1. The privacy vision and mission
A perfect example of this is Apple’s privacy mission statement which reads as follows:
2. Data governance
3. Positioning the privacy governance function
4. Resourcing your privacy governance function
a) Appointment of a Privacy Team
b) Prescribing roles and responsibilities to the privacy governance team
- Initially;
- Legal scoping assessments – fact-finding exercise on the extent of data processing within the organisation
- Data-mapping – showing how data flows within the organisation, including data storage, disposal, transfer, and sharing procedures
- Gaps assessment – identifying any compliance gaps identified from the data map and making recommendations
- Implementation of the data compliance roadmap – including registration with the Data Commissioner, Ensuring ICT security measures, instituting data protection policies and procedures etc.
- Continually;
- Advising the organisation on existing and arising data processing requirements
- Governance and strategy – Establishing and maintaining a data privacy governance model and strategy to respond to the changing landscape
- Facilitate capacity-building of staff involved in data processing through training and sensitisation
- Act as a liaison between the organisation and the Office of the Data Commissioner – for breach reporting, registration renewal, complaint handling etc.
- Liaise with data subjects – to facilitate their rights, receive requests, handle complaints etc.