CIO Applications Europe
About UsConferencePartner With Us
Close
  • Leadership Perspectives
  • Innovation Insights
  • News
  • CXO Awards
    • Europe
      • US
  • Topics

  • Menu
      • Business Intelligence & Analytics
      • Cloud
      • Digital Transformation
      • Generative and Agentic AI
      • Microsoft
      • Risk Management & Compliance
      • Travel and Hospitality Tech
      • Unified Communications (UCaaS)
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Generative and Agentic AI
  • Digital Transformation
  • Business Intelligence & Analytics
  • Cloud
Topics
  • Topics

  • Business Intelligence & Analytics
  • Cloud
  • Digital Transformation
  • Generative and Agentic AI
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Unified Communications (UCaaS)
  • Home
  • GDPR

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

Roquette

Jennifer Godin, Group Data Protection Officer

Keeping Up With Changes In Data Protection Laws

In today's digital world, a company's information assets are more than ever a source of value, while being subject to new risks for which cyber-security has become a major issue at global, national and societal levels.

These new uses (social networks, Cloud Services, connected objects, etc.) have seen the number of personal data multiply, as well as their collection and associated processing, thus creating new challenges in terms of data protection and privacy, whether for institutions, businesses and individuals.

Personal data protection laws and regulations have evolved significantly around the world, in order to strengthen the rights of individuals, guarantee new ones, and empower stakeholders. This induces new obligations for companies.

In Europe, with the application of the GDPR since May 2018, the appointment of a Personal Data Protection Officer is required or strongly recommended, and this trend continues to grow in order to steer the legal and IT measures to be implemented to guarantee a group's compliance with these requirements.

A company based in France, with European subsidiaries, can have a lead authority, which in this case will be the CNIL. If a delegate is appointed for this group, she/ he must be easily reachable from each place of establishment. She/he must indeed be able to communicate effectively with the persons concerned and to cooperate with the supervisory authority.

If in addition, other subsidiaries and establishments are based outside the EU, it may be required to have a local DPO, and at least it will be necessary to have coordinators.

Thus a DPO of an international group will need to set up a Network of local DPOs. Several strategic and operational questions then arise.

The challenges of appointing and managing a network of correspondents and representatives for the protection of personal data led by a Group DPO are at three levels:

From a strategic point of view: the implementation of a compliance program, allowing the application of a Group policy on the protection of Personal Data, dedicated governance, harmonization of practices, support for the dissemination and strengthening of the culture of data protection and respect for privacy with limited costs.

The DPO will play a conductor role to harmonize internal processes and deploy a culture of privacy

From a contextual point of view: better adaptation to legislative and regulatory changes, organizational changes, the development of a Group internationally, the diversity of businesses and entities and their geographical distribution, etc.

From an operational point of view: have an identified and adapted contact within each entity, quickly have relevant information on operational reality and local legislation, have a local coordinator on the application of the Group policy and, where applicable, local requirements.

Local DPOs must be trained in the principles of protection of personal data and made aware of respect for privacy, informed of the missions of the Group DPO and the tasks incumbent on them, as well as internal procedures such as those on the registration of new data processing activity or on the exercise of Data Subjects Rights. Local DPOs will also have to keep themselves informed of legislative and regulatory developments in this area with local stakeholders and professional networks.

To fulfil their missions, the Group DPO and her/his network of local DPOs and experts need specific budgets for the valuation of time spent, the use of communication tools and dedicated business tools: Data Mapping, Data Subject Requests, Incidents Response and Data Breach Notification, Consent Management, Privacy Impact Assessment, Vendor Risk Management, Cookie Compliance etc.

The Group DPO must have an effective internal positioning in order to be able to report directly to the highest level of the company and also to lead the network of DPOs and local correspondents within the group's subsidiaries and to have access to a team of inhouse experts: IT experts, security experts, lawyers, communication experts, translators, etc.

To be efficient and pragmatic, the governance of a Data Protection Compliance Program and Network requires the establishment of a Data Protection Management System according to a risk-based approach and a principle of continuous improvement (Plan-Do-Check-Act), like an Information Security Management System.

To operationalize a privacy program to effectively achieve privacy by design, DPOs, chief information security officer, business contributors, lawyers and digital experts can use a Global Privacy, Security & Data Governance platform.

The DPO will play a conductor role to harmonize internal processes and deploy a culture of privacy.

A culture of privacy provides a shared understanding of how personal data can and should be used to support broader strategic objectives.

This improves the ability of a Privacy & Data Protection program to execute and drives alignment with other teams, increasing their understanding of and desire to support the achievement of Compliance goals.

All these lead to the biggest benefit of all: getting the highest and best use out of personal data — both for an organization and individuals.

In a Privacy & Data Protection program operating within a culture of privacy, legal compliance should be one result of a successful program, not the goal.

An equally important focus is how Data Protection supports other business objectives.

Ethics is increasingly talked about in terms of a key brand value for companies—and data ethics is a key part of that.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
The Leadership Perspectives forum brings together voices shaping construction technology and innovation. Participation is by invitation only. It features leaders who are not merely observing technological change, but actively contributing to it through digital transformation and execution-driven insights.
EDITOR'S CHOICE
  • Willis Towers Watson

    Legal & General

    Building Technology Foundations That Last

    Mark Hall, Group Chief Technology Officer

  • Willis Towers Watson

    Adp Uk

    "Shift left" Defect Discovery using Agile and DevOps

    Keith Watson, Director Of Devops

  • Willis Towers Watson

    Motor Oil

    Trust, Security Strategy and the AI-Driven Threat Landscape

    Syngelakis J. Christos, Group Data Protection Officer

  • Willis Towers Watson

    Swiss Re [SWX: SREN]

    A Future of Enhanced Human Work

    Sergio Chelli, IT Procurement Manager at Swiss Re [SWX: SREN]

Weekly Brief

loading

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

×
#

CIO Applications Europe Weekly Brief

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from CIO Applications Europe

Subscribe

loading

THANK YOU FOR SUBSCRIBING

CIO Applications Europe
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@cioapplicationseurope.com
  • sales@cioapplicationseurope.com
  • marketing@cioapplicationseurope.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 CIO Applications Europe. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://gdpr.cioapplicationseurope.com/leadership-perspective/keeping-up-with-changes-in-data-protection-laws-nid-2561.html