A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

PGS
Daphne Bjerke, Global Data Protection Officer
The Art of Staying 'Data' Protected


What is the biggest data privacy-related challenges that you observe in your business on a day-to-day basis?
We are an integrated marine geophysics company with offices in 14 countries, vessels located all over the world, and more than half of our employees are working offshore. Hence, we need to send a lot of business-critical information to our global network of offshore agents via emails. It is imperative that we secure such information. We do this using a dedicated Private Content Network (PCN) to ensure privacy and compliance of external digital communications, and, internally, we have implemented a company-wide data protection loss policy with appropriate sensitivity labels, and we educated our employees on how to use the labels when attaching information on emails and sending them out.
This solution was a major step for securing business information and personal communication. Our offshore vessel crew members are away from home for weeks or months at a time, so naturally they want to communicate with their families while away, and a lot of personal information gets exchanged because of that. In this case, the sensitivity labels can be used to indicate the data being exchanged during the communication is personal.
What are the aspects you and your company look into when it comes to securing data in the present and the future?
We have a group in our company called the General Data Protection Regulation (GDPR) workgroup, consisting of four different departments: legal, HR, compliance, and IT. We meet every month to review any recent changes in data privacy legislation. We go through all the different requirements when transferring data across Europe, Asia, and the Americas, to make sure we are on top of everything.
Additionally, we have scheduled an external company to come into our company and conduct an audit on our different GDPR processes, policies, and procedures. They will monitor how we are storing the information, how we are processing the information, and how we are handling any personal data breaches to make sure that all our approaches taken are in compliance with the regulations.
When adopting any new solution, what are the usual things you look at when vetting the provider for data compliance?
Usually, before we sign a contract, we have our procurement team vet it. Our legal GDPR experts then review the terms and conditions because, very often, most vendors would have subtle information about the data privacy and data processing section mentioned in the fine print that goes unnoticed. We also have a data processing notification form that all potential system owners must fill out. We review them, ask specific questions, see the kind of data that will be sent, and how it will be sent. We also see if the application system has a built-in delete function for when the employee is no longer working in the company. So, it is programmed to be compliant, and once we have that reviewed, we might need to set up a data processing agreement with the vendor. If the application system does not meet our compliance expectations, we conduct a data processing impact assessment. Only after those action points are executed, we move forward with the contract and implement the new solution. Even after its implementation, we periodically audit the application system and talk to the vendor in case something needs to be amended in the system.
-
It is crucial for a company that aims to remain data-secure to have a good working relationship between the HR, IT, compliance, and legal departments
Can you think of an instance where you had to be quick on your feet to solve a critical data breach your company might have undergone, and how did your company mitigate that problem?
One of the biggest problems, when our employees share personal data, is photos. Before they publish the photos anywhere on social media or even send them to their families via encrypted messaging platforms, we must make sure that they have consent in place. Often photos taken at company events have other employees in the background. We do not want our employees not to share images with their families, but we want to ensure that the images they share are vetted and consent has been given.
We are now looking at a new application system that would do away with the manual process we had in place. So, instead of having to fill out different consent forms every time an employee wants to send out a photo, we will have an app that would be embedded with our workflow to make the task easier.
What advice would you give to the other leaders in this industry or any other industry for tackling data privacy challenges and staying GDPR compliant?
First, it is particularly important that you have the board of directors in your company on board with any company-wide changes you want to implement. They should all realise that GDPR is a part of how we work and not an addition to what we do. Once that is an accepted norm, it becomes important to communicate all the different regulations to everyone within the company. It is also essential to do other things like GDPR training, sensitivity labels, consent forms, and retention periods, so that your employees feel more comfortable. Overall, it is very crucial for a company to have a good working relationship between the HR, IT, compliance, and legal departments to make it a data-secure bubble.
Weekly Brief
I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info


