CIO Applications Europe
About UsConferencePartner With Us
Close
  • Applications
      • Business Intelligence & Analytics
      • Call Center Solutions
      • CRM & Customer Experience
      • Data Center
      • Digital Transformation
      • E-Invoicing
      • Intelligent ERP & Automation
      • Risk Management & Compliance
      • Unified Communications (UCaaS)
  • Industries
      • Automotive & Mobility
      • Construction & Infrastructure
      • Financial Services
      • Healthcare
      • Retail & E-commerce
      • Telecom & Media
      • Travel and Hospitality Tech
  • Technologies
      • Cloud
      • Cybersecurity & Resilience
      • Data Engineering & Analytics
      • Generative and Agentic AI
      • IoT & Edge Computing
      • Robotics
  • Platforms
      • AWS
      • IBM
      • Microsoft
      • Salesforce
      • SAP
      • ServiceNow
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • CXO Awards
    • Europe
      • US
  • Topics

  • Menu
      • Business Intelligence & Analytics
      • Cloud
      • Digital Transformation
      • Generative and Agentic AI
      • Microsoft
      • Risk Management & Compliance
      • Travel and Hospitality Tech
      • Unified Communications (UCaaS)
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Generative and Agentic AI
  • Digital Transformation
  • Business Intelligence & Analytics
  • Cloud
Topics
  • Topics

  • Business Intelligence & Analytics
  • Cloud
  • Digital Transformation
  • Generative and Agentic AI
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Unified Communications (UCaaS)
  • Home
  • GDPR

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

PGS

Daphne Bjerke, Global Data Protection Officer

What I Learned from Tackling the Challenges of GDPR

The exponential growth and spread of the worldwide web, the mushrooming power of search technology and the spread of social media means it has never been easier to access people’s personal data. Companies have a duty to protect personal data.

EU regulators were on the ball in 2015, when they announced plans for increased data protection.The potential for misuse of people’s data was amply exposed by the Cambridge Analytica scandal which began in 2016 and hit the headlines in 2018. By that time,PGS was already working towards being fully compliant with GDPR.

Our journey to GDPR compliance started 2015.However, PGS’ first corporate data protection statement dates from 2012.At that time, I was the personal data protection ombudsman at PGS. This is a well-established role in all larger Norwegian companies, as the country has a tradition of personal data protection for employees, whose regulatory foundation started with the Data Register Act of 1978. The EU regulations and GDPR marked an evolution,on a much broader scale, expanding our efforts from HR systems to all company systems.

When the EU Court of Justice declared,in October 2015,that European companies could no longer transfer personal data from EU to US under the so called “safe harbor principles”, PGS was one of the companies that had to reset their data storage and transfer practices. Failure by companies to comply with EU rules on data protection can result in fines of up to €20 million, or 4% of global annual turnover. Those kinds of numbers elicit management attention.

Mandate, Mapping, and Milestones

From the word go, we had a clear mandate from our board of directors and our executive management team to plan and implement GDPR compliance. I believe that was an important factor in our achieving early success.

In January 2016, PGS updated its procedures, developed a set of binding corporate rules, and I was appointed the Global Data Protection Officer.We immediately started mapping out the tasks, the teams and the timeline for achieving full GDPR compliance within the deadline of May 2018.

The executive management team, recognizing the scale of the task, appointed a cross-functional workgroup to help me, consisting of representatives from IT, legal, compliance and audit, and HR.

Our first step was to map out what systems were storing personal data and clean up our data.

Initially, we found 80 systems storing personal data,however,today the number has grown to almost 140. To uncover all the systems, we needed to raise awareness around the company, so from 2015 through 2017 we ran a series of workshops worldwide. We also published a series of awareness articles on our intranet.

I was familiar with the HR systems, but I needed to know what other systems were out there that needed to be aligned. We issued notification forms for system owners, to help identify data archives and applications with relevant content.

Some work extended outside our own company, as we had to establishdata protection agreements with 3rd parties that managed systems that process our data. For core applications,data protection impact assessments were completed, to assess how non-compliance of each system might affect us.

Early Launch

OnMay 25, 2018 we officially implemented the GDPR rules and regulations, nearly three months earlier than the deadline for Norwegian companies. Our CEO wrote to everyone explaining background and effects.

The work did not stop here. As GDPR regulation applies also to files and spreadsheets held on local PCs and network areas, our efforts to identify and align systems that store personal data continue.

Auditing and compliance

Today our focus is on compliance. We check applications and contact system owners regularly,to review notification forms and data retention plans. Action items are followed up and our internal audit department are about to start regular audits of affected systems.

GDPR has become a way of working for me and for PGS. Awareness programs are ongoing, for instance we hold an annual series ofnano-learning courses: short online updates with tips and checks that focus on people and departments especially affected by GDPR; like IT and HR.

Through our compliance hotline we have an effective system for handling potential data breaches, and we take everything seriously. Basically, we check anything that looks like it could be, or become,a potential breach.

Experienced Insights

The past five years has led me to conclude that everyone is affected by GDPR. Today, every website you visit asks you to approve cookies. That is a result of increased global awareness and sensitivity to use of personal data. Employees, customers and potential recruits, suppliers, owners, and neighbors deserve and demand that we take this seriously.To make it work, you need to make GDPR away of life. In everything you do, you should question how you treat personal data. Ask yourself: Do we need this info? Where should we store it?Who can we share it with?What do we do when we no longer need it?

Five tips for successful GDPR compliance:

Get ownership from the top

Build a team

Map your systems and applications

Define actions

Build awareness and ownership

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
The Leadership Perspectives forum brings together voices shaping construction technology and innovation. Participation is by invitation only. It features leaders who are not merely observing technological change, but actively contributing to it through digital transformation and execution-driven insights.
EDITOR'S CHOICE
  • Willis Towers Watson

    Legal & General

    Building Technology Foundations That Last

    Mark Hall, Group Chief Technology Officer

  • Willis Towers Watson

    Adp Uk

    "Shift left" Defect Discovery using Agile and DevOps

    Keith Watson, Director Of Devops

  • Willis Towers Watson

    Motor Oil

    Trust, Security Strategy and the AI-Driven Threat Landscape

    Syngelakis J. Christos, Group Data Protection Officer

  • Willis Towers Watson

    Swiss Re [SWX: SREN]

    A Future of Enhanced Human Work

    Sergio Chelli, IT Procurement Manager at Swiss Re [SWX: SREN]

Weekly Brief

loading

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

×
#

CIO Applications Europe Weekly Brief

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from CIO Applications Europe

Subscribe

loading

THANK YOU FOR SUBSCRIBING

CIO Applications Europe
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@cioapplicationseurope.com
  • sales@cioapplicationseurope.com
  • marketing@cioapplicationseurope.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 CIO Applications Europe. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://gdpr.cioapplicationseurope.com/leadership-perspective/what-i-learned-from-tackling-the-challenges-of-gdpr-nid-2486.html