Three Things to Consider when Setting Up Data Compliance
This article seeks to highlight three items that we consider to be important when it comes to #data compliance.
It is based on the work that we are doing to support organisations implement or strengthen data compliance systems.
1. Apply the age-old #compliance frameworks when implementing data compliance.
The framework is tried and tested and provides a useful implementation framework that covers:
- policies and procedures (including code of conduct and #ethics),
- effective #communication (hotline),
- training,
- compliance office (outsourced or in-house),
- #audit and monitoring,
- consequence/accountability management, and
- third party transactions.
You will note that registration with the Office of the Data Protection Commissioner (ODPC) is not listed as an element on its own.
Registration is a necessary but not sufficient aspect of compliance.
In
fact, we consider registration, particularly the declarations made in
that process, as exposing organisations to compliance #risks relating to incorrect / misleading disclosures.
To illustrate, review the declarations made during registration, specifically the #data
processing activities and technical measures, against actual practice. Do those declarations replicate existing structures and practices that support the declarations made or do
we congratulate your firm for fulfilling yet another tick-box exercise?
2. Benchmark against global, not just local, legislation.
We live in a global village, and #Kenya is a regional hub. The probability that your organisation is processing other nationalities' data is high.
The ODPC is increasingly, based on last year activities, looking to the EU to develop jurisprudence on data compliance.
This is why, in designing 350-point MZIZI-Audit tool, we looked to gold standards in data compliance for inspiration.
The
compliance team need to continuously update their understanding of
these standards/emerging jurisprudence as part of their continous development.
3. Involve the ICT Teams.
Legislation
does not exist in a vacuum. Data legislation seeks to
influence how organisations process data. This data is stored in
systems, and data may be baked into an organisation's business model.
Working
without the technical teams is fruitlessly and can compromise
/ undermine compliance efforts, this is particularly clear when implementing privacy
by design principles.
Our decision to work with an ICT consultant in this regard, was influenced by this.
Conclusion
Large organisations have specialist functions that deal with specific aspects of regulation with consolidation being achieved at the apex. Smaller organisations may not do this and so consolidating data compliance into the overall regulatory compliance framework of the organisation, whether or not this feeds into the enterprise risk management framework.
Therefore, when conducting annual or regular legal audits, data compliance becomes a part of this regulatory risk management framework.
---
mzizi-africa.com
Compliance, simplified.

Comments
Post a Comment