Three Things to Consider when Setting Up Data Compliance

This article seeks to highlight three items that we consider to be important when it comes to #data compliance.

It is based on the work that we are doing to support organisations implement or strengthen data compliance systems. 

1. Apply the age-old #compliance frameworks when implementing data compliance.
 The framework is tried and tested and provides a useful implementation framework that covers:
- policies and procedures (including code of conduct and #ethics),
- effective #communication (hotline),
- training,
- compliance office (outsourced or in-house),
- #audit and monitoring,
- consequence/accountability management, and
- third party transactions.

You will note that registration with the Office of the Data Protection Commissioner (ODPC) is not listed as an element on its own.

Registration is a necessary but not sufficient aspect of compliance.

In fact, we consider registration, particularly the declarations made in that process, as exposing  organisations to compliance #risks relating to incorrect / misleading disclosures.

To illustrate, review the declarations made during registration, specifically the #data processing activities and technical measures, against actual practice. Do those declarations replicate existing structures
and practices that support the declarations made or do we congratulate your firm for fulfilling yet another tick-box exercise?

2. Benchmark against global, not just local, legislation.

We live in a global village, and #Kenya is a regional hub. The probability that your organisation is processing other nationalities' data is high.

The ODPC is increasingly, based on last year activities, looking to the EU to develop jurisprudence on data compliance.

This is why, in designing 350-point
MZIZI-Audit tool, we looked to gold standards in data compliance for inspiration.

The compliance team need to continuously update their understanding of these standards/emerging jurisprudence as part of their continous development.

3. Involve the ICT Teams.
Legislation does not exist in a vacuum. Data legislation seeks to influence how organisations process data. This data is stored in systems, and data may be baked into an organisation's business model.

Working without the technical teams is fruitlessly and can compromise / undermine compliance efforts, this is particularly clear when implementing privacy by design principles.

Our decision to work with an ICT consultant in this regard, was influenced by this.  

Conclusion

 Large organisations have specialist functions that deal with specific aspects of regulation with consolidation being achieved at the apex. Smaller organisations may not do this and so consolidating data compliance into the overall regulatory compliance framework of the organisation, whether or not this feeds into the enterprise risk management framework. 

Therefore, when conducting annual or regular legal audits, data compliance becomes a part of this regulatory risk management framework.
---
mzizi-africa.com
Compliance, simplified.

Comments

Popular posts from this blog

10 Compliance Movies & Lessons

Data Privacy Risks of Recycled Phone Numbers

Cultivating Ethical Cultures through Technology: The Case for a Policy Management System