Our method
Home / Expertise / Privacy / Our method

Our method

The EU’s General Data Protection Regulation (GDPR) can seem overwhelming. To help you keep track of things and break it down into manageable chunks, we have developed an implementation method tailored to the regulation. Gain an understanding in phase 1 and an overview in phase 2. The heavy lifting comes in phases 3 and 4. In phase 5, you can breathe a sigh of relief, but don’t rest on your laurels.

The method

Phase 1: Establish the team

Data protection involves large parts of the organisation. Data protection projects vary, but typically encompass IT, marketing, HR, operations and legal. The project must have the support of senior management – and preferably the board – if it is to succeed.

  • The aim of the introduction is to create a general understanding of what data protection is and what strategic significance it may have for your business.

    We offer a workshop in which we present to management what data protection is, the key requirements of the GDPR and what they mean for your business, as well as providing suggestions for further work.

    Your organisation should provide managers and other personnel responsible for compliance with data protection regulations.

  • To ensure compliance with the regulations, your organisation must understand the rules and organise itself appropriately.

    Basic training and organisation include:

    • basic training on current data protection requirements
    • basic training on the requirements of the GDPR
    • setting up teams
    • assistance with drawing up plans for future work
    • allocation and description of responsibilities for different roles

Phase 2: Analysis

To determine what measures are required for your organisation to comply with data protection regulations, we need to assess what is already in place. The results of the gap analysis will determine the measures to be taken in your GDPR project.

We can help you carry out such a gap analysis and implement the necessary measures.

  • Once the gap analysis has given you an overview of what you have in place and what you are missing, you can finally begin planning the work involved in implementing measures to ensure GDPR compliance.

    We will help you choose a strategy to close the gaps identified in the gap analysis through two 2-hour workshops. The chosen strategy will be summarised in a written data protection strategy.

    Your organisation will provide representatives responsible for:

    • IT systems and data flows
    • IT security
    • Human Resources (HR)
    • Legal officer (if applicable)
    • Quality manager
    • Overall manager responsible for reporting to the managing director
    • Others who can contribute to the data protection project

    Estimated time: One to four weeks, depending on the intensity and scope of the necessary measures.

  • You do not need to actively provide any personal information in order to use this website.

    When you visit our website, we automatically receive the web address of the website you came from or are going to. This is because that is how internet communication standards work. We also collect information about which pages you visit on our site, your IP address, the type of browser you use and how many times you have visited our website.

    We use this information to compile statistics on visits to our website, not to contact you.

    When you visit our website, we may use cookies to improve your user experience. A cookie is a text file that is stored in your browser's cache when you visit a website. You are free to disable cookies, although this may affect your online experience. Check your browser settings to see if this is possible.

    By using our website, you consent to this collection of information about you.

    Please contact us if you would like further information on this matter.

  • Once the gap analysis, privacy strategy and need for a Data Protection Officer (DPO) have been clarified, it becomes possible to budget for progress and costs.

    We can help you budget for the costs of

    • the establishment or upgrading of internal control procedures
    • the possible establishment of Binding Corporate Rules (BCR)
    • the establishment or upgrading of documentation
    • organisational measures
    • technical measures
    • DPO (in-house or external)

    and drawing up an implementation plan.

    The organisation provides the implementation team, existing procedures, rules, documentation and an overview of measures.

  • By carrying out a gap analysis in phase 2, you will gain an indication of the scope of the work required to comply with the GDPR. Through the analysis, you will gain an overview of

    • current data processing, categories of data and data flows
    • the use of IT systems and data flows between them
    • existing procedures and documentation
    • internal organisation
    • existing data security
    • contractual relationships with external suppliers

    In other words: what you currently have in place. By comparing this with the new requirements of the GDPR, you can determine the level of compliance within your organisation.

    We can help you to

    • draw up tables and checklists
    • gain an overview of data types, types of processing and legal bases for processing
    • identify the necessary technical and organisational measures for information security and other compliance requirements
  • In addition to the liability the business faces following the implementation of the GDPR, the board and the managing director may incur personal liability. Such liability may arise if the company, and consequently its shareholders, suffer losses as a result of, for example:

    • the high fines permitted under the GDPR (up to 4 per cent of annual group turnover)
    • remedial measures in the event of a data breach
    • notification costs in the event of a data breach
    • losses due to disruption

    To determine responsibility, the organisation provides:

Phase 3: Establish routines

Once the needs have been identified during the analysis phase (phase 2), you can begin planning. Below are key elements that should be considered. We’ll help you identify relevant measures.

  • To process personal data lawfully, you must have a so-called legal basis for processing. This could, for example, be consent or a statutory basis.

    We can help you with

    • assessing consent
    • systems for managing these
    • providing adequate information to data subjects
    • assessing other legal bases for processing (legal bases other than consent)
    • summary report
  • The GDPR requires that

    • the organisation implement technical and organisational measures to ensure compliance with the rules
    • these must be systematic and set out in guidelines within an internal control system

    When the Data Protection Authority carries out an inspection, the internal control documents are the first thing they ask to see.

    Based on the gap analysis, your privacy strategy and your legal basis for processing, we will help you to

    • identify the type of processing taking place
    • assess the risks associated with the processing
    • draw up a template for internal guidelines
    • tailor the guidelines specifically to your organisation
  • A privacy policy ensures that you provide data subjects with sufficient information about the processing of their personal data.

    We can help you draft privacy notices in the relevant languages.

  • To be able to meet the tight deadlines set out in the GDPR and to minimise reputational damage in the event of data breaches and other incidents, you need to know who is responsible for what and when.

    We can help you with:

    • Establishing procedures for data breaches and other incidents
    • Basic training for designated personnel
    • Standard templates for information
    • Drawing up an overview of assistance requirements

    as part of a written contingency plan.

    We can also provide immediate assistance if an incident occurs.

  • If you are transferring personal data to countries outside the EEA, specific rules apply. The aim is to ensure that the data is processed appropriately in the recipient country as well.

    We can help you identify the most appropriate legal basis for such a transfer.

  • The GDPR requires organisations to ensure that privacy is built into data processing – from collection and use to deletion.

    Bear data protection by design in mind when developing or procuring IT systems for your organisation.See the Checklist for data protection by design here.

    We can help you assess the lawful

    • amount of data and how to minimise data
    • the duration of the processing
    • scope of processing
    • access to the data
    • default settings

    and identify the necessary technical measures.

    These include:

    • adaptation of processes, IT infrastructure and applications
    • review of process flows and system architecture
  • If you wish to appoint or are required to appoint a Data Protection Officer, this role can be filled by an internal or external candidate.

    If you wish to appoint an in-house Data Protection Officer, they must be appointed on the basis of:

    • Professional expertise, in particular specialist knowledge of data protection law
    • Ability to carry out the tasks assigned to the data protection officer under the Regulation

    We can assist with the necessary training and the definition of procedures and tasks.

    If you wish to engage an external data protection officer as a service, we at Advokatfirmaet Bull AS can fulfil this role.

  • The GDPR encourages the establishment of industry standards. Compliance with these standards will simplify compliance with the Regulation, typically for businesses within a single sector.

    We can assist in drawing up industry standards for a trade association or industry body. This will be based on one or more workshops and will result in a written set of industry standards.

    Your organisation or relevant stakeholders will provide:

    • Experts covering technical and organisational aspects of the
      relevant sector
    • Existing industry standards and the like (if available)

    Expected duration: Four to 26 weeks, depending on the intensity, complexity and consultation practices.

  • The GDPR allows organisations to obtain certification to demonstrate compliance with the regulation. The advantage is greater assurance that all requirements are met. This reduces the risk of data breaches and fines.

    The certification scheme is currently little discussed and underdeveloped, and the period leading up to May 2018 will reveal how this scheme is to be implemented.

    Please get in touch if your organisation is interested in being certified as compliant with the EU General Data Protection Regulation.

  • If your organisation concludes that you need a data protection officer, the question arises as to how this important role should be filled. The GDPR allows for the role of data protection officer to be carried out by external service providers – such as lawyers.

    Outsourcing this role may be of interest to organisations that wish to:

    • avoid investing significant resources in training their own staff to become data protection experts
    • gain flexibility
    • ensure impartiality
    • keep abreast of regulatory changes and the like
    • document compliance
    • reduce liability

    As an ‘in-house data protection officer’, we help your organisation draw up job descriptions, documentation, task lists and carry out all other tasks for which a data protection officer is responsible.

    Please contact us for more information.

Phase 4: Implement

You’re almost there! In this phase, implementation is key – and the whole organisation needs to be on board.

  • In Phase 4, we assume that your organisation has already put in place elements of internal control in the form of

    • a description of how the organisation structures its work relating to data protection and internal controls (policy documentation), including a description of the data protection strategy and data security procedures.
    • a set of procedures and guidelines describing how you comply with the requirements of the GDPR (operational documentation)

    Phase 4 focuses on the monitoring aspect of internal control. Here, the organisation must ensure that internal control procedures are adhered to.

    We can help you put together internal control procedures that ensure compliance with all measures implemented within the organisation, with a focus on the requirements of the GDPR.

  • Information security is critically important for the entire organisation, not just for data protection. The obligations under the GDPR apply to both technical and organisational measures.

    We can help you implement the requirements for information security, both technical and organisational.

  • There is little point in having robust, documented procedures and secure IT systems if staff do not follow the procedures or consider information security. The GDPR sets out requirements for organisational measures and for these to be documented. This includes the existence of a security culture.

    In a case of so-called ‘CEO fraud’, a Norwegian company was defrauded of around 60 million euros. This was achieved through a single phone call and two emails.

    We are working on changes to and the assessment of security culture (through documentation) in collaboration with experts in the field.

  • For staff to be able to comply with the GDPR, they must be familiar with the requirements, the organisation’s privacy policy and/or internal controls, as well as the organisation’s data security rules.

    We can assist you with traditional training courses, webinars or e-learning.

    We can help you

    • set up a training system for data protection
    • data protection training
    • technical training
    • organisational development
  • The much-discussed right to be forgotten is, in reality, a right to have one’s data erased. Erasure must take place both when the data subject requests it and when the purpose has been fulfilled.

  • The hefty fines under the GDPR are not the only reason why you’ll want to detect data breaches as quickly as possible. The risk of revenue loss and claims for compensation can be significantly reduced if data security breaches are detected promptly.

    Detect:

    • whether a breach has occurred
    • how it happened
    • who is affected
    • what data is affected

    You should also consider putting in place a technical solution for notifying those affected.

  • The GDPR gives data subjects the right to request that their personal data be transferred to another data controller or data processor, using a commonly used medium and format. The requirement set out in the Regulation stipulates:

    • Technical system support
    • Organisational support
    • Legal delimitation of data

    Here at Bull we can help you draw the line in the sand regarding which data should be disclosed.

  • Once privacy policies have been drafted in phase 3, they must be implemented technically. The GDPR also requires that the consent itself (as given in such policies) must be documented.

Phase 5: Operations

Once the implementation in Phase 4 has been completed, a new routine begins with a focus on data protection. In this phase, you will need tools and organisational structures that make compliance easier.

  • To keep the organisation up to date with developments in data protection regulations, we have established the Bull Data Protection Network. The network meets twice a year. You will receive

    • an overview of changes to regulations and practices
    • ask us questions
    • discuss issues confidentially within the group
    • information on practical tools and resources
  • If you’ve prepared yourself, incidents will be easier to handle. In any case, we can help you should an accident occur. Typically, we’ll be able to help you with

    • assessing whether you need to report a non-conformity
    • what information to provide to the individual and the Data Protection Authority
    • what measures should be taken

    Get in touch, and we’ll help you minimise the impact.

  • Good procedural guidelines and secure IT systems are of little use if your staff do not follow the procedures and do not prioritise security. The GDPR also sets out requirements for organisational measures and the documentation of these. This encompasses security culture.

    In a so-called CEO fraud case, a Norwegian company was defrauded of around half a billion kroner following a single phone call and two emails.

    We work with experts in change management and the measurement (documentation) of security culture.

Contact us to learn more

Articles on the subject