SlideShare a Scribd company logo
GDPR Compliance program
Implementation overview (Draft)
by Tolu Falusi
September 2017
Approach
• An estimated six-month transition period to complete compliance readiness
implementation.
• Assumption – December 2017 will be treated as holiday/ freeze period
• System Testing and Penetration testing (security system) will start +4months
and overlap to +5months followed by a go-go/readiness review and go-live in
+6months.
• Data protection management system (DPMS) will be deployed as a global
implementation.
• Priority will be given to Knowledge acquisition, training and long lead items
such as staffing.
• DPMS support will be deployed directly following testing and handover to
DPO/BAU.
Transition team
Account Executive
Security manager
Program/Transition Manager
Legal/Contract manager
Service delivery Manager
Tools Implementation
manager (DPMS)
Developers, architects,
storage/Web/DB/QA managers
Testing Manager
GDPR Internal compliance team
DPO
DPO to be on-boarded
during implementation
Governance
FrequencyForum Membership Level
Chaired by
PM
Membership
Executive Sponsor
Program Manager
Steering
Committee
Bi-Monthly
Chaired by
PM
Membership
Program Manager
Workstream Leads
Project
Office
Weekly
Chaired By
PM/ Workstreams
Membership
WorkstreamWorkstream
Ad-
Hoc/Daily
Transition Methodology
TRANSITION GOVERNANCE
PLAN ASSESS DESIGN DEPLOY HANDOVER
Create, document and
publish access,
consent & information
process flow for
subjects.
Complete staffing.
Implement Data
Protection solutions:
 Security measures
 Encryption/Pseudony
misation
 Subject rights
 New protection and
processing policies/
processes/DPMS
 Breach reporting flow
 Third party contracts
 Testing
 Go – live support
 Training/KB
 International working
Assess and present
go-live readiness.
Develop governance
plan
Approve
implementation plan
Design project logs
Conduct kickoff
sessions
Initiate long lead
time tasks –
recruitment
Initiate staffing with
HR
Initiate
communications
plan
Coordinate data
processing
analysis and data
flow assessment
Document gaps
and proposed risk
mitigations
Create DPIA
template, process
& execute
Baseline DP
measures in place
Document location
& personal data
processing activities
Create data subject
access, information
sharing process &
DPIA templates
Create breach
reporting template
Create test plan and
test team
Create standard
reports
Review and
approve security &
data protection
measures design
Take action to meet
GDPR requirements
Regular assessment
and testing
Initiate performance
reporting
Initiate support
Handover to – DPO
and BAU
Conduct closure
review and lessons
learned
QUALITY GATE
Project Plan
QUALITY GATE
Gap analysis Report
QUALITY GATE
Docs, processes
& DPIA template
signed off
QUALITY GATE
Go-Live
Readiness
QUALITY GATE
Handover
artefacts
GDPR
READY
Implementation Schedule
Month 1 Month 2 Month 3 Month 4 Month 5
Kickoff
Plan ApprovalPlanning
Gap ReviewAssessment
HR - Recruiting / Onboarding / KB/Training
Design ApprovedDesign
Go/No Go Decision
Deploy
Milestones / Gate Reviews
Service Commencement
System testing Test complete, system
ready
DPMS ELS supportGo Live
DPMS Integration
GDPR compliant
Readiness review
Month 6
DPO onboard
DPMS ready
Milestones
Ref Major Milestones Due Date
1 Kick off meeting Month 1
2 Implementation plan approval Month 1
3 Assessment report/ Gap Log review Month 2
4 Tooling (DPMS) live Month 3
5 Design approval Month 4
6 Staffing - DPO/KB/Training complete Month 4
7 Security system test Month 4
8 Deploy stage sign off Month 5
9 Readiness review/ Go-no-go Month 5/6
10 Go Live Month 6
Risk Mitigation Risk Avoided
1Staffing Engage HR team immediately after Charter is
signed and closely track on-boarding status for
immediate escalation and response.
HR staffing to meet implementation
timeline, risk of not having resources
available to meet Service
Commencement timeline.
2Data location &
processing
model
Initiate data discovery and mapping, document
findings, gaps and current data processing
model to use as baseline to kick off GDPR
compliance project.
Difficulty in locating data or account for
personal data.
3Schedule Detailed transition schedule will be developed
during planning phase of transition
incorporating all GDPR requirements and
managed throughout the transition. Long lead
items will be started early to reduce risks at
service commencement (DPMS, training,
testing, KT, etc.)
Lack of clarity on the planned
implementation of GDPR compliance
exercise. DPMS tool can impact on
transition timeline – in case there is need
to train agents for additional tool
4Knowledge
Transfer
Joint governance program established with third
parties during Transition to ensure effective
communication, collaboration and co-operation
between all parties
Existing service providers withhold data
information or key knowledge or become
uncompromising and declines access.
5Communication Thorough communication plan developed
specific to GDPR education and implemented
during the transition period
Communication to all staff, including
potential change to data processing
model, security updates and disruption of
service if expected.
Potential risks and mitigations
Thank you
European data protection board
Lead Supervising authority
(Information commissioner’s office)
Processors
Controllers
(Organisations)
Data Subjects
(Individuals)
3rd Parties
3rd Countries
(Data transfer
destinations)
GDPR Structure
European data protection board
Lead Supervising authority
(Information commissioner’s office)
Processors
Controllers
(Organisations)
Data Subjects
(Individuals)
3rd Parties
3rd Countries
(Data transfer
destinations)

More Related Content

Similar to GDPR readiness overview presentation - Tolu Falusi

Disa Itsm V1.2
Disa Itsm V1.2Disa Itsm V1.2
Disa Itsm V1.2
djaehnig
 
Install PRESTO KPI in 5 weeks
Install PRESTO KPI in 5 weeksInstall PRESTO KPI in 5 weeks
Install PRESTO KPI in 5 weeks
TOPP Tactical Intelligence Ltd
 
A successful GDPR Program
A successful GDPR ProgramA successful GDPR Program
A successful GDPR Program
Alberto Canadè
 
Disa Itsm V1.3
Disa Itsm V1.3Disa Itsm V1.3
Disa Itsm V1.3
djaehnig
 
MG2015
MG2015MG2015
1Doug K. Brown PM 5-16-16 Res
1Doug K. Brown PM 5-16-16 Res1Doug K. Brown PM 5-16-16 Res
1Doug K. Brown PM 5-16-16 Res
Doug Brown
 
Data- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerData- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offer
Capgemini
 
Notes On Intranet Implementation And Roadmap
Notes On Intranet Implementation And RoadmapNotes On Intranet Implementation And Roadmap
Notes On Intranet Implementation And Roadmap
Alan McSweeney
 
PMO Proposal For Global Sales Operations
PMO Proposal For Global Sales OperationsPMO Proposal For Global Sales Operations
PMO Proposal For Global Sales Operations
tonyhinojosa
 
6 Steps to Transition Govt ICT effectiveness
6 Steps to Transition Govt ICT effectiveness6 Steps to Transition Govt ICT effectiveness
6 Steps to Transition Govt ICT effectiveness
Ravi Tirumalai
 
Project/Program Manager - Kjf13b1 chron
Project/Program Manager - Kjf13b1 chronProject/Program Manager - Kjf13b1 chron
Project/Program Manager - Kjf13b1 chron
KevinJosephFox
 
Erp implementation life cycle
Erp implementation life cycleErp implementation life cycle
Erp implementation life cycle
dass.spv@gmail.com pandiaraj
 
Saikat Mazumder_PMP
Saikat Mazumder_PMPSaikat Mazumder_PMP
Saikat Mazumder_PMP
Saikat Mazumder
 
Project Management in Health and Human Services
Project Management in Health and Human ServicesProject Management in Health and Human Services
Project Management in Health and Human Services
Brandon Olson
 
PMO 3.0 - Next Gen Lean Model - Doug Floyd
PMO 3.0 - Next Gen Lean Model - Doug FloydPMO 3.0 - Next Gen Lean Model - Doug Floyd
PMO 3.0 - Next Gen Lean Model - Doug Floyd
dvfloyd
 
Miro Data Preparation
Miro Data PreparationMiro Data Preparation
Miro Data Preparation
dlepore
 
A project portfolio management capability framework
A project portfolio management capability frameworkA project portfolio management capability framework
A project portfolio management capability framework
Robert Greca, PMP, SA
 
Project Management - 2015-06-12
Project Management - 2015-06-12Project Management - 2015-06-12
Project Management - 2015-06-12
Yves Francis
 
James dimas it infrastructure approach
James dimas it infrastructure approachJames dimas it infrastructure approach
James dimas it infrastructure approach
James (JD) Dimas
 
Project Management Methodologies
Project Management MethodologiesProject Management Methodologies
Project Management Methodologies
Monief Eid,Prince2,Prosci, Lean Six Sigma &ITIL
 

Similar to GDPR readiness overview presentation - Tolu Falusi (20)

Disa Itsm V1.2
Disa Itsm V1.2Disa Itsm V1.2
Disa Itsm V1.2
 
Install PRESTO KPI in 5 weeks
Install PRESTO KPI in 5 weeksInstall PRESTO KPI in 5 weeks
Install PRESTO KPI in 5 weeks
 
A successful GDPR Program
A successful GDPR ProgramA successful GDPR Program
A successful GDPR Program
 
Disa Itsm V1.3
Disa Itsm V1.3Disa Itsm V1.3
Disa Itsm V1.3
 
MG2015
MG2015MG2015
MG2015
 
1Doug K. Brown PM 5-16-16 Res
1Doug K. Brown PM 5-16-16 Res1Doug K. Brown PM 5-16-16 Res
1Doug K. Brown PM 5-16-16 Res
 
Data- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerData- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offer
 
Notes On Intranet Implementation And Roadmap
Notes On Intranet Implementation And RoadmapNotes On Intranet Implementation And Roadmap
Notes On Intranet Implementation And Roadmap
 
PMO Proposal For Global Sales Operations
PMO Proposal For Global Sales OperationsPMO Proposal For Global Sales Operations
PMO Proposal For Global Sales Operations
 
6 Steps to Transition Govt ICT effectiveness
6 Steps to Transition Govt ICT effectiveness6 Steps to Transition Govt ICT effectiveness
6 Steps to Transition Govt ICT effectiveness
 
Project/Program Manager - Kjf13b1 chron
Project/Program Manager - Kjf13b1 chronProject/Program Manager - Kjf13b1 chron
Project/Program Manager - Kjf13b1 chron
 
Erp implementation life cycle
Erp implementation life cycleErp implementation life cycle
Erp implementation life cycle
 
Saikat Mazumder_PMP
Saikat Mazumder_PMPSaikat Mazumder_PMP
Saikat Mazumder_PMP
 
Project Management in Health and Human Services
Project Management in Health and Human ServicesProject Management in Health and Human Services
Project Management in Health and Human Services
 
PMO 3.0 - Next Gen Lean Model - Doug Floyd
PMO 3.0 - Next Gen Lean Model - Doug FloydPMO 3.0 - Next Gen Lean Model - Doug Floyd
PMO 3.0 - Next Gen Lean Model - Doug Floyd
 
Miro Data Preparation
Miro Data PreparationMiro Data Preparation
Miro Data Preparation
 
A project portfolio management capability framework
A project portfolio management capability frameworkA project portfolio management capability framework
A project portfolio management capability framework
 
Project Management - 2015-06-12
Project Management - 2015-06-12Project Management - 2015-06-12
Project Management - 2015-06-12
 
James dimas it infrastructure approach
James dimas it infrastructure approachJames dimas it infrastructure approach
James dimas it infrastructure approach
 
Project Management Methodologies
Project Management MethodologiesProject Management Methodologies
Project Management Methodologies
 

Recently uploaded

Microsoft - Power Platform_G.Aspiotis.pdf
Microsoft - Power Platform_G.Aspiotis.pdfMicrosoft - Power Platform_G.Aspiotis.pdf
Microsoft - Power Platform_G.Aspiotis.pdf
Uni Systems S.M.S.A.
 
How to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For FlutterHow to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For Flutter
Daiki Mogmet Ito
 
20240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 202420240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 2024
Matthew Sinclair
 
Best 20 SEO Techniques To Improve Website Visibility In SERP
Best 20 SEO Techniques To Improve Website Visibility In SERPBest 20 SEO Techniques To Improve Website Visibility In SERP
Best 20 SEO Techniques To Improve Website Visibility In SERP
Pixlogix Infotech
 
UI5 Controls simplified - UI5con2024 presentation
UI5 Controls simplified - UI5con2024 presentationUI5 Controls simplified - UI5con2024 presentation
UI5 Controls simplified - UI5con2024 presentation
Wouter Lemaire
 
Full-RAG: A modern architecture for hyper-personalization
Full-RAG: A modern architecture for hyper-personalizationFull-RAG: A modern architecture for hyper-personalization
Full-RAG: A modern architecture for hyper-personalization
Zilliz
 
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with SlackLet's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
shyamraj55
 
Driving Business Innovation: Latest Generative AI Advancements & Success Story
Driving Business Innovation: Latest Generative AI Advancements & Success StoryDriving Business Innovation: Latest Generative AI Advancements & Success Story
Driving Business Innovation: Latest Generative AI Advancements & Success Story
Safe Software
 
Things to Consider When Choosing a Website Developer for your Website | FODUU
Things to Consider When Choosing a Website Developer for your Website | FODUUThings to Consider When Choosing a Website Developer for your Website | FODUU
Things to Consider When Choosing a Website Developer for your Website | FODUU
FODUU
 
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Speck&Tech
 
UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6
DianaGray10
 
Programming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup SlidesProgramming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup Slides
Zilliz
 
OpenID AuthZEN Interop Read Out - Authorization
OpenID AuthZEN Interop Read Out - AuthorizationOpenID AuthZEN Interop Read Out - Authorization
OpenID AuthZEN Interop Read Out - Authorization
David Brossard
 
Taking AI to the Next Level in Manufacturing.pdf
Taking AI to the Next Level in Manufacturing.pdfTaking AI to the Next Level in Manufacturing.pdf
Taking AI to the Next Level in Manufacturing.pdf
ssuserfac0301
 
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdfUnlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Malak Abu Hammad
 
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development ProvidersYour One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
akankshawande
 
GraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracyGraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracy
Tomaz Bratanic
 
Serial Arm Control in Real Time Presentation
Serial Arm Control in Real Time PresentationSerial Arm Control in Real Time Presentation
Serial Arm Control in Real Time Presentation
tolgahangng
 
Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024
Jason Packer
 
Generating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and MilvusGenerating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and Milvus
Zilliz
 

Recently uploaded (20)

Microsoft - Power Platform_G.Aspiotis.pdf
Microsoft - Power Platform_G.Aspiotis.pdfMicrosoft - Power Platform_G.Aspiotis.pdf
Microsoft - Power Platform_G.Aspiotis.pdf
 
How to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For FlutterHow to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For Flutter
 
20240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 202420240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 2024
 
Best 20 SEO Techniques To Improve Website Visibility In SERP
Best 20 SEO Techniques To Improve Website Visibility In SERPBest 20 SEO Techniques To Improve Website Visibility In SERP
Best 20 SEO Techniques To Improve Website Visibility In SERP
 
UI5 Controls simplified - UI5con2024 presentation
UI5 Controls simplified - UI5con2024 presentationUI5 Controls simplified - UI5con2024 presentation
UI5 Controls simplified - UI5con2024 presentation
 
Full-RAG: A modern architecture for hyper-personalization
Full-RAG: A modern architecture for hyper-personalizationFull-RAG: A modern architecture for hyper-personalization
Full-RAG: A modern architecture for hyper-personalization
 
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with SlackLet's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
 
Driving Business Innovation: Latest Generative AI Advancements & Success Story
Driving Business Innovation: Latest Generative AI Advancements & Success StoryDriving Business Innovation: Latest Generative AI Advancements & Success Story
Driving Business Innovation: Latest Generative AI Advancements & Success Story
 
Things to Consider When Choosing a Website Developer for your Website | FODUU
Things to Consider When Choosing a Website Developer for your Website | FODUUThings to Consider When Choosing a Website Developer for your Website | FODUU
Things to Consider When Choosing a Website Developer for your Website | FODUU
 
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
 
UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6
 
Programming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup SlidesProgramming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup Slides
 
OpenID AuthZEN Interop Read Out - Authorization
OpenID AuthZEN Interop Read Out - AuthorizationOpenID AuthZEN Interop Read Out - Authorization
OpenID AuthZEN Interop Read Out - Authorization
 
Taking AI to the Next Level in Manufacturing.pdf
Taking AI to the Next Level in Manufacturing.pdfTaking AI to the Next Level in Manufacturing.pdf
Taking AI to the Next Level in Manufacturing.pdf
 
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdfUnlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
 
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development ProvidersYour One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
 
GraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracyGraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracy
 
Serial Arm Control in Real Time Presentation
Serial Arm Control in Real Time PresentationSerial Arm Control in Real Time Presentation
Serial Arm Control in Real Time Presentation
 
Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024
 
Generating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and MilvusGenerating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and Milvus
 

GDPR readiness overview presentation - Tolu Falusi

  • 1. GDPR Compliance program Implementation overview (Draft) by Tolu Falusi September 2017
  • 2. Approach • An estimated six-month transition period to complete compliance readiness implementation. • Assumption – December 2017 will be treated as holiday/ freeze period • System Testing and Penetration testing (security system) will start +4months and overlap to +5months followed by a go-go/readiness review and go-live in +6months. • Data protection management system (DPMS) will be deployed as a global implementation. • Priority will be given to Knowledge acquisition, training and long lead items such as staffing. • DPMS support will be deployed directly following testing and handover to DPO/BAU.
  • 3. Transition team Account Executive Security manager Program/Transition Manager Legal/Contract manager Service delivery Manager Tools Implementation manager (DPMS) Developers, architects, storage/Web/DB/QA managers Testing Manager GDPR Internal compliance team DPO DPO to be on-boarded during implementation
  • 4. Governance FrequencyForum Membership Level Chaired by PM Membership Executive Sponsor Program Manager Steering Committee Bi-Monthly Chaired by PM Membership Program Manager Workstream Leads Project Office Weekly Chaired By PM/ Workstreams Membership WorkstreamWorkstream Ad- Hoc/Daily
  • 5. Transition Methodology TRANSITION GOVERNANCE PLAN ASSESS DESIGN DEPLOY HANDOVER Create, document and publish access, consent & information process flow for subjects. Complete staffing. Implement Data Protection solutions:  Security measures  Encryption/Pseudony misation  Subject rights  New protection and processing policies/ processes/DPMS  Breach reporting flow  Third party contracts  Testing  Go – live support  Training/KB  International working Assess and present go-live readiness. Develop governance plan Approve implementation plan Design project logs Conduct kickoff sessions Initiate long lead time tasks – recruitment Initiate staffing with HR Initiate communications plan Coordinate data processing analysis and data flow assessment Document gaps and proposed risk mitigations Create DPIA template, process & execute Baseline DP measures in place Document location & personal data processing activities Create data subject access, information sharing process & DPIA templates Create breach reporting template Create test plan and test team Create standard reports Review and approve security & data protection measures design Take action to meet GDPR requirements Regular assessment and testing Initiate performance reporting Initiate support Handover to – DPO and BAU Conduct closure review and lessons learned QUALITY GATE Project Plan QUALITY GATE Gap analysis Report QUALITY GATE Docs, processes & DPIA template signed off QUALITY GATE Go-Live Readiness QUALITY GATE Handover artefacts GDPR READY
  • 6. Implementation Schedule Month 1 Month 2 Month 3 Month 4 Month 5 Kickoff Plan ApprovalPlanning Gap ReviewAssessment HR - Recruiting / Onboarding / KB/Training Design ApprovedDesign Go/No Go Decision Deploy Milestones / Gate Reviews Service Commencement System testing Test complete, system ready DPMS ELS supportGo Live DPMS Integration GDPR compliant Readiness review Month 6 DPO onboard DPMS ready
  • 7. Milestones Ref Major Milestones Due Date 1 Kick off meeting Month 1 2 Implementation plan approval Month 1 3 Assessment report/ Gap Log review Month 2 4 Tooling (DPMS) live Month 3 5 Design approval Month 4 6 Staffing - DPO/KB/Training complete Month 4 7 Security system test Month 4 8 Deploy stage sign off Month 5 9 Readiness review/ Go-no-go Month 5/6 10 Go Live Month 6
  • 8. Risk Mitigation Risk Avoided 1Staffing Engage HR team immediately after Charter is signed and closely track on-boarding status for immediate escalation and response. HR staffing to meet implementation timeline, risk of not having resources available to meet Service Commencement timeline. 2Data location & processing model Initiate data discovery and mapping, document findings, gaps and current data processing model to use as baseline to kick off GDPR compliance project. Difficulty in locating data or account for personal data. 3Schedule Detailed transition schedule will be developed during planning phase of transition incorporating all GDPR requirements and managed throughout the transition. Long lead items will be started early to reduce risks at service commencement (DPMS, training, testing, KT, etc.) Lack of clarity on the planned implementation of GDPR compliance exercise. DPMS tool can impact on transition timeline – in case there is need to train agents for additional tool 4Knowledge Transfer Joint governance program established with third parties during Transition to ensure effective communication, collaboration and co-operation between all parties Existing service providers withhold data information or key knowledge or become uncompromising and declines access. 5Communication Thorough communication plan developed specific to GDPR education and implemented during the transition period Communication to all staff, including potential change to data processing model, security updates and disruption of service if expected. Potential risks and mitigations
  • 10. European data protection board Lead Supervising authority (Information commissioner’s office) Processors Controllers (Organisations) Data Subjects (Individuals) 3rd Parties 3rd Countries (Data transfer destinations) GDPR Structure European data protection board Lead Supervising authority (Information commissioner’s office) Processors Controllers (Organisations) Data Subjects (Individuals) 3rd Parties 3rd Countries (Data transfer destinations)