SlideShare a Scribd company logo
1 of 33
Download to read offline
© 2018 FORRESTER. REPRODUCTION PROHIBITED.
© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Shift from GDPR readiness to
sustained compliance to improve your
business and your customer experience
Enza Iannopollo, Analyst
3© 2018 FORRESTER. REPRODUCTION PROHIBITED.
4© 2018 FORRESTER. REPRODUCTION PROHIBITED.
5© 2017 Forrester Research, Inc. Reproduction Prohibited
Customer consent was a given
6© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Privacy Policies were unreadable
7© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Customers
would never
refuse a cookie
8© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Customers’ data
was firms’
prisoners
forever
9© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Privacy and
security risks
were not on
customers’ mind
10© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Disclosure of
data to the
wrong
customers was a
common mistake
Cash withdrawal notice from
Banco del Austro informs you that has been made (a)
withdrawal from BANRED 02550009-CPN-ATM0009 -
THE PINTAMATRIZ QUITO EC EC on 2018/05/09
072734 4931XXXXXXXX7839 your card for $ 20.50.
If this transaction was not authorized contact Customer
Service at 1800-228787 or 07-2832500.
11© 2018 FORRESTER. REPRODUCTION PROHIBITED.
12© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Welcome to a GDPR-compliant world
13© 2018 FORRESTER. REPRODUCTION PROHIBITED.
14© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Consent is an opportunity to build trust & engagement
15© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Privacy Policies
are user-friendly
and inspire trust
in the brand
16© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Cookies require
clear and
specific consent
17© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Flexible and
transparent data
architecture
supports data
subject rights
18© 2018 FORRESTER. REPRODUCTION PROHIBITED.
And the customers?
19© 2018 FORRESTER. REPRODUCTION PROHIBITED.
https://www.forrester.com/report/Best+Practices+For+Privacy+And+GDPR+In+Financial+Services/-/E-RES133848
74% of consumers are ready to switch to a competitor
if their bank or insurer suffered a data breach
20© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Security and privacy concerns deter 47%
from using digital channels
https://www.forrester.com/report/Best+Practices+For+Privacy+And+GDPR+In+Financial+Services/-/E-RES133848
21© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Source: Forrester’s market research online community (MROC), 2017
– I will be more
knowledgeable about who
uses my information
– I will feel more comfortable
about using the internet
– It will get much better as I
will be able to ask for info
to be deleted
I hope my online experience
becomes less targeted and
more generic. I hate when
websites tracks what I view
and then target me with
advertising based on my
browsing history.
“
“
“
“
Privacy and GDPR are key to build trust
22© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Consumers will request their information be deleted and
their data not used for marketing purposes
Base: British Online Adults (18+) 3,285
Source: Consumer Technographics Online Benchmark and Recontacts, 2018
18%
14%
11%
11%
30%
32%
27%
27%
52%
56%
62%
63%
Request a copy of the information companies have about
me
Ask companies to correct or update information they have
about me
Request that companies not profile me for marketing
purposes
Ask companies to delete information about me
Not likely (1,2) Middle (3) Likely (4,5)
How likely are you to exercise the following rights related to
General Data Protection Regulation (GDPR)?
23© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Violations of the
rules – including
failure to
properly identify
and verify
customers’
identity – will be
expensive
1. Additional security requirements as a
result of enforcement action
2. Diminished customer trust
3. Reputational damage
4. Privacy abuses
5. Regulatory fines
24© 2018 FORRESTER. REPRODUCTION PROHIBITED.
25© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Fully compliant
29%
Compliant by
May 2018
20%
All others
51%
49%
Which of the following best describes your firm’s GDPR
compliance efforts?
Base: 3,195 global security decision makers at the manager level and above
Source: Forrester Data Global Business Technographics® Security Survey, May 2017
A lot of work
remains to be
done
26© 2018 FORRESTER. REPRODUCTION PROHIBITED.
May 2018 was
just a starting
block
27© 2018 FORRESTER. REPRODUCTION PROHIBITED.
GDPR Compliance is an ongoing journey…
28© 2018 FORRESTER. REPRODUCTION PROHIBITED.
…Shift your strategy from GDPR
readiness to sustained compliance
29© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Recommendations for less mature programs
› Be part of a interdisciplinary team leading the GDPR program
› Build a gap analysis about high risk data processing activities
• Sensitive personal data
• Cloud
• Third party data sharing
› Adopt a risk assessment framework
› Build a compliance roadmap and document progress as you
execute
› Prioritize remediation on consent, re-consent, and data subject
rights
30© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Recommendations for intermediate programs
› Expand your data mapping and gap analysis to third parties
› Review third-party contracts, SLAs, and perform due diligence
› Focus on governance, processes, and people’s skills as you move
forward in your implementation plan
› Build identity verification into your data subject right processes
› Execute consent and re-consent strategies quickly
› Collect evidence of your compliance efforts and progress on an
ongoing basis.
31© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Recommendations for advanced programs
› Leverage automated discovery and classification of data to feed
into your compliance software and risk assessment frameworks
› Augment your third party risk management frameworks
› Expand the scope of the program to include CX, marketing, and
digital teams to design the “privacy experience” of your customers
› Optimise the process to support “privacy by-design”
› Roll out GDPR training to all employees
› Measure the progress of your GDPR compliance program against
broader business goals
32© 2017 FORRESTER. REPRODUCTION PROHIBITED.
GDPR compliance programs deliver business benefits
1. Improved customer experience
2. Better understanding of data assets and improved data strategies
3. More mature and articulated data governance practices across the
organization
4. Better privacy policy management
5. A more solid (or a new) corporate culture for data privacy
FORRESTER.COM
Thank you
© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Enza Iannopollo
+44 (0)20 7323 7634
eiannopollo@forrester.com

More Related Content

What's hot

The Value of User and Data Centricity Beyond IoT Devices: Stein Myrseth and G...
The Value of User and Data Centricity Beyond IoT Devices: Stein Myrseth and G...The Value of User and Data Centricity Beyond IoT Devices: Stein Myrseth and G...
The Value of User and Data Centricity Beyond IoT Devices: Stein Myrseth and G...ForgeRock
 
Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...
Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...
Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...ForgeRock
 
Digital Identities in the Internet of Things - Securely Manage Devices at Scale
Digital Identities in the Internet of Things - Securely Manage Devices at ScaleDigital Identities in the Internet of Things - Securely Manage Devices at Scale
Digital Identities in the Internet of Things - Securely Manage Devices at ScaleForgeRock
 
Gartner - ForgeRock Identity Live 2017 - Dusseldorf
Gartner - ForgeRock Identity Live 2017 - DusseldorfGartner - ForgeRock Identity Live 2017 - Dusseldorf
Gartner - ForgeRock Identity Live 2017 - DusseldorfForgeRock
 
The Road to Intelligent Authentication Journeys
The Road to Intelligent Authentication JourneysThe Road to Intelligent Authentication Journeys
The Road to Intelligent Authentication JourneysForgeRock
 
Applying Innovative Tools for GDPR Success
Applying Innovative Tools for GDPR SuccessApplying Innovative Tools for GDPR Success
Applying Innovative Tools for GDPR SuccessForgeRock
 
Identity Live in Austin Keynote
Identity Live in Austin Keynote Identity Live in Austin Keynote
Identity Live in Austin Keynote ForgeRock
 
Amer Sports - ForgeRock Identity Live - Dusseldorf
Amer Sports - ForgeRock Identity Live - DusseldorfAmer Sports - ForgeRock Identity Live - Dusseldorf
Amer Sports - ForgeRock Identity Live - DusseldorfForgeRock
 
Identity Live Sydney 2018 Keynote Presentation
Identity Live Sydney 2018 Keynote PresentationIdentity Live Sydney 2018 Keynote Presentation
Identity Live Sydney 2018 Keynote PresentationForgeRock
 
Customer Safeguarding, Fraud and GDPR: Manah Khalil
Customer Safeguarding, Fraud and GDPR: Manah KhalilCustomer Safeguarding, Fraud and GDPR: Manah Khalil
Customer Safeguarding, Fraud and GDPR: Manah KhalilForgeRock
 
GDPR is coming in Hot. Top Burning Questions Answered to Help You Keep Your C...
GDPR is coming in Hot. Top Burning Questions Answered to Help You Keep Your C...GDPR is coming in Hot. Top Burning Questions Answered to Help You Keep Your C...
GDPR is coming in Hot. Top Burning Questions Answered to Help You Keep Your C...ForgeRock
 
The ForgeRock Identity Platform Extends CIAM, Fall 2017 Release
The ForgeRock Identity Platform Extends CIAM, Fall 2017 ReleaseThe ForgeRock Identity Platform Extends CIAM, Fall 2017 Release
The ForgeRock Identity Platform Extends CIAM, Fall 2017 ReleaseForgeRock
 
Identity Live Sydney 2017 - Tim Sheedy
Identity Live Sydney 2017 - Tim SheedyIdentity Live Sydney 2017 - Tim Sheedy
Identity Live Sydney 2017 - Tim SheedyForgeRock
 
Go Beyond PSD2 Compliance with Digital Identity
Go Beyond PSD2 Compliance with Digital Identity Go Beyond PSD2 Compliance with Digital Identity
Go Beyond PSD2 Compliance with Digital Identity ForgeRock
 
Implications of GDPR in Conjunction with UMA
Implications of GDPR in Conjunction with UMAImplications of GDPR in Conjunction with UMA
Implications of GDPR in Conjunction with UMAForgeRock
 
Using Identity to Empower the Enterprise: Identity Relationship Management
Using Identity to Empower the Enterprise: Identity Relationship ManagementUsing Identity to Empower the Enterprise: Identity Relationship Management
Using Identity to Empower the Enterprise: Identity Relationship ManagementForgeRock
 
Identity Live London 2017 | Marko Orenius
Identity Live London 2017 | Marko OreniusIdentity Live London 2017 | Marko Orenius
Identity Live London 2017 | Marko OreniusForgeRock
 
Identity Live Paris 2017 | Marko Orenius, Amer Sports
Identity Live Paris 2017 | Marko Orenius, Amer SportsIdentity Live Paris 2017 | Marko Orenius, Amer Sports
Identity Live Paris 2017 | Marko Orenius, Amer SportsForgeRock
 
IAM for the Masses: Managing Consumer Identities
IAM for the Masses: Managing Consumer Identities IAM for the Masses: Managing Consumer Identities
IAM for the Masses: Managing Consumer Identities ForgeRock
 
Identity Summit UK: HOW TO MAXIMIZE RETURN ON IDENTITY IN A BRAVE NEW WORLD
Identity Summit UK: HOW TO MAXIMIZE RETURN ON IDENTITY IN A BRAVE NEW WORLDIdentity Summit UK: HOW TO MAXIMIZE RETURN ON IDENTITY IN A BRAVE NEW WORLD
Identity Summit UK: HOW TO MAXIMIZE RETURN ON IDENTITY IN A BRAVE NEW WORLDForgeRock
 

What's hot (20)

The Value of User and Data Centricity Beyond IoT Devices: Stein Myrseth and G...
The Value of User and Data Centricity Beyond IoT Devices: Stein Myrseth and G...The Value of User and Data Centricity Beyond IoT Devices: Stein Myrseth and G...
The Value of User and Data Centricity Beyond IoT Devices: Stein Myrseth and G...
 
Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...
Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...
Trust is Everything - The Future of Identity and the ForgeRock Platform (Iden...
 
Digital Identities in the Internet of Things - Securely Manage Devices at Scale
Digital Identities in the Internet of Things - Securely Manage Devices at ScaleDigital Identities in the Internet of Things - Securely Manage Devices at Scale
Digital Identities in the Internet of Things - Securely Manage Devices at Scale
 
Gartner - ForgeRock Identity Live 2017 - Dusseldorf
Gartner - ForgeRock Identity Live 2017 - DusseldorfGartner - ForgeRock Identity Live 2017 - Dusseldorf
Gartner - ForgeRock Identity Live 2017 - Dusseldorf
 
The Road to Intelligent Authentication Journeys
The Road to Intelligent Authentication JourneysThe Road to Intelligent Authentication Journeys
The Road to Intelligent Authentication Journeys
 
Applying Innovative Tools for GDPR Success
Applying Innovative Tools for GDPR SuccessApplying Innovative Tools for GDPR Success
Applying Innovative Tools for GDPR Success
 
Identity Live in Austin Keynote
Identity Live in Austin Keynote Identity Live in Austin Keynote
Identity Live in Austin Keynote
 
Amer Sports - ForgeRock Identity Live - Dusseldorf
Amer Sports - ForgeRock Identity Live - DusseldorfAmer Sports - ForgeRock Identity Live - Dusseldorf
Amer Sports - ForgeRock Identity Live - Dusseldorf
 
Identity Live Sydney 2018 Keynote Presentation
Identity Live Sydney 2018 Keynote PresentationIdentity Live Sydney 2018 Keynote Presentation
Identity Live Sydney 2018 Keynote Presentation
 
Customer Safeguarding, Fraud and GDPR: Manah Khalil
Customer Safeguarding, Fraud and GDPR: Manah KhalilCustomer Safeguarding, Fraud and GDPR: Manah Khalil
Customer Safeguarding, Fraud and GDPR: Manah Khalil
 
GDPR is coming in Hot. Top Burning Questions Answered to Help You Keep Your C...
GDPR is coming in Hot. Top Burning Questions Answered to Help You Keep Your C...GDPR is coming in Hot. Top Burning Questions Answered to Help You Keep Your C...
GDPR is coming in Hot. Top Burning Questions Answered to Help You Keep Your C...
 
The ForgeRock Identity Platform Extends CIAM, Fall 2017 Release
The ForgeRock Identity Platform Extends CIAM, Fall 2017 ReleaseThe ForgeRock Identity Platform Extends CIAM, Fall 2017 Release
The ForgeRock Identity Platform Extends CIAM, Fall 2017 Release
 
Identity Live Sydney 2017 - Tim Sheedy
Identity Live Sydney 2017 - Tim SheedyIdentity Live Sydney 2017 - Tim Sheedy
Identity Live Sydney 2017 - Tim Sheedy
 
Go Beyond PSD2 Compliance with Digital Identity
Go Beyond PSD2 Compliance with Digital Identity Go Beyond PSD2 Compliance with Digital Identity
Go Beyond PSD2 Compliance with Digital Identity
 
Implications of GDPR in Conjunction with UMA
Implications of GDPR in Conjunction with UMAImplications of GDPR in Conjunction with UMA
Implications of GDPR in Conjunction with UMA
 
Using Identity to Empower the Enterprise: Identity Relationship Management
Using Identity to Empower the Enterprise: Identity Relationship ManagementUsing Identity to Empower the Enterprise: Identity Relationship Management
Using Identity to Empower the Enterprise: Identity Relationship Management
 
Identity Live London 2017 | Marko Orenius
Identity Live London 2017 | Marko OreniusIdentity Live London 2017 | Marko Orenius
Identity Live London 2017 | Marko Orenius
 
Identity Live Paris 2017 | Marko Orenius, Amer Sports
Identity Live Paris 2017 | Marko Orenius, Amer SportsIdentity Live Paris 2017 | Marko Orenius, Amer Sports
Identity Live Paris 2017 | Marko Orenius, Amer Sports
 
IAM for the Masses: Managing Consumer Identities
IAM for the Masses: Managing Consumer Identities IAM for the Masses: Managing Consumer Identities
IAM for the Masses: Managing Consumer Identities
 
Identity Summit UK: HOW TO MAXIMIZE RETURN ON IDENTITY IN A BRAVE NEW WORLD
Identity Summit UK: HOW TO MAXIMIZE RETURN ON IDENTITY IN A BRAVE NEW WORLDIdentity Summit UK: HOW TO MAXIMIZE RETURN ON IDENTITY IN A BRAVE NEW WORLD
Identity Summit UK: HOW TO MAXIMIZE RETURN ON IDENTITY IN A BRAVE NEW WORLD
 

Similar to Shift from GDPR readiness to sustained compliance to improve your business and your customer experience (Identity Live Berlin 2018)

GDPR: Data Privacy in the New
GDPR: Data Privacy in the NewGDPR: Data Privacy in the New
GDPR: Data Privacy in the Newaccenture
 
General Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) ComplianceGeneral Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) Complianceaccenture
 
Looking Beyond GDPR Compliance Deadline
Looking Beyond GDPR Compliance DeadlineLooking Beyond GDPR Compliance Deadline
Looking Beyond GDPR Compliance Deadlineaccenture
 
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPRSrijan Technologies
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowIntegrate
 
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides DATUM LLC
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...CIO Edge
 
GDPR & Demand Generation: What Your Team Needs To Know
GDPR & Demand Generation: What Your Team Needs To KnowGDPR & Demand Generation: What Your Team Needs To Know
GDPR & Demand Generation: What Your Team Needs To KnowHannah Flynn
 
Data Privacy and the GDPR
Data Privacy and the GDPRData Privacy and the GDPR
Data Privacy and the GDPRDemandbase
 
GDPR & Data Privacy Guide - Free Download
GDPR & Data Privacy Guide - Free DownloadGDPR & Data Privacy Guide - Free Download
GDPR & Data Privacy Guide - Free DownloadVisitor Analytics
 
Are you GDPR Ready? Checklist Whitepaper
Are you GDPR Ready? Checklist WhitepaperAre you GDPR Ready? Checklist Whitepaper
Are you GDPR Ready? Checklist WhitepaperServersys
 
Rethinking Trust in Data
Rethinking Trust in Data Rethinking Trust in Data
Rethinking Trust in Data DATAVERSITY
 
The GDPR - A data revolution
The GDPR - A data revolutionThe GDPR - A data revolution
The GDPR - A data revolutionDan Brookman
 
How GDPR Guidelines Regulate Marketing Automation and Customer Engagement
How GDPR Guidelines Regulate Marketing Automation and Customer EngagementHow GDPR Guidelines Regulate Marketing Automation and Customer Engagement
How GDPR Guidelines Regulate Marketing Automation and Customer EngagementRay Business Technologies
 
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?DATUM LLC
 
Impact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A SecurityImpact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A SecurityEQS Group
 
Janrain Identity Cloud GDPR Assessment Kit
Janrain Identity Cloud GDPR Assessment Kit Janrain Identity Cloud GDPR Assessment Kit
Janrain Identity Cloud GDPR Assessment Kit Sean Bailey
 
What Marketers Need To Know About GDPR
What Marketers Need To Know About GDPRWhat Marketers Need To Know About GDPR
What Marketers Need To Know About GDPRCrawfordGroup
 
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in ComplianceThe GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in ComplianceObservePoint
 

Similar to Shift from GDPR readiness to sustained compliance to improve your business and your customer experience (Identity Live Berlin 2018) (20)

GDPR: Data Privacy in the New
GDPR: Data Privacy in the NewGDPR: Data Privacy in the New
GDPR: Data Privacy in the New
 
General Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) ComplianceGeneral Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) Compliance
 
Looking Beyond GDPR Compliance Deadline
Looking Beyond GDPR Compliance DeadlineLooking Beyond GDPR Compliance Deadline
Looking Beyond GDPR Compliance Deadline
 
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must Know
 
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
 
GDPR & Demand Generation: What Your Team Needs To Know
GDPR & Demand Generation: What Your Team Needs To KnowGDPR & Demand Generation: What Your Team Needs To Know
GDPR & Demand Generation: What Your Team Needs To Know
 
Data Privacy and the GDPR
Data Privacy and the GDPRData Privacy and the GDPR
Data Privacy and the GDPR
 
GDPR & Data Privacy Guide - Free Download
GDPR & Data Privacy Guide - Free DownloadGDPR & Data Privacy Guide - Free Download
GDPR & Data Privacy Guide - Free Download
 
Are you GDPR Ready? Checklist Whitepaper
Are you GDPR Ready? Checklist WhitepaperAre you GDPR Ready? Checklist Whitepaper
Are you GDPR Ready? Checklist Whitepaper
 
Rethinking Trust in Data
Rethinking Trust in Data Rethinking Trust in Data
Rethinking Trust in Data
 
The GDPR - A data revolution
The GDPR - A data revolutionThe GDPR - A data revolution
The GDPR - A data revolution
 
Driving value from first-party data in a privacy-centric world - Vimal Badian...
Driving value from first-party data in a privacy-centric world - Vimal Badian...Driving value from first-party data in a privacy-centric world - Vimal Badian...
Driving value from first-party data in a privacy-centric world - Vimal Badian...
 
How GDPR Guidelines Regulate Marketing Automation and Customer Engagement
How GDPR Guidelines Regulate Marketing Automation and Customer EngagementHow GDPR Guidelines Regulate Marketing Automation and Customer Engagement
How GDPR Guidelines Regulate Marketing Automation and Customer Engagement
 
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
 
Impact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A SecurityImpact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A Security
 
Janrain Identity Cloud GDPR Assessment Kit
Janrain Identity Cloud GDPR Assessment Kit Janrain Identity Cloud GDPR Assessment Kit
Janrain Identity Cloud GDPR Assessment Kit
 
What Marketers Need To Know About GDPR
What Marketers Need To Know About GDPRWhat Marketers Need To Know About GDPR
What Marketers Need To Know About GDPR
 
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in ComplianceThe GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
 

More from ForgeRock

Get the Exact Identity Solution You Need - In the Cloud - AWS and Beyond
Get the Exact Identity Solution You Need - In the Cloud - AWS and BeyondGet the Exact Identity Solution You Need - In the Cloud - AWS and Beyond
Get the Exact Identity Solution You Need - In the Cloud - AWS and BeyondForgeRock
 
Identity Live Sydney: Identity Management - A Strategic Opportunity
Identity Live Sydney: Identity Management  - A Strategic OpportunityIdentity Live Sydney: Identity Management  - A Strategic Opportunity
Identity Live Sydney: Identity Management - A Strategic OpportunityForgeRock
 
Identity Live Singapore: Transform Your Cybersecurity Capability
Identity Live Singapore: Transform Your Cybersecurity CapabilityIdentity Live Singapore: Transform Your Cybersecurity Capability
Identity Live Singapore: Transform Your Cybersecurity CapabilityForgeRock
 
Identity Live Singapore: Just Ask 'Em
Identity Live Singapore: Just Ask 'EmIdentity Live Singapore: Just Ask 'Em
Identity Live Singapore: Just Ask 'EmForgeRock
 
Identity Live Singapore: Building Trust & Privacy in a Connected Society
Identity Live Singapore: Building Trust & Privacy in a Connected SocietyIdentity Live Singapore: Building Trust & Privacy in a Connected Society
Identity Live Singapore: Building Trust & Privacy in a Connected SocietyForgeRock
 
Get the Exact Identity Solution you Need in the Cloud - Deep Dive
Get the Exact Identity Solution you Need in the Cloud - Deep DiveGet the Exact Identity Solution you Need in the Cloud - Deep Dive
Get the Exact Identity Solution you Need in the Cloud - Deep DiveForgeRock
 
Get the Exact Identity Solution You Need - In the Cloud - Overview
Get the Exact Identity Solution You Need - In the Cloud - OverviewGet the Exact Identity Solution You Need - In the Cloud - Overview
Get the Exact Identity Solution You Need - In the Cloud - OverviewForgeRock
 
BMW Group - Identity Enables the Next 100 Years.. (Identity Live Berlin 2018)
BMW Group - Identity Enables the Next 100 Years..  (Identity Live Berlin 2018)BMW Group - Identity Enables the Next 100 Years..  (Identity Live Berlin 2018)
BMW Group - Identity Enables the Next 100 Years.. (Identity Live Berlin 2018)ForgeRock
 
Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...
Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...
Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...ForgeRock
 
What the Internet of Things Means for Consumer Privacy: Veronica Lara
What the Internet of Things Means for Consumer Privacy: Veronica LaraWhat the Internet of Things Means for Consumer Privacy: Veronica Lara
What the Internet of Things Means for Consumer Privacy: Veronica LaraForgeRock
 
Where Biometrics, Blockchains, and Bots are Taking Digital Identity: David Birch
Where Biometrics, Blockchains, and Bots are Taking Digital Identity: David BirchWhere Biometrics, Blockchains, and Bots are Taking Digital Identity: David Birch
Where Biometrics, Blockchains, and Bots are Taking Digital Identity: David BirchForgeRock
 
Identity Live Paris 2017 | Ian Sorbello, HSBC
Identity Live Paris 2017 | Ian Sorbello, HSBCIdentity Live Paris 2017 | Ian Sorbello, HSBC
Identity Live Paris 2017 | Ian Sorbello, HSBCForgeRock
 
Identity Live Paris 2017 | Jean-François Dupitier & Christophe Lemaire, Pôle ...
Identity Live Paris 2017 | Jean-François Dupitier & Christophe Lemaire, Pôle ...Identity Live Paris 2017 | Jean-François Dupitier & Christophe Lemaire, Pôle ...
Identity Live Paris 2017 | Jean-François Dupitier & Christophe Lemaire, Pôle ...ForgeRock
 
Identity Live Paris 2017 | Monetising Digital Customer Relationships
Identity Live Paris 2017 | Monetising Digital Customer RelationshipsIdentity Live Paris 2017 | Monetising Digital Customer Relationships
Identity Live Paris 2017 | Monetising Digital Customer RelationshipsForgeRock
 

More from ForgeRock (14)

Get the Exact Identity Solution You Need - In the Cloud - AWS and Beyond
Get the Exact Identity Solution You Need - In the Cloud - AWS and BeyondGet the Exact Identity Solution You Need - In the Cloud - AWS and Beyond
Get the Exact Identity Solution You Need - In the Cloud - AWS and Beyond
 
Identity Live Sydney: Identity Management - A Strategic Opportunity
Identity Live Sydney: Identity Management  - A Strategic OpportunityIdentity Live Sydney: Identity Management  - A Strategic Opportunity
Identity Live Sydney: Identity Management - A Strategic Opportunity
 
Identity Live Singapore: Transform Your Cybersecurity Capability
Identity Live Singapore: Transform Your Cybersecurity CapabilityIdentity Live Singapore: Transform Your Cybersecurity Capability
Identity Live Singapore: Transform Your Cybersecurity Capability
 
Identity Live Singapore: Just Ask 'Em
Identity Live Singapore: Just Ask 'EmIdentity Live Singapore: Just Ask 'Em
Identity Live Singapore: Just Ask 'Em
 
Identity Live Singapore: Building Trust & Privacy in a Connected Society
Identity Live Singapore: Building Trust & Privacy in a Connected SocietyIdentity Live Singapore: Building Trust & Privacy in a Connected Society
Identity Live Singapore: Building Trust & Privacy in a Connected Society
 
Get the Exact Identity Solution you Need in the Cloud - Deep Dive
Get the Exact Identity Solution you Need in the Cloud - Deep DiveGet the Exact Identity Solution you Need in the Cloud - Deep Dive
Get the Exact Identity Solution you Need in the Cloud - Deep Dive
 
Get the Exact Identity Solution You Need - In the Cloud - Overview
Get the Exact Identity Solution You Need - In the Cloud - OverviewGet the Exact Identity Solution You Need - In the Cloud - Overview
Get the Exact Identity Solution You Need - In the Cloud - Overview
 
BMW Group - Identity Enables the Next 100 Years.. (Identity Live Berlin 2018)
BMW Group - Identity Enables the Next 100 Years..  (Identity Live Berlin 2018)BMW Group - Identity Enables the Next 100 Years..  (Identity Live Berlin 2018)
BMW Group - Identity Enables the Next 100 Years.. (Identity Live Berlin 2018)
 
Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...
Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...
Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...
 
What the Internet of Things Means for Consumer Privacy: Veronica Lara
What the Internet of Things Means for Consumer Privacy: Veronica LaraWhat the Internet of Things Means for Consumer Privacy: Veronica Lara
What the Internet of Things Means for Consumer Privacy: Veronica Lara
 
Where Biometrics, Blockchains, and Bots are Taking Digital Identity: David Birch
Where Biometrics, Blockchains, and Bots are Taking Digital Identity: David BirchWhere Biometrics, Blockchains, and Bots are Taking Digital Identity: David Birch
Where Biometrics, Blockchains, and Bots are Taking Digital Identity: David Birch
 
Identity Live Paris 2017 | Ian Sorbello, HSBC
Identity Live Paris 2017 | Ian Sorbello, HSBCIdentity Live Paris 2017 | Ian Sorbello, HSBC
Identity Live Paris 2017 | Ian Sorbello, HSBC
 
Identity Live Paris 2017 | Jean-François Dupitier & Christophe Lemaire, Pôle ...
Identity Live Paris 2017 | Jean-François Dupitier & Christophe Lemaire, Pôle ...Identity Live Paris 2017 | Jean-François Dupitier & Christophe Lemaire, Pôle ...
Identity Live Paris 2017 | Jean-François Dupitier & Christophe Lemaire, Pôle ...
 
Identity Live Paris 2017 | Monetising Digital Customer Relationships
Identity Live Paris 2017 | Monetising Digital Customer RelationshipsIdentity Live Paris 2017 | Monetising Digital Customer Relationships
Identity Live Paris 2017 | Monetising Digital Customer Relationships
 

Recently uploaded

What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfRankYa
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024The Digital Insurer
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxhariprasad279825
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostZilliz
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Manik S Magar
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyAlfredo García Lavilla
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebUiPathCommunity
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
The Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfThe Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfSeasiaInfotech2
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLScyllaDB
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 

Recently uploaded (20)

What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdf
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptx
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easy
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio Web
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
The Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfThe Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdf
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQL
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 

Shift from GDPR readiness to sustained compliance to improve your business and your customer experience (Identity Live Berlin 2018)

  • 1. © 2018 FORRESTER. REPRODUCTION PROHIBITED.
  • 2. © 2018 FORRESTER. REPRODUCTION PROHIBITED. Shift from GDPR readiness to sustained compliance to improve your business and your customer experience Enza Iannopollo, Analyst
  • 3. 3© 2018 FORRESTER. REPRODUCTION PROHIBITED.
  • 4. 4© 2018 FORRESTER. REPRODUCTION PROHIBITED.
  • 5. 5© 2017 Forrester Research, Inc. Reproduction Prohibited Customer consent was a given
  • 6. 6© 2018 FORRESTER. REPRODUCTION PROHIBITED. Privacy Policies were unreadable
  • 7. 7© 2018 FORRESTER. REPRODUCTION PROHIBITED. Customers would never refuse a cookie
  • 8. 8© 2018 FORRESTER. REPRODUCTION PROHIBITED. Customers’ data was firms’ prisoners forever
  • 9. 9© 2018 FORRESTER. REPRODUCTION PROHIBITED. Privacy and security risks were not on customers’ mind
  • 10. 10© 2018 FORRESTER. REPRODUCTION PROHIBITED. Disclosure of data to the wrong customers was a common mistake Cash withdrawal notice from Banco del Austro informs you that has been made (a) withdrawal from BANRED 02550009-CPN-ATM0009 - THE PINTAMATRIZ QUITO EC EC on 2018/05/09 072734 4931XXXXXXXX7839 your card for $ 20.50. If this transaction was not authorized contact Customer Service at 1800-228787 or 07-2832500.
  • 11. 11© 2018 FORRESTER. REPRODUCTION PROHIBITED.
  • 12. 12© 2018 FORRESTER. REPRODUCTION PROHIBITED. Welcome to a GDPR-compliant world
  • 13. 13© 2018 FORRESTER. REPRODUCTION PROHIBITED.
  • 14. 14© 2018 FORRESTER. REPRODUCTION PROHIBITED. Consent is an opportunity to build trust & engagement
  • 15. 15© 2018 FORRESTER. REPRODUCTION PROHIBITED. Privacy Policies are user-friendly and inspire trust in the brand
  • 16. 16© 2018 FORRESTER. REPRODUCTION PROHIBITED. Cookies require clear and specific consent
  • 17. 17© 2018 FORRESTER. REPRODUCTION PROHIBITED. Flexible and transparent data architecture supports data subject rights
  • 18. 18© 2018 FORRESTER. REPRODUCTION PROHIBITED. And the customers?
  • 19. 19© 2018 FORRESTER. REPRODUCTION PROHIBITED. https://www.forrester.com/report/Best+Practices+For+Privacy+And+GDPR+In+Financial+Services/-/E-RES133848 74% of consumers are ready to switch to a competitor if their bank or insurer suffered a data breach
  • 20. 20© 2018 FORRESTER. REPRODUCTION PROHIBITED. Security and privacy concerns deter 47% from using digital channels https://www.forrester.com/report/Best+Practices+For+Privacy+And+GDPR+In+Financial+Services/-/E-RES133848
  • 21. 21© 2018 FORRESTER. REPRODUCTION PROHIBITED. Source: Forrester’s market research online community (MROC), 2017 – I will be more knowledgeable about who uses my information – I will feel more comfortable about using the internet – It will get much better as I will be able to ask for info to be deleted I hope my online experience becomes less targeted and more generic. I hate when websites tracks what I view and then target me with advertising based on my browsing history. “ “ “ “ Privacy and GDPR are key to build trust
  • 22. 22© 2018 FORRESTER. REPRODUCTION PROHIBITED. Consumers will request their information be deleted and their data not used for marketing purposes Base: British Online Adults (18+) 3,285 Source: Consumer Technographics Online Benchmark and Recontacts, 2018 18% 14% 11% 11% 30% 32% 27% 27% 52% 56% 62% 63% Request a copy of the information companies have about me Ask companies to correct or update information they have about me Request that companies not profile me for marketing purposes Ask companies to delete information about me Not likely (1,2) Middle (3) Likely (4,5) How likely are you to exercise the following rights related to General Data Protection Regulation (GDPR)?
  • 23. 23© 2018 FORRESTER. REPRODUCTION PROHIBITED. Violations of the rules – including failure to properly identify and verify customers’ identity – will be expensive 1. Additional security requirements as a result of enforcement action 2. Diminished customer trust 3. Reputational damage 4. Privacy abuses 5. Regulatory fines
  • 24. 24© 2018 FORRESTER. REPRODUCTION PROHIBITED.
  • 25. 25© 2018 FORRESTER. REPRODUCTION PROHIBITED. Fully compliant 29% Compliant by May 2018 20% All others 51% 49% Which of the following best describes your firm’s GDPR compliance efforts? Base: 3,195 global security decision makers at the manager level and above Source: Forrester Data Global Business Technographics® Security Survey, May 2017 A lot of work remains to be done
  • 26. 26© 2018 FORRESTER. REPRODUCTION PROHIBITED. May 2018 was just a starting block
  • 27. 27© 2018 FORRESTER. REPRODUCTION PROHIBITED. GDPR Compliance is an ongoing journey…
  • 28. 28© 2018 FORRESTER. REPRODUCTION PROHIBITED. …Shift your strategy from GDPR readiness to sustained compliance
  • 29. 29© 2018 FORRESTER. REPRODUCTION PROHIBITED. Recommendations for less mature programs › Be part of a interdisciplinary team leading the GDPR program › Build a gap analysis about high risk data processing activities • Sensitive personal data • Cloud • Third party data sharing › Adopt a risk assessment framework › Build a compliance roadmap and document progress as you execute › Prioritize remediation on consent, re-consent, and data subject rights
  • 30. 30© 2018 FORRESTER. REPRODUCTION PROHIBITED. Recommendations for intermediate programs › Expand your data mapping and gap analysis to third parties › Review third-party contracts, SLAs, and perform due diligence › Focus on governance, processes, and people’s skills as you move forward in your implementation plan › Build identity verification into your data subject right processes › Execute consent and re-consent strategies quickly › Collect evidence of your compliance efforts and progress on an ongoing basis.
  • 31. 31© 2018 FORRESTER. REPRODUCTION PROHIBITED. Recommendations for advanced programs › Leverage automated discovery and classification of data to feed into your compliance software and risk assessment frameworks › Augment your third party risk management frameworks › Expand the scope of the program to include CX, marketing, and digital teams to design the “privacy experience” of your customers › Optimise the process to support “privacy by-design” › Roll out GDPR training to all employees › Measure the progress of your GDPR compliance program against broader business goals
  • 32. 32© 2017 FORRESTER. REPRODUCTION PROHIBITED. GDPR compliance programs deliver business benefits 1. Improved customer experience 2. Better understanding of data assets and improved data strategies 3. More mature and articulated data governance practices across the organization 4. Better privacy policy management 5. A more solid (or a new) corporate culture for data privacy
  • 33. FORRESTER.COM Thank you © 2018 FORRESTER. REPRODUCTION PROHIBITED. Enza Iannopollo +44 (0)20 7323 7634 eiannopollo@forrester.com