© 2018 FORRESTER. REPRODUCTION PROHIBITED.
© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Shift from GDPR readiness to
sustained compliance to improve your
business and your customer experience
Enza Iannopollo, Analyst
3© 2018 FORRESTER. REPRODUCTION PROHIBITED.
4© 2018 FORRESTER. REPRODUCTION PROHIBITED.
5© 2017 Forrester Research, Inc. Reproduction Prohibited
Customer consent was a given
6© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Privacy Policies were unreadable
7© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Customers
would never
refuse a cookie
8© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Customers’ data
was firms’
prisoners
forever
9© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Privacy and
security risks
were not on
customers’ mind
10© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Disclosure of
data to the
wrong
customers was a
common mistake
Cash withdrawal notice from
Banco del Austro informs you that has been made (a)
withdrawal from BANRED 02550009-CPN-ATM0009 -
THE PINTAMATRIZ QUITO EC EC on 2018/05/09
072734 4931XXXXXXXX7839 your card for $ 20.50.
If this transaction was not authorized contact Customer
Service at 1800-228787 or 07-2832500.
11© 2018 FORRESTER. REPRODUCTION PROHIBITED.
12© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Welcome to a GDPR-compliant world
13© 2018 FORRESTER. REPRODUCTION PROHIBITED.
14© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Consent is an opportunity to build trust & engagement
15© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Privacy Policies
are user-friendly
and inspire trust
in the brand
16© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Cookies require
clear and
specific consent
17© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Flexible and
transparent data
architecture
supports data
subject rights
18© 2018 FORRESTER. REPRODUCTION PROHIBITED.
And the customers?
19© 2018 FORRESTER. REPRODUCTION PROHIBITED.
https://www.forrester.com/report/Best+Practices+For+Privacy+And+GDPR+In+Financial+Services/-/E-RES133848
74% of consumers are ready to switch to a competitor
if their bank or insurer suffered a data breach
20© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Security and privacy concerns deter 47%
from using digital channels
https://www.forrester.com/report/Best+Practices+For+Privacy+And+GDPR+In+Financial+Services/-/E-RES133848
21© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Source: Forrester’s market research online community (MROC), 2017
– I will be more
knowledgeable about who
uses my information
– I will feel more comfortable
about using the internet
– It will get much better as I
will be able to ask for info
to be deleted
I hope my online experience
becomes less targeted and
more generic. I hate when
websites tracks what I view
and then target me with
advertising based on my
browsing history.
“
“
“
“
Privacy and GDPR are key to build trust
22© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Consumers will request their information be deleted and
their data not used for marketing purposes
Base: British Online Adults (18+) 3,285
Source: Consumer Technographics Online Benchmark and Recontacts, 2018
18%
14%
11%
11%
30%
32%
27%
27%
52%
56%
62%
63%
Request a copy of the information companies have about
me
Ask companies to correct or update information they have
about me
Request that companies not profile me for marketing
purposes
Ask companies to delete information about me
Not likely (1,2) Middle (3) Likely (4,5)
How likely are you to exercise the following rights related to
General Data Protection Regulation (GDPR)?
23© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Violations of the
rules – including
failure to
properly identify
and verify
customers’
identity – will be
expensive
1. Additional security requirements as a
result of enforcement action
2. Diminished customer trust
3. Reputational damage
4. Privacy abuses
5. Regulatory fines
24© 2018 FORRESTER. REPRODUCTION PROHIBITED.
25© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Fully compliant
29%
Compliant by
May 2018
20%
All others
51%
49%
Which of the following best describes your firm’s GDPR
compliance efforts?
Base: 3,195 global security decision makers at the manager level and above
Source: Forrester Data Global Business Technographics® Security Survey, May 2017
A lot of work
remains to be
done
26© 2018 FORRESTER. REPRODUCTION PROHIBITED.
May 2018 was
just a starting
block
27© 2018 FORRESTER. REPRODUCTION PROHIBITED.
GDPR Compliance is an ongoing journey…
28© 2018 FORRESTER. REPRODUCTION PROHIBITED.
…Shift your strategy from GDPR
readiness to sustained compliance
29© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Recommendations for less mature programs
› Be part of a interdisciplinary team leading the GDPR program
› Build a gap analysis about high risk data processing activities
• Sensitive personal data
• Cloud
• Third party data sharing
› Adopt a risk assessment framework
› Build a compliance roadmap and document progress as you
execute
› Prioritize remediation on consent, re-consent, and data subject
rights
30© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Recommendations for intermediate programs
› Expand your data mapping and gap analysis to third parties
› Review third-party contracts, SLAs, and perform due diligence
› Focus on governance, processes, and people’s skills as you move
forward in your implementation plan
› Build identity verification into your data subject right processes
› Execute consent and re-consent strategies quickly
› Collect evidence of your compliance efforts and progress on an
ongoing basis.
31© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Recommendations for advanced programs
› Leverage automated discovery and classification of data to feed
into your compliance software and risk assessment frameworks
› Augment your third party risk management frameworks
› Expand the scope of the program to include CX, marketing, and
digital teams to design the “privacy experience” of your customers
› Optimise the process to support “privacy by-design”
› Roll out GDPR training to all employees
› Measure the progress of your GDPR compliance program against
broader business goals
32© 2017 FORRESTER. REPRODUCTION PROHIBITED.
GDPR compliance programs deliver business benefits
1. Improved customer experience
2. Better understanding of data assets and improved data strategies
3. More mature and articulated data governance practices across the
organization
4. Better privacy policy management
5. A more solid (or a new) corporate culture for data privacy
FORRESTER.COM
Thank you
© 2018 FORRESTER. REPRODUCTION PROHIBITED.
Enza Iannopollo
+44 (0)20 7323 7634
eiannopollo@forrester.com

Shift from GDPR readiness to sustained compliance to improve your business and your customer experience (Identity Live Berlin 2018)

  • 1.
    © 2018 FORRESTER.REPRODUCTION PROHIBITED.
  • 2.
    © 2018 FORRESTER.REPRODUCTION PROHIBITED. Shift from GDPR readiness to sustained compliance to improve your business and your customer experience Enza Iannopollo, Analyst
  • 3.
    3© 2018 FORRESTER.REPRODUCTION PROHIBITED.
  • 4.
    4© 2018 FORRESTER.REPRODUCTION PROHIBITED.
  • 5.
    5© 2017 ForresterResearch, Inc. Reproduction Prohibited Customer consent was a given
  • 6.
    6© 2018 FORRESTER.REPRODUCTION PROHIBITED. Privacy Policies were unreadable
  • 7.
    7© 2018 FORRESTER.REPRODUCTION PROHIBITED. Customers would never refuse a cookie
  • 8.
    8© 2018 FORRESTER.REPRODUCTION PROHIBITED. Customers’ data was firms’ prisoners forever
  • 9.
    9© 2018 FORRESTER.REPRODUCTION PROHIBITED. Privacy and security risks were not on customers’ mind
  • 10.
    10© 2018 FORRESTER.REPRODUCTION PROHIBITED. Disclosure of data to the wrong customers was a common mistake Cash withdrawal notice from Banco del Austro informs you that has been made (a) withdrawal from BANRED 02550009-CPN-ATM0009 - THE PINTAMATRIZ QUITO EC EC on 2018/05/09 072734 4931XXXXXXXX7839 your card for $ 20.50. If this transaction was not authorized contact Customer Service at 1800-228787 or 07-2832500.
  • 11.
    11© 2018 FORRESTER.REPRODUCTION PROHIBITED.
  • 12.
    12© 2018 FORRESTER.REPRODUCTION PROHIBITED. Welcome to a GDPR-compliant world
  • 13.
    13© 2018 FORRESTER.REPRODUCTION PROHIBITED.
  • 14.
    14© 2018 FORRESTER.REPRODUCTION PROHIBITED. Consent is an opportunity to build trust & engagement
  • 15.
    15© 2018 FORRESTER.REPRODUCTION PROHIBITED. Privacy Policies are user-friendly and inspire trust in the brand
  • 16.
    16© 2018 FORRESTER.REPRODUCTION PROHIBITED. Cookies require clear and specific consent
  • 17.
    17© 2018 FORRESTER.REPRODUCTION PROHIBITED. Flexible and transparent data architecture supports data subject rights
  • 18.
    18© 2018 FORRESTER.REPRODUCTION PROHIBITED. And the customers?
  • 19.
    19© 2018 FORRESTER.REPRODUCTION PROHIBITED. https://www.forrester.com/report/Best+Practices+For+Privacy+And+GDPR+In+Financial+Services/-/E-RES133848 74% of consumers are ready to switch to a competitor if their bank or insurer suffered a data breach
  • 20.
    20© 2018 FORRESTER.REPRODUCTION PROHIBITED. Security and privacy concerns deter 47% from using digital channels https://www.forrester.com/report/Best+Practices+For+Privacy+And+GDPR+In+Financial+Services/-/E-RES133848
  • 21.
    21© 2018 FORRESTER.REPRODUCTION PROHIBITED. Source: Forrester’s market research online community (MROC), 2017 – I will be more knowledgeable about who uses my information – I will feel more comfortable about using the internet – It will get much better as I will be able to ask for info to be deleted I hope my online experience becomes less targeted and more generic. I hate when websites tracks what I view and then target me with advertising based on my browsing history. “ “ “ “ Privacy and GDPR are key to build trust
  • 22.
    22© 2018 FORRESTER.REPRODUCTION PROHIBITED. Consumers will request their information be deleted and their data not used for marketing purposes Base: British Online Adults (18+) 3,285 Source: Consumer Technographics Online Benchmark and Recontacts, 2018 18% 14% 11% 11% 30% 32% 27% 27% 52% 56% 62% 63% Request a copy of the information companies have about me Ask companies to correct or update information they have about me Request that companies not profile me for marketing purposes Ask companies to delete information about me Not likely (1,2) Middle (3) Likely (4,5) How likely are you to exercise the following rights related to General Data Protection Regulation (GDPR)?
  • 23.
    23© 2018 FORRESTER.REPRODUCTION PROHIBITED. Violations of the rules – including failure to properly identify and verify customers’ identity – will be expensive 1. Additional security requirements as a result of enforcement action 2. Diminished customer trust 3. Reputational damage 4. Privacy abuses 5. Regulatory fines
  • 24.
    24© 2018 FORRESTER.REPRODUCTION PROHIBITED.
  • 25.
    25© 2018 FORRESTER.REPRODUCTION PROHIBITED. Fully compliant 29% Compliant by May 2018 20% All others 51% 49% Which of the following best describes your firm’s GDPR compliance efforts? Base: 3,195 global security decision makers at the manager level and above Source: Forrester Data Global Business Technographics® Security Survey, May 2017 A lot of work remains to be done
  • 26.
    26© 2018 FORRESTER.REPRODUCTION PROHIBITED. May 2018 was just a starting block
  • 27.
    27© 2018 FORRESTER.REPRODUCTION PROHIBITED. GDPR Compliance is an ongoing journey…
  • 28.
    28© 2018 FORRESTER.REPRODUCTION PROHIBITED. …Shift your strategy from GDPR readiness to sustained compliance
  • 29.
    29© 2018 FORRESTER.REPRODUCTION PROHIBITED. Recommendations for less mature programs › Be part of a interdisciplinary team leading the GDPR program › Build a gap analysis about high risk data processing activities • Sensitive personal data • Cloud • Third party data sharing › Adopt a risk assessment framework › Build a compliance roadmap and document progress as you execute › Prioritize remediation on consent, re-consent, and data subject rights
  • 30.
    30© 2018 FORRESTER.REPRODUCTION PROHIBITED. Recommendations for intermediate programs › Expand your data mapping and gap analysis to third parties › Review third-party contracts, SLAs, and perform due diligence › Focus on governance, processes, and people’s skills as you move forward in your implementation plan › Build identity verification into your data subject right processes › Execute consent and re-consent strategies quickly › Collect evidence of your compliance efforts and progress on an ongoing basis.
  • 31.
    31© 2018 FORRESTER.REPRODUCTION PROHIBITED. Recommendations for advanced programs › Leverage automated discovery and classification of data to feed into your compliance software and risk assessment frameworks › Augment your third party risk management frameworks › Expand the scope of the program to include CX, marketing, and digital teams to design the “privacy experience” of your customers › Optimise the process to support “privacy by-design” › Roll out GDPR training to all employees › Measure the progress of your GDPR compliance program against broader business goals
  • 32.
    32© 2017 FORRESTER.REPRODUCTION PROHIBITED. GDPR compliance programs deliver business benefits 1. Improved customer experience 2. Better understanding of data assets and improved data strategies 3. More mature and articulated data governance practices across the organization 4. Better privacy policy management 5. A more solid (or a new) corporate culture for data privacy
  • 33.
    FORRESTER.COM Thank you © 2018FORRESTER. REPRODUCTION PROHIBITED. Enza Iannopollo +44 (0)20 7323 7634 eiannopollo@forrester.com