All organisations under the regulation should by now comply with GDPR. However, our recent PwC third GDPR pulse survey shows that the majority of organisations were not ready in time. Key results of a recent study* by the Zurich School of Management and Law show that:
The results of the study are in accordance with my daily interactions with clients. In Switzerland, many clients are not aware that they are falling under that regulation and others wish to postpone any efforts for data protection now and wait for the revised Federal Act on Data Protection (FADP).
As mentioned in the GDPR, data “controllers” and “processors” must demonstrate their compliance with the regulation. Being transparent in terms of how you as an organisation comply with GDPR provides the trust that your business partners, other stakeholders and the society in general are looking for when doing business with you. Consequently, you might face competitive disadvantages or even severe fines if you are not compliant.
As a multi-disciplinary practice, we are uniquely placed to help you adjust to a new environment driven by regulatory scrutiny around data privacy. Our data privacy team includes lawyers, consultants, auditors, cyber security and forensics experts. Our team is truly global, with expertise in all major economies.
Within Switzerland, we have a dedicated team available with proven expertise in connecting the dots between Data Privacy, Information Governance, Data Management, Cyber Security and Trust and Transparency. Our team has extensive hands-on data privacy knowledge and experience and provides you with solutions that expand over the compliance horizon. We have helped many organisations in their journey to GDPR compliance.
Organisations are facing various challenges in protecting their data and responding to the need for trust and transparency in this area. We therefore have created a comprehensive trust services portfolio. Through a variety of available services, we are able to offer you a tailored solution, including designing and implementing the relevant controls within your existing process and technology control framework (e.g. ICS and ITGC). Alternatively, we can assist you to adopt a reference framework or other public available data privacy standard.
Illustration 1: The various data privacy trust services that will help you to achieve a sustainable, trustworthy and transparency data privacy framework commensurate the GDPR requirement.
Our trust services portfolio allows you to further enhance and increase the maturity of your data privacy environment in a structured manner. It covers the main areas that address the GDPR requirements as outlined below.
Through our online and interactive platform, we offer a free-of-charge quick scan assessment of your current and desired data privacy environment, based on the key GDPR principles. Our quick scan solution provides you almost instantly with an overview of how your data privacy environment currently addresses the GDPR requirements. Our quick scan focusses on the most important GDPR principles: transparency of data processing, legitimate purposes, application of data minimisation, security measures taken to protect data and ability to demonstrate compliance.
The outcome of the quick scan comprises of a high-level maturity indication with generic yet actionable recommendations. This provides you with an excellent starting point for discussions with your management to start further enhancing the data privacy maturity level and your overall state of compliance in this area.
Illustration 2: The results of our free-of-charge quick scan provide you an excellent data privacy maturity indication and start point for management discussions to enhance your data privacy environment
Our detailed maturity readiness assessment focuses on all GDPR elements and the principles for effective data privacy management. The assessment is based on our best practice framework, but can be supplemented with other privacy management standards if required. Our assessment can help you to provide your internal stakeholders with the confidence that you have taken the necessary steps to comply with the GDPR requirements. Furthermore, it helps you to prepare for more formal certification or assurance-related activities. The readiness assessment is also an excellent way to identify and assess your third parties (e.g. vendors and services providers) for their state of GDPR compliance. Based on the results we enable you to determine the impact of third parties on your target state of compliance and take the appropriate actions. During the assessment, we will provide you with advice on how technology can be leveraged to support your certification/assurance objectives.
We make use of our proprietary GDPR Maturity Assessment tool to measure, in a granular way, your current maturity level and define a desired maturity level for data privacy management. This will result in a maturity assessment report with detailed findings, risks and prioritised and actionable recommendations to reach the desired maturity level.
Organisations going through readiness assessments not only increase their understanding of their privacy capabilities, they also identify priority areas for improvement. Feedback from dozens of our clients shows that as a result, they are better equipped to demonstrate compliance to EU data protection authorities and promote trust to their clients.
Our experienced auditors and privacy specialists offer data privacy solutions from controls to certification and/or assurance programmes for organisations that have completed their GDPR implementation.
We will define and agree together with you the required certification and/or assurance scope, amount of controls to be tested and testing methodology. We will apply the right certification/assurance framework based on your organisational needs and our experience. Examples of data privacy frameworks that we typically apply are the GDPR-CARPA (Certified Assurance Report-based Processing Activities Certification Criteria) from Luxembourg or the NOREA-PCF (Privacy Control Framework) from the Netherlands. Moreover, we have also developed our proprietary PwC Data Privacy Control Framework consisting of 700+ control criteria mapped against the GDPR’s legislative requirements.
Based on the selected applicable framework components, we will evaluate and attest the controls you have adopted. Where needed, we will communicate to you any necessary requirements for additional (good practice) data privacy controls.
Finally, our certification and/or assurance deliverables, which are based on known standards (e.g. GDPR-CARPA, NOREA-PCF), and PwC proprietary frameworks will enable you to have the necessary transparency in place. The transparency will build trust with your relevant internal and external stakeholders that you have implemented and operated the necessary measures to comply with the requirements as stipulated in the GDPR.
Preparing for certification and assurance activities is not a straight forward exercise. It is particularly challenging to define the right scope and underlying standards. Based on our experience with relevant data privacy control frameworks and audit standards, we can filter out these complexities and focus with our clients on the execution and completion of the certification and assurance activities.
The scope of the GDPR is far reaching and also impacts Swiss organisations. Every data “controller” and “processor” in- and outside of the EU is regulated, if they are processing personal data in their offering of goods or services to data subjects in the EU, or if they are monitoring their behaviour within the EU.
One of the requirements under the GDPR is that data “controllers” and “processors” must demonstrate their compliance with the regulation. Being transparent in terms of how you as an organisation comply with the GDPR provides the trust that your business partners, other stakeholders and the society in general are looking for when doing business with you. Consequently, establishing a transparent yet mature (i.e. sustainable and scalable) data privacy environment is crucial.
By performing quick scan assessments and detailed maturity readiness assessments, you will be able to get deep insights into the current and desired maturity level of your data privacy environment. This provides you with the necessary details to discuss the implementation of additional process, technology and control measures to (further) mature your data privacy environment. Moreover, this will prepare for the required certification and/or assurance activities. Such activities are based on known industry standards (e.g. GDPR-CARPA, NOREA-PCF) and/or PwC proprietary frameworks and will enable you to put the required transparency in place.
Ultimately, it is this transparency that will build the necessary trust with your relevant stakeholders and demonstrate that you have implemented and operated those measures to comply with the requirements as stipulated in the GDPR.
* ZHAW Zürcher Hochschule für Angewandte Wissenschaften – «Datenschutz in Schweizer Unternehmen 2018 : eine Studie des Instituts für Wirtschaftsinformatik und des Zentrums für Sozialrecht»
Partner, Leader Digital Assurance & Trust and Cybersecurity & Privacy, PwC Switzerland
Tel: +41 58 792 84 59