GDPR
In response to Client requests, IT-EBS has developed an inclusive package which looks at the overall impact of the new GDPR legislation on your company. That will involve such thing as review data processing, access to filing cabinets, staff working from home and all the other myriad of possibilities that will be unique to each business. The package is designed so that we can work with your IT provider rather than competing against them.
GDPR compliance
It has now been almost 3 years since the general data protection regulation came into force. Many businesses just wanted to protect their mailing lists and rewrite their website privacy notice but there is more to it than that. Most of the core requirements of the regulation where not addressed leaving companies exposed to excessive fines and reputational damage if they have not shown due care with client’s personal data. At risk are small to medium size enterprises that do not have the expertise, nor the budget to conduct full data protection reviews.
At IT enterprise business Solutions, we bring together our combined knowledge of business process and database architecture to custom design a data protection plan unique to your business. This involves:
-
Preparing a data map
Before developing a data protection plan it is important to know where your data is being stored and how it is being processed. Some data maybe on a cloud service but where is their data processing centre? (within EU or outside). Some of your data maybe outsourced to subcontractors, so how do you know if they have adequate data protection procedures? This is where drafting a visual data map assists management to appreciate the scope of their data management workflow. With our experienced consultants we gain insights from each department to provide a visual representation of your data movements across the organisation highlighting strengths and risks that are inherent in the system.
-
Data impact assessment
It is not enough just to know where your data is, but it needs to be classified by types of data under your care. If you deal with sensitive personal information, such as health or dealing with children, then extra effort is required to keep that data safe. With our expertise we can assist in prioritise efforts by recommending appropriate mitigating strategies to maintain data integrity. Remember that you must have applied reasonable steps to protect your data in relation to the consequences of any breach.
-
Staff training
By far the biggest cause of lapses in data security are not from technology but from people not being aware of the consequences of their actions. We run custom designed training courses developed around your circumstance that highlight issues such as email phishing, suspicious websites and how to deal with subject access requests. If ever an organisation is investigated by the ICO then the sheer fact that training has been provided to staff goes a long way in mitigating any judgements against you.
-
Outsourced data protection officer
For some organisations which deal with types of sensitive data they may be required to engage a data protection officer. This can be expensive exercise and finding people with this sort of specialist skill set would be difficult. We offer a scalable outsourced solution that allows for ongoing care at an affordable budget. This allows for ongoing support of data privacy procedures and for a single point of contact for the public and dealings with the ICO.
ISO27001 accreditation
For those smaller entities that service larger customers they may need to have data security accreditations to continue servicing their clients. This requires a commitment to ongoing improvement and to make sure their policies and procedures are in line with international standards. To get this accreditation think GDPR compliance on steroids. There is a lot of documentation that must be produced, manuals written and even job descriptions reviewed. it is a mammoth task for an organisation to perform and may take many months to complete. As outside consultants we can dedicate our time to achieving this goal as we know the documentation required what the assessors are looking for. This should not be seen as an added cost for compliance but an opportunity to open doors with larger organisations whilst reassuring your existing client base that their data is in safe hands. Prices vary depending on the size and complexity of the enterprise.
















