Data Privacy Consulting Proactively navigate the data privacy regulation landscape Organisations are experiencing unprecedented change in the data privacy landscape. Changing regulations are forcing constant business, technical, and legal operational changes. These changes often overlap, resulting in highly complex legal and regulatory scenarios.We offer a dedicated global cross-functional team that includes former regulatory agency officials, attorneys, chief privacy and data security officers, technologists and privacy consultants, and auditors to help you build, implement, and optimise your data protection programme.We partner with you to understand jurisdictions and regulatory obligations, assess your privacy needs, implement compliance measures and safeguards and respond to new and changing regulations. Survey December 7, 2023 Executive Perspectives on Top Risks for 2024 and 2034 The 12th annual Top Risks Survey report highlights top-of-mind issues for directors and executives around the globe over the next year - 2024 - and a decade later – 2034. Read more Our data privacy consulting services include: Pro Briefcase Privacy compliance Compliance with current and future privacy laws requires disciplined execution. From developing a robust compliance strategy to managing consent order response and data subject requests for information, Protiviti can help at every stage. Pro Building office Data discovery We help establish a formal inventory of data to capture where personal data is collected, processed, and stored. Paired with data privacy flow mapping, classification, and assessments, companies can automate and optimise their data discovery efforts. Pro Rightmark Square Privacy as a Service (Protiviti PraaS™) Think of us as an extension of your team. We provide tailored, full-service support to assess privacy needs, implement and automate privacy-related functions, and respond to new and changing regulations. Our comprehensive approach to data privacy Data privacy regulations are in flux globally. Even as companies put the finishing touches on extensive preparations to comply with applicable privacy laws, such as the European Union’s GDPR and California’s Consumer Privacy Act, new regulations continue to be introduced in other countries. As legislators pass new laws, they continuously amend those already in effect. Data protection regulations are not static.The problem and proposed solutions are complex and evolving. One thing is almost certain—anyone aiming to comply with a specific regulation with a target date in mind will be disappointed as those near-term obligations are supplanted by new and different rules over the mid and long-term.In response to this changing landscape, Protiviti applies a holistic framework that addresses the fundamental aspects of data security management without being locked into any one specific compliance format. We focus on the most pressing data privacy technology issues companies face, including:Developing strategies to address global data privacy regulationsCompliance with regulatory obligationsAddressing resource and skill shortagesOperationalising privacy needsImplementing privacy tools and remediation supportBy working ahead of the law in a comprehensive fashion, Protiviti helps build the foundations of a strong but flexible privacy programme that includes understanding principles, educating stakeholders, and developing an applicable governance structure for managing changes. This base enables companies and their stakeholders to look to the uncertain future of data privacy regulations with greater confidence. Key data privacy partners We partner closely with cybersecurity and privacy market leaders, ensuring our clients receive the best solutions to meet their needs.Notably, Protiviti has performed more global implementations than other OneTrust partners and has well over 175 OneTrust-certified consultants, including more than 10% of the global population of OneTrust fellows of privacy technology spread across Europe, the Americas, and the Asia-Pacific regions.Some of our top partners include: CISO Next CISO Next connects CISOs and security thought leaders to explore and shape how their role will evolve in the current and future business landscape. Stay informed on latest trends, network with fellow CISOs, and build solutions for the future. Get involved The present and future of data privacy What’s next for privacy programmes? Listen to Protiviti leaders around the world talk about the sustainability of privacy investments.A number of organisations are struggling with sustainability. Data breaches will happen at some point in time, hence knowing your personal data and understanding where the data is or mapping data is critical.Watch this video to gain insights on (a) how to sustain the benefits that we have gained through the investments that have been made, (b) what the biggest issues in terms of sustainability are, and (c) how to drive sustainability through your privacy programme. Leadership Tjakko de Boer Tjakko is managing director in the technology consulting practice at Protiviti’s Amsterdam office. For over 20 years he assisted clients to leverage digital solutions, improve performance, and manage operational risk and control. Key focus areas include information ... Learn more FLASH REPORT NIST Releases Version 2.0 of Its Cybersecurity Framework (CSF): What This Means for Your Organisation On February 26, 2024, The National Institute of Standards and Technology (NIST) released version 2.0 of its updated and widely used Cybersecurity Framework (CSF). This latest edition of the CSF is designed for all audiences, industry sectors and... INSIGHTS PAPER How data sovereignty and data localisation impact your privacy programmes The concepts of data sovereignty and data localisation stem from a desire to keep data within a country’s borders for greater control. While the broad strokes of various privacy laws may be consistent across jurisdictions, governments will dictate... NEWSLETTER Framing the Data Privacy Discussion in the Boardroom Data proliferation and data privacy regulatory activity across the globe have created the need for focused boardroom discussions. While cybersecurity continues to be an issue for boards, a more targeted focus on data privacy is increasingly... WHITEPAPER Building a Comprehensive Data Privacy Programme: Four Actionable Steps for Technology Companies Introduction Most technology companies today understand that ensuringdata privacyand protection is an imperative for their business; however, few manage this process well or even invest enough resources in that effort. As governments... SURVEY Talent, culture, cybersecurity and data privacy represent top risk issues for public sector organisations The level of uncertainty in today’s global marketplace and the velocity of change continue to produce a multitude of potential risks that can disrupt an organisation’s business model and strategy on very short notice. Unfolding events in Eastern... FLASH REPORT Virginia Becomes the Second State to Enact Consumer Privacy Law The Commonwealth of Virginia passed theConsumer Data Protection Act (CDPA)into law on March 2, 2021, following overwhelming bipartisan support for a state consumer privacy law. The November 2020 election results provided the much needed... Button Button Global Chocolatier Adopts Privacy Technology to Prevent Data Exposure Data privacy has become a strategic priority as companies adapt to comply with rapidly proliferating data privacy laws. Recent years have seen the adoption of the European Union’s General Data Protection Regulation (GDPR), the more recent California Consumer Protection Act (CCPA), and similar regulations. Read more