SlideShare ist ein Scribd-Unternehmen logo
1 von 25
Live Webinar #4 – Thursday 5
December 2019
GDPR : where do we stand?
Framework :
• 27th April 2016 : Adoption
• 6th May 2018 : Application
• May 2020: Public evaluation report by
the Commission in May 2020 and transmitted
to the European parliament and to the Council
• 2020 : E-PRIVACY
• April 2019 : European Data
Protection Board report:
COOPERATION – CONSISTENCY –
STANDARDISED for Supervisory
Authorities
• July 2019 – European Commission
Communication taking stock of one year
application of the GDPR
• June 2019 - European Commission
report of the multi-stakeholder group
Total
206326
Complaint
s
94622
Data
breach
notificat
ions
64684
Other
47020
47%
52%
1%
Ongoing Closed Appealed
SAs from 11 EEA countries imposed a total of
€55.955,671 in fines
GDPR : where do we stand?
A joint project carried out between ECIIA and
FERMA, with the support of 5 IIA national
Institutes and 11 national risk management
associations.
Our ambitious objectives were to:
• Collect “best practices” and key challenges
related to GDPR from a large panel of
practitioners.
• Promote good governance and internal audit
and risk management alongside the GDPR.
• Provide facts and tangibles to be used as
an advocacy tool for the new GDPR
guidelines.Up to
19Questions in
total
346
respondents
25
Interviewees
GDPR : expert’s introduction
Lene
Ritz
Chief Risk Officer &
Team leader
Energinet (Denmark)
Ralf Herold
SVP Corporate Audit
BASF (Germany)
GDPR : Polling question #1
Do you have a DPO internally or
as outsourced function ?
• Internally – new function
• Internally – existing function
• Outsourced
• Other
Do you have a DPO internally or as
outsourced function ?
6
Yes
82%
No
18%
DPO role was
assigned
internally to an
existing
function
53%
New
internal
function
…
Outsource
d
11%
1.Legal - Compliance :
54%
2.IT - IS : 15%
3.Risk Management : 11%
4.Operations - Finance :
10%
GDPR : Polling question #2
What is your level of
interaction with the DPO ?
• Formalised
• Not Formalised
• No contact
• Not applicable
What is your level of interaction with
the DPO ?
Formalised
(several
times a
year…)
31%
Not formalised
(on request)
55%
Not
applicable –
I’m the DPO…
No
contact…
Not sure 1%
86% in
contact
GDPR : Polling question #3
In your organisation, who is
in charge of reporting to the
Board about data privacy
matters including GDPR ?
• DPO
• Senior Management
• CRO
• CAE
• Other
Who is in charge of reporting to the
Board about data privacy matters
including GDPR?
CAE
7%
CRO
10%
DPO
43%
Senior
management
21%
Other
19%
GDPR : Polling question #4
Do you foresee that the GDPR
related engagements will
become recurring audits in
your audit plan ?
• Yes
• No
• I do not know
What elements of GDPR do you plan to (or
currently) audit?
56%
44% 42%
33%
GDPR Governance GDPR General
Design
GDPR
Implementation
GDPR
performance &
effectiveness
39%
60%
47%
2018 2019 2020
Audit plan trends
GDPR : Polling question #5
Which one of the following
type of risks does GDPR
represent for your
organisation?
• Strategic
• Operational
• Compliance
• Financial
• Reputational
How do you rate the various risks of
GDPR in your organisation ?
Did you perform an evaluation of the
threats arising from the GDPR
implementation?
Yes
76%
No
24%
Yes, they have
been financially
quantified and
with proposed
mitigation
measures
30%
Yes, as regards
frequency and severity
without financial
quantification
44%
No, not my
role, performed
by another
function,
please specify
which one
26%
Is Data Protection integrated
in your global risk mapping of
ERM?
What are the challenges of GDPR
implementation in your organisation ?
Top challenges mentioned by
respondents in the survey (%)
1. Uncertainty,
complexity
30%
2. Innovation/ R&D 25%
3. Workload, resources 17%
4. Relations – 3rd parties 14%
5. Relations – internal 14%
Questions & Answers
Recommendations
Appendix
1.Lene’s recommendation
2.Ralph’s recommendation
Main recommendations for IA and the
European Authorities
1. Recognize the key role played by corporate
governance in ensuring GDPR compliance as well as a
certain degree of accountability of organizations
about personal data protection.
2. Reduce the uncertainty of how local authorities
will deal with GDPR compliance (interpretation of
what constitutes “high” risks, amount, format and
frequency of the reporting…).
3. Formalize the relationship regarding privacy risks
between the DPO, Risk Management and Internal
Audit, relying on the three lines of defense model
as a starting point.
Main recommendations for RM and the
European Authorities
1. Embed data privacy in most of the existing risk maps.
2. Include the understanding of how privacy risks can affect all aspects of
the business into their risk assessment, in order to propose credible
and documented mitigation measures to the senior management of
the organisation
3. The next review of the GDPR by the European Commission in May
2020 should preserve the organisation’s ability to innovate.
Next steps
Final report
available on
FERMA and
ECIIA
websites
FERMA and
ECIIA to
follow up
with EU
institution
s in 2020
Thank you and see you in 2020
Subscribe to our
newsletter to stay
informed
https://www.ferma.eu/conta
ct-us/
About FERMA
FERMA brings together 21 risk management associations in 20
European countries.
They represent nearly 5,000 professional risk
managers active in a wide range of business
sectors.
The Federation of European Risk Management
Associations (FERMA) speaks for the risk
management profession in Europe.
FERMA acts on its behalf at European level and
promotes the risk management profession.
FERMA provides a risk management perspective on
European issues and strengthens the profession
through a European risk management certification
(rimap).
About ECIIA
ECIIA gives voice to 47.000 Internal Auditors in 34 countries
from wider Europe.
The European Confederation of Institutes of Internal
Auditing (ECIIA) is the voice of internal audit in
Europe.
Our role is to enhance corporate governance
through the promotion of the professional
practice of internal auditing.
The ECIIA mission is to further the development of
good corporate governance and internal audit at the
European level, through
• Knowledge sharing
• Developing key relationships
• Impacting the regulatory environment, by dealing
with the European Union, its Parliament and the
European Authorities.

Weitere ähnliche Inhalte

Was ist angesagt?

GDPRIBMWhitePaper
GDPRIBMWhitePaperGDPRIBMWhitePaper
GDPRIBMWhitePaper
Jim Wilson
 

Was ist angesagt? (20)

1 -2-6 kista watson summit-gdpr ibm pov hogg-sm
1 -2-6 kista watson summit-gdpr ibm pov hogg-sm1 -2-6 kista watson summit-gdpr ibm pov hogg-sm
1 -2-6 kista watson summit-gdpr ibm pov hogg-sm
 
2 -2-6 kista watson summit-gdpr how ibm preparing hogg-sm
2 -2-6 kista watson summit-gdpr how ibm preparing hogg-sm2 -2-6 kista watson summit-gdpr how ibm preparing hogg-sm
2 -2-6 kista watson summit-gdpr how ibm preparing hogg-sm
 
COVID-19: What are the Potential Impacts on Data Privacy?
COVID-19: What are the Potential Impacts on Data Privacy?COVID-19: What are the Potential Impacts on Data Privacy?
COVID-19: What are the Potential Impacts on Data Privacy?
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
Assessing Risk: How Organizations Can Proactively Manage Privacy Risk
Assessing Risk: How Organizations Can Proactively Manage Privacy RiskAssessing Risk: How Organizations Can Proactively Manage Privacy Risk
Assessing Risk: How Organizations Can Proactively Manage Privacy Risk
 
GDPR Solutions That Won't Break the Bank
GDPR Solutions That Won't Break the BankGDPR Solutions That Won't Break the Bank
GDPR Solutions That Won't Break the Bank
 
The 2013 Cost of Data Breach Study is out from Symantec - RapidSSLOnline
The 2013 Cost of Data Breach Study is out from Symantec - RapidSSLOnlineThe 2013 Cost of Data Breach Study is out from Symantec - RapidSSLOnline
The 2013 Cost of Data Breach Study is out from Symantec - RapidSSLOnline
 
2013 cost of data breach study - France
2013 cost of data breach study - France2013 cost of data breach study - France
2013 cost of data breach study - France
 
GDPRIBMWhitePaper
GDPRIBMWhitePaperGDPRIBMWhitePaper
GDPRIBMWhitePaper
 
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
 
Data Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPRData Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPR
 
New rules of Digital Marketing 25 May2016
New rules of Digital Marketing 25 May2016New rules of Digital Marketing 25 May2016
New rules of Digital Marketing 25 May2016
 
EMEA Quarterly Update: GDPR Two Years Later
EMEA Quarterly Update: GDPR Two Years LaterEMEA Quarterly Update: GDPR Two Years Later
EMEA Quarterly Update: GDPR Two Years Later
 
Ipswitch and cordery on the road " All you need to know about GDPR but are t...
Ipswitch and cordery on the road  " All you need to know about GDPR but are t...Ipswitch and cordery on the road  " All you need to know about GDPR but are t...
Ipswitch and cordery on the road " All you need to know about GDPR but are t...
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
 
ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection Regulation
 
Research Data Codes of Conduct - Status and Roadmap
Research Data Codes of Conduct - Status and RoadmapResearch Data Codes of Conduct - Status and Roadmap
Research Data Codes of Conduct - Status and Roadmap
 
Are you preparing for GDPR?
Are you preparing for GDPR?Are you preparing for GDPR?
Are you preparing for GDPR?
 
Sustainable Brands New Metrics: The evolution of social and human capital man...
Sustainable Brands New Metrics: The evolution of social and human capital man...Sustainable Brands New Metrics: The evolution of social and human capital man...
Sustainable Brands New Metrics: The evolution of social and human capital man...
 
Third-Party Risk Management: How to Identify, Assess & Act
Third-Party Risk Management: How to Identify, Assess & ActThird-Party Risk Management: How to Identify, Assess & Act
Third-Party Risk Management: How to Identify, Assess & Act
 

Ähnlich wie GDPR & corporate governance: the role of risk management and internal audit one year after implementation

FERMA Survey - Press Release
FERMA Survey - Press ReleaseFERMA Survey - Press Release
FERMA Survey - Press Release
FERMA
 

Ähnlich wie GDPR & corporate governance: the role of risk management and internal audit one year after implementation (20)

The European risk manager report 2020: webinar presentation
The European risk manager report 2020: webinar presentationThe European risk manager report 2020: webinar presentation
The European risk manager report 2020: webinar presentation
 
FERMA European Risk Manager Report 2020: full set of results
FERMA European Risk Manager Report 2020: full set of results  FERMA European Risk Manager Report 2020: full set of results
FERMA European Risk Manager Report 2020: full set of results
 
GDPR & corporate governance: The Role of Internal Audit and Risk Management O...
GDPR & corporate governance: The Role of Internal Audit and Risk Management O...GDPR & corporate governance: The Role of Internal Audit and Risk Management O...
GDPR & corporate governance: The Role of Internal Audit and Risk Management O...
 
Ferma PwC European Risk Manager Report_ full set results 2018
Ferma PwC European Risk Manager Report_ full set results 2018Ferma PwC European Risk Manager Report_ full set results 2018
Ferma PwC European Risk Manager Report_ full set results 2018
 
FERMA European risk and insurance report 2016 - full set of results
FERMA European risk and insurance report 2016 - full set of resultsFERMA European risk and insurance report 2016 - full set of results
FERMA European risk and insurance report 2016 - full set of results
 
8th edition of the FERMA benchmarking survey
8th edition of the FERMA benchmarking survey8th edition of the FERMA benchmarking survey
8th edition of the FERMA benchmarking survey
 
Webinar: Why risk managers should look at Artificial Intelligence now?
Webinar: Why risk managers should look at Artificial Intelligence now?Webinar: Why risk managers should look at Artificial Intelligence now?
Webinar: Why risk managers should look at Artificial Intelligence now?
 
Ferma European Risk Manager Report 2018
Ferma European Risk Manager Report 2018Ferma European Risk Manager Report 2018
Ferma European Risk Manager Report 2018
 
FERMA Newsletter #70
FERMA Newsletter #70FERMA Newsletter #70
FERMA Newsletter #70
 
FERMA European Risk and Insurance Report (ERIR) 2016
FERMA European Risk and Insurance Report (ERIR) 2016FERMA European Risk and Insurance Report (ERIR) 2016
FERMA European Risk and Insurance Report (ERIR) 2016
 
European Risk Management Seminar 2018 - Cyber Report
European Risk Management Seminar 2018 - Cyber Report European Risk Management Seminar 2018 - Cyber Report
European Risk Management Seminar 2018 - Cyber Report
 
The State of TPRM in the UK - DVV Solutions Breakfast Briefing March 2019
The State of TPRM in the UK - DVV Solutions Breakfast Briefing March 2019The State of TPRM in the UK - DVV Solutions Breakfast Briefing March 2019
The State of TPRM in the UK - DVV Solutions Breakfast Briefing March 2019
 
FERMA Newsletter #61
FERMA Newsletter #61FERMA Newsletter #61
FERMA Newsletter #61
 
FERMA Risk Management Benchmarking Survey 2014
FERMA Risk Management Benchmarking Survey 2014FERMA Risk Management Benchmarking Survey 2014
FERMA Risk Management Benchmarking Survey 2014
 
WISER @Ferma Forum, 4-7 October 2015, Venice, Italy
WISER @Ferma Forum, 4-7 October 2015, Venice, ItalyWISER @Ferma Forum, 4-7 October 2015, Venice, Italy
WISER @Ferma Forum, 4-7 October 2015, Venice, Italy
 
Francesco Аlbore fraud prevention, sofia conf 2016, olaf presentation
Francesco Аlbore   fraud prevention, sofia conf 2016, olaf presentationFrancesco Аlbore   fraud prevention, sofia conf 2016, olaf presentation
Francesco Аlbore fraud prevention, sofia conf 2016, olaf presentation
 
FERMA Survey - Press Release
FERMA Survey - Press ReleaseFERMA Survey - Press Release
FERMA Survey - Press Release
 
FERMA Newsletter #69
FERMA Newsletter #69FERMA Newsletter #69
FERMA Newsletter #69
 
Decoding the review of EU's Non-Financial Reporting Directive
Decoding the review of EU's Non-Financial Reporting DirectiveDecoding the review of EU's Non-Financial Reporting Directive
Decoding the review of EU's Non-Financial Reporting Directive
 
Standards in Third Party Risk - DVV Solutions ISACA North May 19
Standards in Third Party Risk - DVV Solutions ISACA North May 19 Standards in Third Party Risk - DVV Solutions ISACA North May 19
Standards in Third Party Risk - DVV Solutions ISACA North May 19
 

Mehr von FERMA

FERMA Webinar: At the Junction of Corporate Governance and Cyber Security
FERMA Webinar: At the Junction of Corporate Governance and Cyber SecurityFERMA Webinar: At the Junction of Corporate Governance and Cyber Security
FERMA Webinar: At the Junction of Corporate Governance and Cyber Security
FERMA
 

Mehr von FERMA (19)

FERMA contribution to the French Presidency agenda
FERMA contribution to the French Presidency agendaFERMA contribution to the French Presidency agenda
FERMA contribution to the French Presidency agenda
 
The role of risk management in corporate resilience
The role of risk management in corporate resilienceThe role of risk management in corporate resilience
The role of risk management in corporate resilience
 
Webinar: the role of risk management in corporate resilience
Webinar: the role of risk management in corporate resilience Webinar: the role of risk management in corporate resilience
Webinar: the role of risk management in corporate resilience
 
People, Planet & Performance: sustainability guide for risk and insurance man...
People, Planet & Performance: sustainability guide for risk and insurance man...People, Planet & Performance: sustainability guide for risk and insurance man...
People, Planet & Performance: sustainability guide for risk and insurance man...
 
Collaboration of the Year Award winner 2020: Pim Moerman and Rob van den Eijn...
Collaboration of the Year Award winner 2020: Pim Moerman and Rob van den Eijn...Collaboration of the Year Award winner 2020: Pim Moerman and Rob van den Eijn...
Collaboration of the Year Award winner 2020: Pim Moerman and Rob van den Eijn...
 
Argo Group: operationalizing emerging risk 2020
Argo Group: operationalizing emerging risk 2020Argo Group: operationalizing emerging risk 2020
Argo Group: operationalizing emerging risk 2020
 
Argo Group: entry for emerging risk initiative of the year Award 2020
Argo Group: entry for emerging risk initiative of the year Award 2020Argo Group: entry for emerging risk initiative of the year Award 2020
Argo Group: entry for emerging risk initiative of the year Award 2020
 
George Ong, Chief Risk Officer, Northern Ireland Water
George Ong, Chief Risk Officer, Northern Ireland WaterGeorge Ong, Chief Risk Officer, Northern Ireland Water
George Ong, Chief Risk Officer, Northern Ireland Water
 
Webinar: Risk management in a global pandemic - Early lessons learned, EU – U...
Webinar: Risk management in a global pandemic - Early lessons learned, EU – U...Webinar: Risk management in a global pandemic - Early lessons learned, EU – U...
Webinar: Risk management in a global pandemic - Early lessons learned, EU – U...
 
Risk management recovery and resilience covid 19 survey report 2020 2020.12.0...
Risk management recovery and resilience covid 19 survey report 2020 2020.12.0...Risk management recovery and resilience covid 19 survey report 2020 2020.12.0...
Risk management recovery and resilience covid 19 survey report 2020 2020.12.0...
 
Webinar: how risk management can contribute to sustainable growth?
Webinar: how risk management can contribute to sustainable growth?Webinar: how risk management can contribute to sustainable growth?
Webinar: how risk management can contribute to sustainable growth?
 
FERMA Webinar: At the Junction of Corporate Governance and Cyber Security
FERMA Webinar: At the Junction of Corporate Governance and Cyber SecurityFERMA Webinar: At the Junction of Corporate Governance and Cyber Security
FERMA Webinar: At the Junction of Corporate Governance and Cyber Security
 
European risk management sustainability seminar report
European risk management sustainability seminar reportEuropean risk management sustainability seminar report
European risk management sustainability seminar report
 
Fer008 ferma risk-mangmt_18_sem_sustainabiity_report_v15_07_nov18 (1)
Fer008 ferma risk-mangmt_18_sem_sustainabiity_report_v15_07_nov18 (1)Fer008 ferma risk-mangmt_18_sem_sustainabiity_report_v15_07_nov18 (1)
Fer008 ferma risk-mangmt_18_sem_sustainabiity_report_v15_07_nov18 (1)
 
European Risk Management Seminar 2018 - Sustainability Report
European Risk Management Seminar 2018 - Sustainability ReportEuropean Risk Management Seminar 2018 - Sustainability Report
European Risk Management Seminar 2018 - Sustainability Report
 
Ferma perspectives #2 - Cyber Risk Governance 09.10.2018
Ferma perspectives #2 - Cyber Risk Governance 09.10.2018Ferma perspectives #2 - Cyber Risk Governance 09.10.2018
Ferma perspectives #2 - Cyber Risk Governance 09.10.2018
 
Preparing for cyber insurance - FERMA - Insurance Europe - BIPAR
Preparing for cyber insurance - FERMA - Insurance Europe - BIPARPreparing for cyber insurance - FERMA - Insurance Europe - BIPAR
Preparing for cyber insurance - FERMA - Insurance Europe - BIPAR
 
1st international edition of the RMIS Panorama with the support of FERMA network
1st international edition of the RMIS Panorama with the support of FERMA network1st international edition of the RMIS Panorama with the support of FERMA network
1st international edition of the RMIS Panorama with the support of FERMA network
 
FERMA Network: facts and figures about risk management associations in Europe
FERMA Network: facts and figures about risk management associations in EuropeFERMA Network: facts and figures about risk management associations in Europe
FERMA Network: facts and figures about risk management associations in Europe
 

Kürzlich hochgeladen

The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
daisycvs
 
Mckinsey foundation level Handbook for Viewing
Mckinsey foundation level Handbook for ViewingMckinsey foundation level Handbook for Viewing
Mckinsey foundation level Handbook for Viewing
Nauman Safdar
 
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pillsMifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
Abortion pills in Kuwait Cytotec pills in Kuwait
 
Structuring and Writing DRL Mckinsey (1).pdf
Structuring and Writing DRL Mckinsey (1).pdfStructuring and Writing DRL Mckinsey (1).pdf
Structuring and Writing DRL Mckinsey (1).pdf
laloo_007
 

Kürzlich hochgeladen (20)

Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Century
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with Culture
 
Falcon Invoice Discounting: Tailored Financial Wings
Falcon Invoice Discounting: Tailored Financial WingsFalcon Invoice Discounting: Tailored Financial Wings
Falcon Invoice Discounting: Tailored Financial Wings
 
Lundin Gold - Q1 2024 Conference Call Presentation (Revised)
Lundin Gold - Q1 2024 Conference Call Presentation (Revised)Lundin Gold - Q1 2024 Conference Call Presentation (Revised)
Lundin Gold - Q1 2024 Conference Call Presentation (Revised)
 
BeMetals Investor Presentation_May 3, 2024.pdf
BeMetals Investor Presentation_May 3, 2024.pdfBeMetals Investor Presentation_May 3, 2024.pdf
BeMetals Investor Presentation_May 3, 2024.pdf
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
 
TVB_The Vietnam Believer Newsletter_May 6th, 2024_ENVol. 006.pdf
TVB_The Vietnam Believer Newsletter_May 6th, 2024_ENVol. 006.pdfTVB_The Vietnam Believer Newsletter_May 6th, 2024_ENVol. 006.pdf
TVB_The Vietnam Believer Newsletter_May 6th, 2024_ENVol. 006.pdf
 
Mckinsey foundation level Handbook for Viewing
Mckinsey foundation level Handbook for ViewingMckinsey foundation level Handbook for Viewing
Mckinsey foundation level Handbook for Viewing
 
Falcon Invoice Discounting: Aviate Your Cash Flow Challenges
Falcon Invoice Discounting: Aviate Your Cash Flow ChallengesFalcon Invoice Discounting: Aviate Your Cash Flow Challenges
Falcon Invoice Discounting: Aviate Your Cash Flow Challenges
 
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pillsMifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
 
Call 7737669865 Vadodara Call Girls Service at your Door Step Available All Time
Call 7737669865 Vadodara Call Girls Service at your Door Step Available All TimeCall 7737669865 Vadodara Call Girls Service at your Door Step Available All Time
Call 7737669865 Vadodara Call Girls Service at your Door Step Available All Time
 
CROSS CULTURAL NEGOTIATION BY PANMISEM NS
CROSS CULTURAL NEGOTIATION BY PANMISEM NSCROSS CULTURAL NEGOTIATION BY PANMISEM NS
CROSS CULTURAL NEGOTIATION BY PANMISEM NS
 
Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptx
 
Pre Engineered Building Manufacturers Hyderabad.pptx
Pre Engineered  Building Manufacturers Hyderabad.pptxPre Engineered  Building Manufacturers Hyderabad.pptx
Pre Engineered Building Manufacturers Hyderabad.pptx
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
 
Buy gmail accounts.pdf buy Old Gmail Accounts
Buy gmail accounts.pdf buy Old Gmail AccountsBuy gmail accounts.pdf buy Old Gmail Accounts
Buy gmail accounts.pdf buy Old Gmail Accounts
 
Buy Verified TransferWise Accounts From Seosmmearth
Buy Verified TransferWise Accounts From SeosmmearthBuy Verified TransferWise Accounts From Seosmmearth
Buy Verified TransferWise Accounts From Seosmmearth
 
HomeRoots Pitch Deck | Investor Insights | April 2024
HomeRoots Pitch Deck | Investor Insights | April 2024HomeRoots Pitch Deck | Investor Insights | April 2024
HomeRoots Pitch Deck | Investor Insights | April 2024
 
Structuring and Writing DRL Mckinsey (1).pdf
Structuring and Writing DRL Mckinsey (1).pdfStructuring and Writing DRL Mckinsey (1).pdf
Structuring and Writing DRL Mckinsey (1).pdf
 

GDPR & corporate governance: the role of risk management and internal audit one year after implementation

  • 1. Live Webinar #4 – Thursday 5 December 2019
  • 2. GDPR : where do we stand? Framework : • 27th April 2016 : Adoption • 6th May 2018 : Application • May 2020: Public evaluation report by the Commission in May 2020 and transmitted to the European parliament and to the Council • 2020 : E-PRIVACY • April 2019 : European Data Protection Board report: COOPERATION – CONSISTENCY – STANDARDISED for Supervisory Authorities • July 2019 – European Commission Communication taking stock of one year application of the GDPR • June 2019 - European Commission report of the multi-stakeholder group Total 206326 Complaint s 94622 Data breach notificat ions 64684 Other 47020 47% 52% 1% Ongoing Closed Appealed SAs from 11 EEA countries imposed a total of €55.955,671 in fines
  • 3. GDPR : where do we stand? A joint project carried out between ECIIA and FERMA, with the support of 5 IIA national Institutes and 11 national risk management associations. Our ambitious objectives were to: • Collect “best practices” and key challenges related to GDPR from a large panel of practitioners. • Promote good governance and internal audit and risk management alongside the GDPR. • Provide facts and tangibles to be used as an advocacy tool for the new GDPR guidelines.Up to 19Questions in total 346 respondents 25 Interviewees
  • 4. GDPR : expert’s introduction Lene Ritz Chief Risk Officer & Team leader Energinet (Denmark) Ralf Herold SVP Corporate Audit BASF (Germany)
  • 5. GDPR : Polling question #1 Do you have a DPO internally or as outsourced function ? • Internally – new function • Internally – existing function • Outsourced • Other
  • 6. Do you have a DPO internally or as outsourced function ? 6 Yes 82% No 18% DPO role was assigned internally to an existing function 53% New internal function … Outsource d 11% 1.Legal - Compliance : 54% 2.IT - IS : 15% 3.Risk Management : 11% 4.Operations - Finance : 10%
  • 7. GDPR : Polling question #2 What is your level of interaction with the DPO ? • Formalised • Not Formalised • No contact • Not applicable
  • 8. What is your level of interaction with the DPO ? Formalised (several times a year…) 31% Not formalised (on request) 55% Not applicable – I’m the DPO… No contact… Not sure 1% 86% in contact
  • 9. GDPR : Polling question #3 In your organisation, who is in charge of reporting to the Board about data privacy matters including GDPR ? • DPO • Senior Management • CRO • CAE • Other
  • 10. Who is in charge of reporting to the Board about data privacy matters including GDPR? CAE 7% CRO 10% DPO 43% Senior management 21% Other 19%
  • 11. GDPR : Polling question #4 Do you foresee that the GDPR related engagements will become recurring audits in your audit plan ? • Yes • No • I do not know
  • 12. What elements of GDPR do you plan to (or currently) audit? 56% 44% 42% 33% GDPR Governance GDPR General Design GDPR Implementation GDPR performance & effectiveness 39% 60% 47% 2018 2019 2020 Audit plan trends
  • 13. GDPR : Polling question #5 Which one of the following type of risks does GDPR represent for your organisation? • Strategic • Operational • Compliance • Financial • Reputational
  • 14. How do you rate the various risks of GDPR in your organisation ?
  • 15. Did you perform an evaluation of the threats arising from the GDPR implementation? Yes 76% No 24% Yes, they have been financially quantified and with proposed mitigation measures 30% Yes, as regards frequency and severity without financial quantification 44% No, not my role, performed by another function, please specify which one 26% Is Data Protection integrated in your global risk mapping of ERM?
  • 16. What are the challenges of GDPR implementation in your organisation ? Top challenges mentioned by respondents in the survey (%) 1. Uncertainty, complexity 30% 2. Innovation/ R&D 25% 3. Workload, resources 17% 4. Relations – 3rd parties 14% 5. Relations – internal 14%
  • 20. Main recommendations for IA and the European Authorities 1. Recognize the key role played by corporate governance in ensuring GDPR compliance as well as a certain degree of accountability of organizations about personal data protection. 2. Reduce the uncertainty of how local authorities will deal with GDPR compliance (interpretation of what constitutes “high” risks, amount, format and frequency of the reporting…). 3. Formalize the relationship regarding privacy risks between the DPO, Risk Management and Internal Audit, relying on the three lines of defense model as a starting point.
  • 21. Main recommendations for RM and the European Authorities 1. Embed data privacy in most of the existing risk maps. 2. Include the understanding of how privacy risks can affect all aspects of the business into their risk assessment, in order to propose credible and documented mitigation measures to the senior management of the organisation 3. The next review of the GDPR by the European Commission in May 2020 should preserve the organisation’s ability to innovate.
  • 22. Next steps Final report available on FERMA and ECIIA websites FERMA and ECIIA to follow up with EU institution s in 2020
  • 23. Thank you and see you in 2020 Subscribe to our newsletter to stay informed https://www.ferma.eu/conta ct-us/
  • 24. About FERMA FERMA brings together 21 risk management associations in 20 European countries. They represent nearly 5,000 professional risk managers active in a wide range of business sectors. The Federation of European Risk Management Associations (FERMA) speaks for the risk management profession in Europe. FERMA acts on its behalf at European level and promotes the risk management profession. FERMA provides a risk management perspective on European issues and strengthens the profession through a European risk management certification (rimap).
  • 25. About ECIIA ECIIA gives voice to 47.000 Internal Auditors in 34 countries from wider Europe. The European Confederation of Institutes of Internal Auditing (ECIIA) is the voice of internal audit in Europe. Our role is to enhance corporate governance through the promotion of the professional practice of internal auditing. The ECIIA mission is to further the development of good corporate governance and internal audit at the European level, through • Knowledge sharing • Developing key relationships • Impacting the regulatory environment, by dealing with the European Union, its Parliament and the European Authorities.

Hinweis der Redaktion

  1. TB Quelle source pour les chiffres? July 2019 – European Commission Communication taking stock of one year application of the GDPR: https://ec.europa.eu/info/sites/info/files/aid_development_cooperation_fundamental_rights/aid_and_development_by_topic/documents/communication_2019374_final.pdf   June 2019 - European Commission Report of the multi-stakeholder group:   http://ec.europa.eu/transparency/regexpert/index.cfm?do=groupDetail.groupMeeting&meetingId=15670
  2. PVB Présenter aussi la structure du doc: reco pour les autorités, praticiens du risk et audit puis détails des résultats des questions du survey et analyse
  3. TB Lene Ritz is Chief Risk Officer and Team leader for the Danish company Energinet since 2014. She has developed the ERM strategy and set up the risk management function at Energinet. Lene participates in international works and networks including FERMA and has performed numerous speeches and presentations Ralf Herold is Senior Vice President Corporate audit at BASF a German company. He is an expert in GDPR as Germany was a pioneer in this piece of legislation
  4. TB
  5. TB
  6. PVB
  7. PVB
  8. TB
  9. TB
  10. PVB
  11. PVB
  12. TB
  13. TB Financial risk is surprisingly low (11% high) Reputation risk is high on the agenda (47% high)
  14. TB
  15. PVB Challenges identifiés dans le rapport – juste des keywords
  16. Slide non affiché Demander aux experts des recommandations clés pour les entreprises, sur la base de celles du rapport TB – 1 reco pour les autorités PVB – 1 reco pour les autorités
  17. Slide non affiché
  18. Slide non affiché