The General Data Protection Regulation (GDPR) recently went into effect, yet many multinational companies are still behind the compliance curve.

This sweeping regulation requires organizations to meet stringent data protection requirements affecting the personal data of EU citizens and for the first time, also impacts companies that are based outside of Europe. With severe penalties in play - fines of up to €20m or 4% of global annual revenues - corporations must implement actionable and efficient strategies to achieve compliance.

Our global GDPR services include:

GDPR Assessment: Review requirements, applicability, identify gaps and areas of risk across people, process and technology, and develop a pragmatic roadmap and action plan.

GDPR Technology & Program Implementation: Provide privacy subject matter expertise and assist with the implementation of GDPR enabling technology. Our team has experience with GDPR relevant technologies (e.g. Data Mapping, Data Remediation, Incident Response, Subject Access Request Workflow, Records Management, Archival tools and more). Define requirements, perform vendor selection and implement compliant processes and procedures.

Data Map Development: Develop a GDPR specific personal data map and inventory personal data across the enterprise, where it flows internally and externally in the organisation.

Sensitive Data Remediation: Define and classify data to identify redundant, old or trivial (ROT) data appropriate for remediation, and decommission applications.

Data Subject Rights: Define a standardized process to review and efficiently handle Data Subject requests, including defining roles and responsibilities for internal and external stakeholders. Enable efficient data mapping, identification and searching across diverse data sources.

Privacy Impact Assessment & Privacy by Design: Assess risks for specific areas, systems or projects, update system provisioning processes, policies, procedures, roles, and technical standards, and review and align with an Enterprise Risk Framework.

Cybersecurity Assessment and Program Implementation Assess cybersecurity posture and provide recommendations for implementing policies, processes and technologies that establish the appropriate level of security to mitigate risks.

Data Breach Preparedness and Response Develop and implement incident response preparedness, response and notification plans to help companies meet the 72 hour breach notification requirements.

Employee Training and Change Management Develop GDPR awareness campaign and develop multi-channel stakeholder specific training materials for employees, HR, IT, Customer Support, Marketing, and other key stakeholder areas. Ensure client specific drivers are fully reflected in messaging and tonality of communications and training.

Contract Intelligence Identify potentially relevant contracts that may need to be reviewed and updated with new GDPR compliant data protection clauses utilizing FTI or partner related technologies.

GDPR Program Auditing Conduct an independent review and audit of your existing GDPR program and related practices to identify potential areas of improvement and ongoing compliance.