Privacy Assessments
Technological advancement, and the massive, global exchange of personal data borne of it, must have its counterbalances. The General Data Protection Regulation (GDPR) is the manifestation of this notion.
The General Data Protection Regulation (“GDPR”) is the European Union’s comprehensive data privacy law effective as of May 25, 2018. The regulation establishes rules on how organizations collect, use, and protect personal data of individuals in the European Union, and grants those individuals rights over their data, including the right to delete their data and the right to access their data.
Many companies exploring this new privacy doctrine, in the Unites States and elsewhere, are asking “does the GDPR even apply to me?” and “how can the GDPR have province over our business if we’re not even located in the European Union?” The GDPR applies to any organization that is offering goods or services (irrespective of payment) to residents of the European Union or who is monitoring residents of the European Union. Monitoring in the GDPR framework is referred to as “profiling” and is defined as the automated analysis or predicting of behavior, location, movements, reliability, interests, personal preferences, health, economic situation, performance, etc. It does not matter whether an organization operates physically within Europe (a concept referred to as “extraterritoriality”).
Many companies based outside of the European Union are asking “does the GDPR apply to our operations?” and “how can the GDPR have province over our business if we’re not even located in the European Union?” The GDPR applies to any organization that is offering goods or services (irrespective of payment) to residents of the European Union or that is monitoring residents of the European Union. Monitoring is referred to as “profiling” under the GDPR and is defined as the automated analysis or predicting of behavior, location, movements, reliability, interests, personal preferences, health, economic situation, performance, etc. It does not matter whether an organization operates physically within Europe (a concept referred to as “extraterritoriality”).
A GDPR assessment is not required by law, however, it may be useful for companies to identify gaps in compliance with the regulation and avoid the risk of severe financial penalties. Assessments against the GDPR also demonstrate a commitment to privacy that ultimately builds trust and enhances reputation. Recurring assessments can be conducted as a company’s technology evolves, business ventures solidify, or data usage changes.
The planning phase occurs at least two months in advance of fieldwork in accordance with the timing outlined in the job arrangement letter (JAL) or statement of work (SOW) executed with the client. Planning includes confirming timing of interviews with key points of contact and deployment of and evidence gathering for the information request list provided via AuditSource 2.0. Schellman will be available to the client to answer any questions associated with the assessment to ensure both parties are aligned on scope and expectations.
Schellman will hold a kickoff meeting to start fieldwork. Fieldwork consists of various testing procedures to evidence the requirements are met. The testing procedures may include one of the following:
Inquiry of relevant personnel with the requisite knowledge and experience regarding the performance and application of the related requirement
Observation of the relevant processes or procedures that includes, but is not limited to, witnessing the performance of controls or evidence of control performance with relevant personnel
Inspection of the relevant audit records that include, but is not limited to, policies, documented procedures, system configurations, or the existence of sampling attributes such as logged events or acknowledgements
Schellman has a no surprises policy and regular contact with the client during fieldwork, allowing clients to be apprised at all times of conformance status.
Schellman's assessment is focused on creating a deliverable that is clear, concise, and accurate. The draft report is provided within 2-3 weeks of the last day of fieldwork. The final deliverable is available within 5 business days of the client approving the draft version.
Chris is a Director and Privacy Technical Lead at Schellman based out of Atlanta, GA. With more than five years of experience in information assurance, Chris has a concentration in privacy-related engagements.
Whether it is an ISO 27001 certification, SOC 2 examination or a FedRAMP assessment, companies are often challenged by the need to address customer requirements while ensuring a return on compliance investment.
The most important factor in scoping a potential assessment is understanding what deliverable the recipient (i.e. your customer or partner) is expecting.
Once we have scoped your environment and needs, there are several factors that contribute to Schellman’s pricing: