{"id":183,"date":"2018-09-17T12:23:00","date_gmt":"2018-09-17T06:53:00","guid":{"rendered":"http:\/\/www.sws-international.com\/?p=183"},"modified":"2018-09-17T12:23:00","modified_gmt":"2018-09-17T06:53:00","slug":"evolution-of-data-governance-ecosystem","status":"publish","type":"post","link":"https:\/\/swstech.sws-international.com\/?p=183","title":{"rendered":"Evolution of Data Governance Ecosystem"},"content":{"rendered":"<div data-blogger-escaped-style=\"text-align: justify;\">\n<p>The emergence of Data Protection regulations is going to bring forward a new data governance ecosystem to regulate the business market place.<\/p>\n<\/div>\n<div data-blogger-escaped-style=\"text-align: justify;\">\n<p>While earlier, Cyber Security related work was predominantly seen only in IT world, and rest of organizations used to mostly work to get their ISO and Cyber Security regulations, a new paradigm is expected to evolve to regulate data importance across industry (both Tech and Non-Tech)<\/p>\n<\/div>\n<div data-blogger-escaped-style=\"text-align: justify;\"><\/div>\n<div data-blogger-escaped-style=\"text-align: justify;\">\n<p>The business place will evolve to have following entities apart from the users whose personal data is being processed by Controllers and processors.<\/p>\n<\/div>\n<ol>\n<li>Data Controllers (and its representation by DPO)<\/li>\n<li>Data Processors (and its representation by\u00a0DPO)<\/li>\n<li>Certification Authorities<\/li>\n<li>Independent Regulator (example in case of GDPR, Supervisory Authority headed by a Lead Supervisory Authority)<\/li>\n<li>Government Body (Department dealing with Data Protection Laws)<\/li>\n<li>Court<\/li>\n<li>Data Protection Board (constituted in Europe to ensure consistent application of Regulation across members states)<\/li>\n<li>[Standard Development Organizations]<\/li>\n<li>Consulting Organizations<\/li>\n<\/ol>\n<div data-blogger-escaped-style=\"text-align: justify;\">\n<p><span style=\"color: #0000ff;\" data-blogger-escaped-style=\"color: blue;\">Data Controllers and Data Processors<\/span>\u00a0(#1 \/ #2), organizations capturing &amp; processing personal data of users, shall appoint a\u00a0<span style=\"color: #0000ff;\" data-blogger-escaped-style=\"color: blue;\">DPO\u00a0<\/span>(Data Protection Officer) who is going to be SPOC for end users (it is going to be mandatory for specific cases where significant personal data is going to be processed, or data being processed is of sensitive nature)<\/p>\n<\/div>\n<div data-blogger-escaped-style=\"text-align: justify;\"><\/div>\n<div data-blogger-escaped-style=\"text-align: justify;\">\n<p><span style=\"color: #0000ff;\" data-blogger-escaped-style=\"color: blue;\">Certification Authorities<\/span>\u00a0(#3) are going to help evaluate technology and organizational implementations sufficiency to validate required level of adherence to Regulation.<\/p>\n<\/div>\n<div data-blogger-escaped-style=\"text-align: justify;\"><\/div>\n<div data-blogger-escaped-style=\"text-align: justify;\">\n<p><span style=\"color: #0000ff;\" data-blogger-escaped-style=\"color: blue;\">Independent Regulator\u00a0<\/span>(#4) is going to ensure monitoring the application of Regulation, and act as bridge between Users and Organizations (both Private and Govt, including controller and processor).\u00a0 In case of European Union, there is going to be one or more supervisory authorities per Member State (in case of multiple authorities, Govt to decided which Supervisory Authority shall be representing authority in Board (#7)). The regulator will be lead by a Lead Supervisory Authority.<\/p>\n<\/div>\n<div data-blogger-escaped-style=\"text-align: justify;\"><\/div>\n<div data-blogger-escaped-style=\"text-align: justify;\">\n<p>In case of contention, users will have right to Judicial proceeding against Regulator (supervisory authority), controller or processor (#4\/#2\/#3)in an appropriate\u00a0<span style=\"color: #0000ff;\" data-blogger-escaped-style=\"color: blue;\">court of law\u00a0<\/span>(#6).<\/p>\n<\/div>\n<div data-blogger-escaped-style=\"text-align: justify;\"><\/div>\n<div data-blogger-escaped-style=\"text-align: justify;\">\n<p>A\u00a0<span style=\"color: #0000ff;\" data-blogger-escaped-style=\"color: blue;\">Data Protection Board<\/span>\u00a0(#7) has been constituted in case of European Union to ensure consistent application of Regulation across its member states. The Member State Government has right to participate in activities of Board (without voting right)<\/p>\n<\/div>\n<div data-blogger-escaped-style=\"text-align: justify;\"><\/div>\n<div data-blogger-escaped-style=\"text-align: justify;\">\n<p>Apart from this, several organizations (self driven, industry specific) are evolving that provide for standard and code of conduct for several domain \/ sector specific requirements.<\/p>\n<\/div>\n<div data-blogger-escaped-style=\"text-align: justify;\"><\/div>\n<div data-blogger-escaped-style=\"text-align: justify;\">\n<p>The market place has already several\u00a0<span style=\"color: #0000ff;\" data-blogger-escaped-style=\"color: blue;\">Consulting\u00a0<\/span>and Solution providing organizations (#9) that are already providing several services to Data Controllers \/ Processors, including but not limited to following:<\/p>\n<\/div>\n<ul>\n<li>Preparing Organization for Certifications<\/li>\n<li>Privacy Impact (PIA or DPIA) assessment in case of new technology implementation or projects dealing with Personal Data<\/li>\n<li>Legal &amp; Financial Consulting (example related to Loss &amp; Compensation Suites, Cross border data flow, Merger &amp; Acquisitions)<\/li>\n<li>Technology products and services for Data Protection<\/li>\n<li>Data Audits (this service is expected to gain prominence)<\/li>\n<\/ul>\n<div>\n<p>There is going to be high level of churn for various industries based on these developments happening. Few examples include:<\/p>\n<ol>\n<li>Biometric identification industry will go through major changes, and face major risk on their business volume.<\/li>\n<li>Several Quality Certification industries are gearing up for new need of Data Audits, Certification and training needs that will be required across industries that deal with personal data.<\/li>\n<li>PIA perlocation, Risk Management firms will start happening across globe<\/li>\n<li>CAs, Law firms are gearing up challenge that will be brought by trans-border flow of data, difference in regulations, complaints from users.<\/li>\n<\/ol>\n<\/div>\n<div data-blogger-escaped-style=\"text-align: justify;\">\n<p>Reference<\/p>\n<\/div>\n<ol data-blogger-escaped-style=\"text-align: left;\">\n<li data-blogger-escaped-style=\"text-align: justify;\"><a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CELEX:32016R0679&amp;from=EN\" data-blogger-escaped-target=\"_blank\">GDPR<\/a>\u00a0Act<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>The emergence of Data Protection regulations is going to bring forward a new data governance ecosystem to regulate the business [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[4],"tags":[],"class_list":["post-183","post","type-post","status-publish","format-standard","hentry","category-data-protection"],"_links":{"self":[{"href":"https:\/\/swstech.sws-international.com\/index.php?rest_route=\/wp\/v2\/posts\/183","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/swstech.sws-international.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/swstech.sws-international.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/swstech.sws-international.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/swstech.sws-international.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=183"}],"version-history":[{"count":0,"href":"https:\/\/swstech.sws-international.com\/index.php?rest_route=\/wp\/v2\/posts\/183\/revisions"}],"wp:attachment":[{"href":"https:\/\/swstech.sws-international.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=183"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/swstech.sws-international.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=183"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/swstech.sws-international.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=183"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}