Skip to main content

Month: October 2019

Calligo recertifies for ISO 9001 and ISO 27001

Calligo has once again passed two key compliance audit requirements: ISO 9001 and ISO 27001.

These certifications cover our entire European and North American presence, and have been updated to encompass our complete service portfolio, “Global Data Optimization and Privacy Services”.

What this means for our clients

ISO 9001:2015 – Quality Management System

ISO 9001 is the world’s most widely recognized quality management standard. By aligning our internal processes with it, we are assuring our clients that our services will be delivered to a consistently high standard, even as we scale.

 Holding an ISO 9001 certification is objective evidence that we take the high-quality delivery of our services seriously. It was therefore important to us that we ensured that our audit covered our entire service portfolio and all our global locations. Every client of any service should be able to expect the same high-quality service from us.

ISO/IEC 27001:2013 – Information Security Management System

This standard assures clients that we have put in place, and continuously maintain, an effective information security management system (ISMS) – a framework of policies and procedures that keep our own and our clients’ information secure. Our clients can continue to be confident that the confidentiality, integrity and availability of their data is our top priority. The audit involved an extensive assessment of potential vulnerabilities and risks to the business, and the creation of a set of mitigating processes that ensure our ongoing resilience.

Combined with ISO 9001 above, we are showing that we are independently certified as capable of managing clients’ data securely and responsibly, and delivering consistently high-performing services that make their data work harder for them.

IAPP: Privacy. Security. Risk. 2019 – What we learnt

Last week, Calligo exhibited at IAPP’s annual Privacy. Security. Risk 2019 in Las Vegas, Nevada. PSR is noticeably the most significant event in the privacy industry; attracting privacy professionals across the globe to discuss the latest data privacy news, trends, tech and issues.

Over two days, keynotes and panels explored how privacy and technology must work together simultaneously, discussing topics such as building privacy programmes to accommodate a wide range of data privacy laws such as GDPR and CCPA (California Consumer Privacy Act), Privacy by Design, as well as bridging the gap between privacy and security.

What did we learn?
Data Protection Officers

This topic came up repeatedly, and is a subject close to our hearts – appointing a Data Protection Officer.

Currently, under GDPR, articles 37-39 state that if your business is a public authority or if your business handles and processes large quantities of personal data, you are required to appoint a DPO. However, many companies are either not appointing someone at all, or they’re struggling to find an external candidate due to the expense of hiring the right skillset. And, not to forget arguably the most common mistake companies are making – appointing the wrong person internally.

We have seen many businesses appoint someone internally, on top of an existing position, to act as their DPO. This isn’t always wise.

J. Trevor. Hughes, President & CEO of IAPP

A DPO needs to tick several boxes, which are rarely possible for an internal appointment:

A DPO is a very technical and multi-faceted role, and one that has evolved quickly in recent years and that few have experience in
A DPO needs the latest knowledge of data privacy and GDPR, as well as being able to advise on the data protection and Infosecurity.
A DPO must act independently, with no conflict of interest with any other data or privacy-based role, so cannot hold a role in IT, security, HR, finance or legal for example.
A DPO must have access to the highest management levels

To avoid these issues, organizations are increasingly outsourcing their DPOs. Our Data Protection Officer as a Service (DPOaas) provides companies access to independent privacy consultants who will monitor your compliance, conduct audits and represent your organization to data subjects and regulators.

CCPA

Another hot topic during the event was unsurprisingly the introduction of CCPA. With similar implications as GDPR, CCPA will radically transform how businesses across the USA and beyond handle Californians’ personal data. Also, despite having well over a year to prepare for its arrival on the 1st of January 2020, many businesses are falling short.

Seemingly mainly because of a lack of understanding or awareness of the status of the Californian privacy law itself, organizations are struggling to come to terms with its nuances and requirements, such as data consent, opts-ins/outs and consumer access requests.

And whilst businesses play catch-up, another stream of conversation that followed was “what’s next?” Privacy does not stop with the GDPR and CCPA, and with proposed privacy laws from many more US states and countries, what will the next new round of obligations look like? And how will businesses prepare?

Bridging the gap between privacy professionals and Infosecurity

A subject that many privacy professionals can relate to – being able to understand and be understood by IT and Infosec teams.

As privacy laws evolve, they are driving an ever-increasing technical agenda. For example, GDPR’s Privacy by Design requirements are not an issue of legislation, but of technical oversight. Performing these obligations therefore naturally requires privacy professionals and their counterparts in technology and security to co-operate.

Unfortunately, both sides tend to speak a different language. Some words have completely different meanings on both sides of the fence. For example, to a privacy professional, the word “ensure” implies a guarantee that a certain action will be taken, but the same word to a security professional means that there will be vague oversight of a situation. These are far from the same thing! Unsurprisingly, the split lexicon of the two teams can lead to misunderstandings that have substantial commercial and reputational impacts on the business.

Calligo’s Jennifer Wu, Privacy Consultant, even presented on this topic on the Little Big Stage during PSR. Jennifer highlighted the common mistakes both sides are making and how it’s hindering Privacy by Design. She also made recommendations on how to avoid these issues, and how Privacy teams and IT / Infosec teams need to build a better working relationship, which depends on speaking the same language.

If you missed Jennifer’s presentation or would like to discover how to understand or be understood by your CISO and CIO, our ebook “The Privacy Rosetta Stone” provides real-life case studies on three businesses who encountered this language barrier, the impacts it had on their businesses, and how they fixed the problem. It also includes top tips on how to identify a good and bad Privacy and Technical relationship and how to create your own Rosetta Stone.