Mariliza Baka and team, planned and implemented the global data mapping project for a multinational pharmaceutical company, leveraging it for compliance of Article 30 of the GDPR while enhancing its data governance, assessing inherited risks and applying necessary security and privacy controls.
The team created more than a 1000 data mapping records and privacy assessments in a 2-year period, for EMEA, ASIAPAC, LATAM countries, as well as Canada and US, while developing mitigation strategies and solutions to reduce identified risks per activity and department.
The team established effective privacy risk management practices by identifying business privacy champions per department for all company’s entities globally, train them on basic notions of privacy and data protection and guide them on how to use the applicable data mapping tool, OneTrust, by scheduling weekly 1-2-1 interviews. The team recorded all activities that entail the processing of personal data at a local, regional and global level; once the identification of records was completed, the team proceed with the completion of the Privacy Impact Assessments (PIAs) on OneTrust to assess the level of the risk of each activity. In the event the level of risk was considered as “high” or “very high”, the team performed Data Protection Impact Assessments (DPIAs) also on OneTrust and classified mitigation measures to be implemented by the company.
The team has recorded the complete data mapping lifecycle, from the moment the data is collected to the point its destructed, creating a culture of monitoring of projects and activities to remain up-to-date and accurate, while streamlining and standardizing company’s privacy program by creating master records to set standards and guidelines on the ways central processing activities or assets should be carried out and managed.
The data mapping exercise also offered insights to company’s gap analysis and together with the planned mitigation of the risks, the team supported company to prevent data breaches and to succeed an audit conducted by data protection authorities.