Articles

Preparing for the GDPR: How can Winterhawk help?

Over the past three weeks, we’ve taken you on a practical journey, describing step-by-step the approaches our clients have taken in preparation for the GDPR. Step 1) Identify the gaps  Step 2) Plug the gaps  Step 3) Moving to Continuous Improvement  About half of the organisations we’ve been involved with already had a Data Protection Officer (DPO) appointed; of those

Read More »

Preparing for the GDPR: Step 3) Moving to Continuous Improvement

Regardless of the regulation, some organisations’ approach to ongoing regulatory compliance is to adopt a continuous improvement model. The rationale being that any given audit, whether internal or external, is conducted at a point in time and is therefore a snapshot of the state of compliance at that given moment. The trouble with this approach is that today you could

Read More »

Preparing for the GDPR: Step 2) Plugging the gaps

Now that your organisation has successfully completed the workshop to review current processes and data protection obligations (described in last week’s post) you now understand where and what the gaps are. The workshop should result in an Executive Report which the workshop leaders present to the board, or at least the senior management team, to get buy-in, resources and budget

Read More »

Preparing for the GDPR: Step 1) Identify the gaps

We are starting to see organisations taking stock of how they currently comply with local Data Protection laws. That is certainly a commendable first step – if you don’t comply with the currently enforceable Data Protection laws, you may have some way to go with the new, updated laws emanating from the GDPR. Current Data Protection laws Looking at the

Read More »

Who are the people in your neighbourhood?

Like most children growing up in North America in the 1970’s, Sesame Street was a part of my daily schedule. The programme had puppets, humour & catchy songs – everything a pre-schooler could want from a TV show. My favourite Sesame Street song was “The People in Your Neighbourhood;” it’s about the occupations children are likely to encounter in their

Read More »

GDPR: When is a law a law?

  By Elodie Ellingsen, Data Privacy Officer The UK government website glossary defines a Regulation as “a legislative act of the EU which is directly applicable in Member States without the need for national implementing legislation. [Article 288 TFEU].” Did you know that under EU law, Regulations become automatically binding and directly applicable on the date they enter into force?

Read More »

Management Consultancy: The view from both sides

By Suki Latuske, SAP Security & GRC Manager A recent BBC News article titled “Managing the managers: The rise of the ‘philosopher-kings’” by Tim Harford, made me think about the perception of Management Consultants. Winterhawk is a boutique consultancy – each of us has had it drilled into us that the customer and value-added services are our focuses. Having been

Read More »

Access Control: SP19 is Here!

By Andrew Sawyer, Chief Operations Officer On the 23rd of October, we received the news those of us who work within SAP Access Risk & Provisioning have been waiting for. That’s right – SAP have released Support Pack 19 for Access Control 10.1 (cue the trumpets)! Among the many released notes, the highlight of this Support Pack provides the much-requested

Read More »

Why I’m a big fan of the GDPR – A Canadian’s viewpoint

  By Elodie Ellingsen, Data Privacy Officer I am proud to come from Canada – a country where you cannot ask personal questions which could support any kind of discrimination. During a job interview, for instance, questions pertaining to ethnicity, religion, gender, age or disabilities may not be asked. The Canadian Charter of Rights and Freedoms is a bill of

Read More »

GDPR: My organisation is paper-based, so it doesn’t apply to us…

Wrong. GDPR still applies, and here’s why. Records can be stolen and misused whether they are on paper or stored digitally. If the information included in a given record can be used to identify an individual, then it falls under General Data Protection Regulations. Consider all your organisation’s physical paper and digital records. Do they include information about employees or

Read More »
Scroll to Top