<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Scott Bancroft Archives - International Finance</title>
	<atom:link href="https://internationalfinance.com/tag/scott-bancroft/feed/" rel="self" type="application/rss+xml" />
	<link>https://internationalfinance.com/tag/scott-bancroft/</link>
	<description>International Finance - Financial News, Magazine and Awards</description>
	<lastBuildDate>Fri, 13 Dec 2019 07:35:11 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://internationalfinance.com/wp-content/uploads/2020/08/favicon-1-75x75.png</url>
	<title>Scott Bancroft Archives - International Finance</title>
	<link>https://internationalfinance.com/tag/scott-bancroft/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>How firms can recover the Holy Grail from GDPR</title>
		<link>https://internationalfinance.com/magazine/banking-magazine/how-firms-can-recover-the-holy-grail-from-gdpr/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=how-firms-can-recover-the-holy-grail-from-gdpr</link>
					<comments>https://internationalfinance.com/magazine/banking-magazine/how-firms-can-recover-the-holy-grail-from-gdpr/#respond</comments>
		
		<dc:creator><![CDATA[Bharath Kumar]]></dc:creator>
		<pubDate>Thu, 12 Jul 2018 09:37:03 +0000</pubDate>
				<category><![CDATA[Banking]]></category>
		<category><![CDATA[July - August 2018]]></category>
		<category><![CDATA[Magazine]]></category>
		<category><![CDATA[business compliance]]></category>
		<category><![CDATA[Capco]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Scott Bancroft]]></category>
		<guid isPermaLink="false">https://www.internationalfinance.com/magazine/?p=3371</guid>

					<description><![CDATA[<p>In this article Scott Bancroft, Capco’s Chief Information Security Officer discusses the five key steps businesses must take to gain from General Data Protection Regulation (GDPR)</p>
<p>The post <a href="https://internationalfinance.com/magazine/banking-magazine/how-firms-can-recover-the-holy-grail-from-gdpr/">How firms can recover the Holy Grail from GDPR</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><span style="font-family: Calibri Light, serif;">In the run up to the GDPR deadline on 25 May, many companies were largely struck by panic. This new EU data privacy law, designed to overhaul how businesses process and handle data, certainly presented some operational challenges for companies. </span></p>
<p><span style="font-family: Calibri Light, serif;">However, as they joined the mad rush to comply or die, many financial services firms seemed to miss that getting GDPR ‘right’ could bring them opportunities that most have been seeking to fulfil forever &#8211; a single view of the customer’s data and effective information management in the digital age. </span></p>
<p><span style="font-family: Calibri Light, serif;">Getting a single view of all data held on a customer has largely become the ‘holy grail’ these days &#8211; allowing businesses to track their customers and communications across all marketing channels, and as a result, turn that data into viable business intelligence. While the big online retailers have been making a success of this for years, few businesses have in financial services. Why? Many haven’t had the financial impetus before, and their technology infrastructure hasn’t been up to it. </span></p>
<p><span style="font-family: Calibri Light, serif;">So how can GDPR facilitate? Most recent financial regulations (such as MiFID II, Open Banking and GDPR) all have elements of data privacy requirements that must be fulfilled. If companies manage GDPR compliance properly, they will spend significantly less time, effort and money on managing other regulations &#8211; and achieve a much-improved level of information management – irrespective of the type of information – in the process. </span></p>
<figure id="attachment_3373" aria-describedby="caption-attachment-3373" style="width: 239px" class="wp-caption alignright"><img fetchpriority="high" decoding="async" class="size-medium wp-image-3373" src="https://www.internationalfinance.com/magazine/wp-content/uploads/2018/07/Scott-Bancroft-239x300.jpg" alt="Scott Bancroft, Capco’s Chief Information Security Officer" width="239" height="300" srcset="https://internationalfinance.com/wp-content/uploads/2018/07/Scott-Bancroft-239x300.jpg 239w, https://internationalfinance.com/wp-content/uploads/2018/07/Scott-Bancroft.jpg 300w" sizes="(max-width: 239px) 100vw, 239px" /><figcaption id="caption-attachment-3373" class="wp-caption-text">Scott Bancroft, Capco’s Chief Information Security Officer</figcaption></figure>
<p><span style="font-family: Calibri Light, serif;">This requires a unified and consistent approach to information throughout its lifecycle, not forgetting record management across the business, which with GDPR returns with a vengeance. Under GDPR, unused or ‘stale’ data must now be disposed of, thus giving companies the ability to properly respond to data subject access requests and perform defensible disposition. </span></p>
<p><span style="font-family: Calibri Light, serif;">Here are my tips on how you can discover the Holy Grail: </span></p>
<ol>
<li><span style="font-family: Calibri Light, serif;"><b>Assess your existing ‘maturity’ in terms of GDPR compliance… and identify any gaps.</b></span></li>
</ol>
<p><span style="font-family: Calibri Light, serif;">This requires looking at the maturity of your whole organisation – and additionally from the perspective of company functions handling customer data, such as human resources, sales &amp; marketing and finance. Remember: the regulator won’t absolve you if all but one of your teams is GDPR compliant!</span></p>
<p><span style="font-family: Calibri Light, serif;">Therefore, company processes and systems should cover all types of business information, not just those pertinent to GDPR. This includes all information repositories in a company, down to end-user computing equipment. </span></p>
<ol start="2">
<li style="list-style-type: none;">
<ol start="2">
<li><span style="font-family: Calibri Light, serif;"><b>Set up an information management programme.</b></span></li>
</ol>
</li>
</ol>
<p><span style="font-family: Calibri Light, serif;">Once a gap assessment has been completed, create an internal team responsible for information management strategy. This needs to have support at board level, to give it the prominence it deserves. </span></p>
<p><span style="font-family: Calibri Light, serif;">The programme should not just concern GDPR, which will undoubtedly be updated or surpassed by new laws and regulations in due course, but all data matters. </span></p>
<p><span style="font-family: Calibri Light, serif;">To be truly effective, the team must additionally contemplate how it can consolidate existing regulatory and compliance change programmes throughout the business. For instance, many businesses have multiple enterprise resource planning (ERP) systems. That in turn, means going through the GDPR consent process multiple times, but also adding to the risk of a breach!</span></p>
<ol start="3">
<li><span style="font-family: Calibri Light, serif;"><b>Fill in the gaps you find from your assessment.<br />
</b></span></li>
</ol>
<p><span style="font-family: Calibri Light, serif;">The difficulty comes with discovering where data comes from, how it is used, and where it resides. Therefore, data management needs to become a continual process of reviewing and tracking these elements. </span></p>
<p><span style="font-family: Calibri Light, serif;">It should be noted that this is not a purely technology-related activity &#8211; and will include non-techie representatives to fully understand the business processes that the information supports. </span></p>
<ol start="4">
<li><span style="font-family: Calibri Light, serif;"><b>Be certain of your evidentiary capabilities &#8211; now and for the future. </b></span></li>
</ol>
<p><span style="font-family: Calibri Light, serif;">Go through GDPR and read it &#8211; yes, all 88 pages! When it comes to data protection, it’s no longer ‘innocent until proven guilty’, the regulator now needs proof of compliance. </span><b> </b><span style="font-family: Calibri Light, serif;">Enlisting the help of internal audit should help with this.</span></p>
<p><span style="font-family: Calibri Light, serif;">To put this into motion, consider what evidence you need, why you need it and how long you’ll retain it. Therefore, knowing the legal citation for retention of information of all types across the whole business becomes an imperative. </span></p>
<p><span style="font-family: Calibri Light, serif;">Also, GDPR gives data subjects additional rights and specifies the times in which companies must comply. This has the potential for litigation to become more commonplace in financial services and some people will want to take advantage of GDPR. For example, GDPR requires you to delete data subject information within 30 days of the request (up to 90 if sufficient complexity can be demonstrated). Yet, you need to know where the data is, that it uniquely identifies the requester, that they are actually the requester (as opposed to a fraudster or third-party), and that the data does not have to be retained for any other legal or regulatory reason. This is a true step-change in the ability of companies to manage information – could your company do this today?</span></p>
<ol start="5">
<li><span style="font-family: Calibri Light, serif;"><b>Know your risks. </b></span></li>
</ol>
<p><span style="font-family: Calibri Light, serif;">You need to ascertain whether the other third-parties (i.e .vendors) you are working with are also GDPR compliant. Your GDPR contracts will therefore require model clauses and risk assessments to ensure these third-parties up to speed. This will in turn give you the opportunity to review both data privacy contractual terms, controls and drive improvement within your third-party risk management process; resulting in a far clearer picture on the level of risk and allows more accurate evaluation of whether this is within your risk appetite. </span></p>
<p><span style="font-family: Calibri Light, serif;"><b>Finally… </b></span></p>
<p><span style="font-family: Calibri Light, serif;">GDPR is what we all should have been doing for years, however, it should be seen as an ongoing process that does not finish at the end of a specific project. It may be painful, but it’s absolutely the right thing to do. As technology and the world moves on, GDPR will evolve. </span></p>
<p><span style="font-family: Calibri Light, serif;">Do not only think about how you meet the minimum requirements of GDPR, but how you’ll use the lessons learnt to anticipate and be ready for the next generation of data privacy requirements. Wouldn’t it be a differentiator if all customer data was available quickly and simply – benefiting both the business and the consumer? That has to be the Holy Grail. </span></p>
<p><span style="font-family: Calibri Light, serif;">How great would it be to go to your boss with a cheaper and more streamlined approach to information management?</span></p>
<p>The post <a href="https://internationalfinance.com/magazine/banking-magazine/how-firms-can-recover-the-holy-grail-from-gdpr/">How firms can recover the Holy Grail from GDPR</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/magazine/banking-magazine/how-firms-can-recover-the-holy-grail-from-gdpr/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
