1,453 karma · joined May 16, 2011
Recital 14 - The protection afforded by this Regulation should apply to natural persons, whatever their nationality or place of residence, in relation to the processing of their personal data. This Regulation does not cover the processing of personal data which concerns legal persons and in particular undertakings established as legal persons, including the name and the form of the legal person and the contact details of the legal person.
"The protection afforded by this Regulation should apply to natural persons, whatever their nationality or place of residence, in relation to the processing of their personal data."
Article 3(1) of GDPR "This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not."
Recital 14 of GDPR "The protection afforded by this Regulation should apply to natural persons, whatever their nationality or place of residence, in relation to the processing of their personal data."
A lot of organisations forget to discuss the scope of a subject access request. If you imagine an employee at an average company, an undefined subject access request can include months or years of pension contributions, internet and email logs, training records, meal choices for their end of year party... if their issue is a recent performance review, the scope will often be email chains or HR documentation relating to that. The incentive for them is that they can often have the data they're interested in a short space of time rather than wait longer for pages of data they've got no need in. If you do this, make sure it's a genuine conversation with them and it's documented as to the scope they agreed.
Remember that right to be forgotten isn't an absolute right especially where you're relying on basis other than consent. If you ask your employer to erase all data about you, they'd have an argument under 17.1.a. to argue that it's necessary to keep that information in order to pay you. Nor can you ask the police or tax office to erase your data.
Where a SaaS provider steps into more complex analytics or has some freedom in the process, there's an argument that they're joint controllers and bear those responsibilities. The difference between cloud and on- premises is that you're actively processing personal data in SaaS.
In many cases, the processor/controller relationship will be correct. But GDPR is focused on active compliance so it's something which should be actively considered and documented.
Process maps even at a high level are a good start to decide where you can add value in the quickest way. But make sure you question the business process and whether it's effective before just implementing technology around it.
In terms of project management, something like the Scaled Agile Framework (SAFE) will work in an enterprise environment if you're from an agile background. Minimum Viable Products work well in enterprises but it's often a huge mindshift for enterprise customers who think they need every feature.
Charging by day rate is your best option. Enterprise IT projects will generally overrun and scopes will increase. If you're charging by day, you're protected from scope creep.
Make sure you've documented what you're doing clearly and you've got a strong contract. If I need to challenge an IT supplier over what's been implemented, and I often do, the contract is the first place I started. A good contract and clear expectations is a positive thing for both parties.
Otherwise, the presentation looks amazing and it's interesting to see a company be so open about their deck.
Something like Ernie's would be ideal. It'd even be worthwhile for collecting a few day to day items. I'm surprised Tesco hasn't done this already.