CIO Applications Europe
About UsConferencePartner With Us
Close
  • Applications
      • Business Intelligence & Analytics
      • Call Center Solutions
      • CRM & Customer Experience
      • Data Center
      • Digital Transformation
      • E-Invoicing
      • Intelligent ERP & Automation
      • Risk Management & Compliance
      • Unified Communications (UCaaS)
  • Industries
      • Automotive & Mobility
      • Construction & Infrastructure
      • Financial Services
      • Healthcare
      • Retail & E-commerce
      • Telecom & Media
      • Travel and Hospitality Tech
  • Technologies
      • Cloud
      • Cybersecurity & Resilience
      • Data Engineering & Analytics
      • Generative and Agentic AI
      • IoT & Edge Computing
      • Robotics
  • Platforms
      • AWS
      • IBM
      • Microsoft
      • Salesforce
      • SAP
      • ServiceNow
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • CXO Awards
    • Europe
      • US
  • Topics

  • Menu
      • Business Intelligence & Analytics
      • Cloud
      • Digital Transformation
      • Generative and Agentic AI
      • Microsoft
      • Risk Management & Compliance
      • Travel and Hospitality Tech
      • Unified Communications (UCaaS)
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Generative and Agentic AI
  • Digital Transformation
  • Business Intelligence & Analytics
  • Cloud
Topics
  • Topics

  • Business Intelligence & Analytics
  • Cloud
  • Digital Transformation
  • Generative and Agentic AI
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Unified Communications (UCaaS)
  • Home

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

Franklin Templeton

Eric Bedell, Chief Privacy Officer

From Privacy Law(S) to an Operational Privacy Programme

GDPR – enforcing accountability

The EU General Data Protection Regulation of 2018, shifted the way organisationsneed to deal with personal data. Before GDPR, it was akin to childhood, where oneneeded to request autorisations or had to follow the strict rules from authorities before using personal data. After GDPR, it has grown up, reaching maturity, where oneshould do what is thought to be best outcome and be-accountable for that. Privacy has been relegated for a long time to a secondary role, an afterthought, with the business considering it as part of a legal checklist. But now, afterEU enforced the GDPR and various EU countries providing guidelines and best practicies, organisations need to embed privacy into its new normality.

Everyone is involved at different levelsand we all have an impact on privacy, from the amount of our own information that we willingly disclose or, as employees, when we handle someone else’s personal data.Everyone agrees that it is not an easy move from the old world to the new, especially in this time of mass data collection. Sometimes, one part of an organisation does not know what other parts are doing. Ever more difficult arethe budget allocations for financing Sizing, targeting, prioritizing and preparing for continuous improvement cycles in privacy management, instead of implementing a succession of one-off projects should help your organisation overcome the challenges.

When leading such a privacy programme, several areas should be concideredto improve efficiency. The first, in my view, is the networking aspect. It is really beneficial to share experiences, issues and successes with your peers.

Organisations that have not already developed their own privacy compliance frameworks should use a standardised framework to ease their path to privacy compliance.

The three key areas of a privacy compliance framework combine an accountability framework, management systems and A privacy programme must be driven as a well as arisk management programme,aligned with the organisation’s global risk programme. Privacy risk must be considered as a risk for the whole organisation, and not as something that a Privacy Office(r) manages in isolation. The value of understanding your data processing activities, as required by GDRP (Record of Processing Activities), can be an incredible source of information for your broader risk management efforts. In addition, assessing risk, given the potential impacts of privacy issues, is a key element of protecting personal data.

Once a framework has been selected (based on network capability, external elements and subsequently developed based on risk assessment) the DPO can commence building a privacy programme. Some important conciderationswhen doing so:

• Implement Governance modelaligned with the type and size of the organisation (using Privacy references/resources located in various lines of business is advantageous)

• Enforcing the “privacy by design” principle is key. Privacy has to be embededin all activties.

• Building a continuous improvement methodology, as it is unrealistic to believe every privacy requirements can be completed in one go.

• Do not use “finger pointing” or “naming and shaming”approaches, especialywhen managing breaches and compliance issues.

• To avoid human errors or unlawful management of personal data, implementtraining and awareness campaigns, for both employees and management.

• The Data Protection Office(r) should rarely veto anything, instead educate thebusiness and advise on potential better methods.

• Another, often forgotten, aspect of awareness is reporting to senior management. In order toprocure appropriate financing, a privacy programmemust be visible, not only because of its risks but also for its achievements.

Finally, in preparation for the future, I recommend starting to embed ethics into the privacy programme. This is not because this is a legal necessity but because your customers/employees expect you to do it. With a well-balanced, operational, Privacy Programme, it can be assured that the organisation will be successful. With Privacy no longer an afterthought, it may even become a marketing advantage.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
The Leadership Perspectives forum brings together voices shaping construction technology and innovation. Participation is by invitation only. It features leaders who are not merely observing technological change, but actively contributing to it through digital transformation and execution-driven insights.
EDITOR'S CHOICE
  • Willis Towers Watson

    Legal & General

    Building Technology Foundations That Last

    Mark Hall, Group Chief Technology Officer

  • Willis Towers Watson

    Adp Uk

    "Shift left" Defect Discovery using Agile and DevOps

    Keith Watson, Director Of Devops

  • Willis Towers Watson

    Motor Oil

    Trust, Security Strategy and the AI-Driven Threat Landscape

    Syngelakis J. Christos, Group Data Protection Officer

  • Willis Towers Watson

    Swiss Re [SWX: SREN]

    A Future of Enhanced Human Work

    Sergio Chelli, IT Procurement Manager at Swiss Re [SWX: SREN]

Weekly Brief

loading

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

×
#

CIO Applications Europe Weekly Brief

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from CIO Applications Europe

Subscribe

loading

THANK YOU FOR SUBSCRIBING

CIO Applications Europe
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@cioapplicationseurope.com
  • sales@cioapplicationseurope.com
  • marketing@cioapplicationseurope.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 CIO Applications Europe. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://www.cioapplicationseurope.com/leadership-perspective/from-privacy-laws-to-an-operational-privacy-programme-nid-3817.html