Privacy Compliance Achieve regulatory compliance and remain competitive Privacy risk is an ongoing challenge for organisations across industries and geographies. New regulations and laws continue to evolve rapidly, making it a challenge for organisations to remain compliant with privacy expectations. Protiviti’s privacy compliance experts identify key risks, address compliance gaps, and provide recommendations and the remediation support necessary to maintain compliance with applicable privacy laws. Identify key risks and address compliance gaps Our Privacy Compliance solutions Pro Briefcase Data Privacy and Data Protection Strategy We help you develop and implement a data privacy and data protection strategy supported by a strategic roadmap to operationalise privacy obligations. We connect people, processes, and technologies to automate and reduce the effort of privacy compliance. Pro Workflow Flowchart Privacy Program Establishment For organisations just getting started on their privacy compliance journey, Protiviti’s privacy compliance experts can identify necessary work streams and establish the foundational elements for a global privacy program. Pro Briefcase Compliance and Third-Party Validation No matter the state of your privacy compliance journey, we help validate and implement efforts to become compliant with regulatory and third-party contractual requirements, including cross-border data transfers. Pro Briefcase Privacy Data Subject Requests Protiviti captures an accurate and complete picture of compliance at scale, enabling companies to manage high-volume data subject requests from consumers. Pro Briefcase Privacy Audits, Assessments, and Consent Order Services We conduct internal audits and assessments to validate and report on the effectiveness of privacy and data protection controls against regulatory requirements and industry frameworks. We also serve as an independent assessor for consent order response services. Pro Legal Briefcase Ongoing Compliance Monitoring Protiviti helps you identify high-risk activities and exposure through ongoing monitoring of compliance data, privacy protection, and changes to legal obligations. Pro Tools Gear Privacy Program Optimisation Data has value for both business growth and compliance. We help you centralise, operationalise, and optimise your data by leveraging industry-leading privacy frameworks for company-wide protection and compliance, such as GDPR, AICPA, and NIST Privacy Framework. FLASH REPORT The American Privacy Rights Act of 2024: Could this framework become the data privacy panacea? On April 8, 2024, U.S. Representative Cathy McMorris Rodgers (R-WA) and U.S. Senator Maria Cantwell (D-WA) announced the American Privacy Rights Act. This act aims to establish a comprehensive set of rules that govern the usage of citizens' data. The... INSIGHTS PAPER Mastering Data Dilemmas: Navigating Privacy, Localisation and Sovereignty In today's digital age, data privacy management is paramount for businesses and individuals alike. With the ever-changing regulatory landscape surrounding data protection, organisations must adapt swiftly to ensure compliance and maintain trust with... FLASH REPORT NIST Releases Version 2.0 of Its Cybersecurity Framework (CSF): What This Means for Your Organisation On February 26, 2024, The National Institute of Standards and Technology (NIST) released version 2.0 of its updated and widely used Cybersecurity Framework (CSF). This latest edition of the CSF is designed for all audiences, industry sectors and... INSIGHTS PAPER How data sovereignty and data localisation impact your privacy programs The concepts of data sovereignty and data localisation stem from a desire to keep data within a country’s borders for greater control. While the broad strokes of various privacy laws may be consistent across jurisdictions, governments will dictate... BLOG SEC Gives Guidance on Permitted Cyber Incident Filing Delays on Material Events The big picture: The SEC has released new rules around the timing and filing of Form 8-K for reporting material cybersecurity incidents that could pose a substantial risk to national security or public safety. Why it matters: The new rules require... BLOG How Washington State Just Changed the Consumer Health Data Privacy Game 2023 is proving to be an interesting legislative year in the United States, as several individual states take on new legislation aimed at protecting consumer data. California, of course, was the first and has been joined by Virginia, Connecticut,... Button Button Our comprehensive approach to Data Privacy Protiviti applies a holistic framework that addresses the fundamental aspects of data privacy Data privacy regulations are in flux globally. Even as companies put the finishing touches on extensive preparations to comply with applicable privacy laws, such as the European Union’s GDPR and California’s Consumer Privacy Act, new regulations continue to be introduced in other countries. As legislators pass new laws, they continuously amend those already in effect. Data privacy regulations are not static. The problem and proposed solutions are complex and evolving. One thing is almost certain—anyone aiming to comply with a specific regulation with a target date in mind will be disappointed as those near-term obligations are supplanted by new and different rules over the mid- and long-term. In response to this changing landscape, Protiviti applies a holistic framework that addresses the fundamental aspects of data privacy without being locked into any one specific compliance format. We focus on the most pressing data privacy issues companies face, including: Developing strategies to address global data privacy regulations Compliance with regulatory obligations Addressing resource and skill shortages Operationalising privacy needs Implementing privacy tools and remediation support By working ahead of the law in a comprehensive fashion, Protiviti helps build the foundations of a strong but flexible privacy program that includes understanding principles, educating stakeholders, and developing an applicable governance structure for managing changes. This base enables companies and their stakeholders to look to the uncertain future of privacy regulations with greater confidence. Protiviti applies a holistic framework that addresses the fundamental aspects of data privacy Global Chocolatier Adopts Privacy Technology to Prevent Data Exposure Data privacy and compliance do not only affect the safety of an organisation’s employees and customers, but they can also affect future business as customers increasingly prioritise security. Protiviti helped a global chocolatier transform its privacy programme and be fully compliant in the wake of the COVID-19 pandemic. Read More Map, Manage, and Secure Your Data Data privacy can be difficult to navigate. Protiviti’s privacy experts help you map, manage, and secure your data with our data discovery services. Learn More Tailored, Full-Service Support for Privacy Priorities Today’s consumers demand privacy and control over their data, and organisations need to respond accordingly. Protiviti’s Privacy as a Service experts deliver custom solutions and full-service support for your privacy governance and compliance needs. Learn More Key Data Privacy partners We partner closely with cybersecurity and privacy market leaders , ensuring our clients receive the best solutions to meet their needs. Notably, Protiviti has performed more global implementations than other OneTrust partner s and has well over 175 OneTrust-certified consultants, including more than 10% of the global population of OneTrust Fellows of Privacy Technology spread across Europe, the Americas, and the Asia-Pacific regions. Some of our top partners include: Leadership Sameer Ansari Sameer Ansari is a Managing Director and leader of Protiviti’s Security and Privacy Practice. Sameer brings more than 20 years of experience developing and delivering complex privacy solutions to the Financial Industry, and privacy consulting and implementation ... Learn More Philip Greaves Philip is a Managing Director in Protiviti’s London Technology Consulting practice, leading solutions around Technology Strategy and Operations, Technology Risk, Third Party Risk and Privacy. He has over 20 years experience in consulting and previous worked for Andersen ... Learn More Tjakko de Boer Tjakko is Managing Director in the Technology Consulting practice at Protiviti’s Amsterdam office. For over 20 years he assisted clients to leverage Digital solutions, improve performance, and manage operational risk and control. Key focus areas include Information ... Learn More Enrico Ferretti Enrico Ferretti has been with Protiviti since 2007 and is responsible for the Technology Consulting service line and the Telecommunication industry in Italy. Previously, Enrico gained more than ten years of professional experience in Accenture, where he held various ... Learn More What is next for CISOs? CISO Next initiative The CISO Next initiative produces content and events crafted exclusively for CISOs, with CISOs. The resources focus on what CISOs need to succeed. The first step is finding out “What CISO type are you?” Get Involved CISO Next initiative