The Situation

The customer did not have an adequate, user-friendly and modern recordkeeping system for staff to use increasing the risk of breaching the Public Records Act, Freedom of Information Act and the General Data Protection Regulation. They also had no way to monitor or report on information stored across multiple solutions and disparate ways of working across the organisation. They had been subject to a number of investigations by the ICO and given their current recordkeeping practices it was deemed only a matter of time before they were fined and / or suffered reputational damage.

The Task

The objective was to ensure the customer meets its information compliance obligations by moving employees to a new system of record with extensive compliance monitoring and reporting capabilities (Microsoft 365 SharePoint and Compliance Centre). Leading with business change and adoption strategy, plans and activities to realise the benefits of the new ways of working.

 

The Action / Approach

I managed the project from the start point of building the Business Case with a value of £1 Million and achieving sign-off. Facilitating the Request for Proposal phase to select an appropriate partner with the technical and business change skills required. Running the project with a focus on the business change element and managing the team of consultants and internals. Acted as a subject matter expert for the tools implemented.

The Result

  • Supported the business to manage their data privacy obligations, (including policies, procedures and guidance)
  • Implemented the records and retention solution and associated business change to ensure Personal data is retained for the right amount of time
  • Provided the tools to provide a clear view of data held and able to efficiently respond to Data Subject Requests
  • Organisation educated to the appropriate level in the understanding and implementation of data privacy
  • Able to monitor and assess regularly and in a timely manner business compliance with data privacy
  • Maintained a balance between compliance / privacy and commercial demands to use data

Relevant Business Perspectives

Relevant Industries

Practice