Sei sulla pagina 1di 29

Let

the experience begin!

Elevate Your Customer’s


Experience with GDPR
Chris Hubbard | Pre-Sales Manager
François Ruiter | Product Marketing Manager I October 5, 2017 I Inspire Days, Berlin

© Quadient Classification: CONFIDENTIAL


General Data
Protection
Regulation

2017 - © Quadient Classification: CONFIDENTIAL


The New Privacy Legislation
6 Areas of Consideration

a consumer has the right to


an adequate level of know which personal data has
security shall be provided been stored
a consumer has the right to
a consumer has the right to maintain his or her stored
be forgotten personal data

personal data is only a consumer has the right to


allowed to be stored for a transfer his or her personal data
specified period of time to another automated data
processing system

2017 - © Quadient Classification: CONFIDENTIAL


Big Picture Impact

Risks Opportunity
■ Proving that you have appropriate ■ Establish customer trust in a digital
and adequate controls world
■ Reputational damage of ■ Standardizing, simplifying and
noncompliance automating processes to ensure on-
going compliance
■ High cost of noncompliance
■ Successful compliance with new
regulations and good standing

2017 - © Quadient Classification: CONFIDENTIAL


Status of Business Preparations for GDPR

GDPR Research in the US and UK, June 2017, online IT community Spiceworks

2017 - © Quadient Classification: CONFIDENTIAL


GDPR Consumer
Data Privacy
Rights

2017 - © Quadient Classification: CONFIDENTIAL


GDPR Chapter 3 – Rights of ‘Data Subject’
Articles
Article 12: Information should be easy accessible in clear and plain language
Article 13: Personal data are collected from the data subject.
Article 14: Personal data are collected from the other sources.
Article 15: Right of access by the data subject. *30 day response required
Article 16: Right to rectification.
Article 17: Right to erasure ('right to be forgotten').
Article 18: Right to restriction of processing.
Article 19: Pro-actively notification of changes.
Article 20: Right to data portability.
Article 21: Right to object.
Article 22: Automated individual decision-making

2017 - © Quadient Classification: CONFIDENTIAL


A Simple Request?

Identify Compile Notification


Request Verification
Find Action Distribution

2017 - © Quadient Classification: CONFIDENTIAL


Implementation Questions & Concerns
It takes time and money to respond to SARs, particularly without a full view of all their data.

Policies and Procedures Avoided Overburdening the Identify IT Investment


• Manual or automated processes? Organisation • What data do we have on
• How will GDPR events be managed • How much effort and resource are individuals and where is it stored?
and tracked? going to be required to deal with • Can change events be automated?
• What procedures are in place to GDPR events ? • What should we keep and for how
avoid phishing ? long?

Clear Customer Consolidate and Secure Data


Communication • Do we need to store multiple copy
• Will communication to be of the same data?
structured and standardised? • What data should be secured or
• Can it be delivered across multi- anonymised?
channels?

2017 - © Quadient Classification: CONFIDENTIAL


Top Concerns about GDPR

GDPR Research in the US and UK, June 2017, online IT community Spiceworks

2017 - © Quadient Classification: CONFIDENTIAL


Privacy
Compliance
by Quadient

2017 - © Quadient Classification: CONFIDENTIAL


First, establish the foundation to…

2017 - © Quadient Classification: CONFIDENTIAL


Data Dynamics
Data Management is the Prerequisite for GDPR

Know Your Customer

Ensure Compliance

Enhance

Consolidate

Cleanse

Profile

Your
Data

2017 - © Quadient Classification: CONFIDENTIAL


Demo…

2017 - © Quadient Classification: CONFIDENTIAL


Know Your Customer
One record in DataHub links all source system records.

2017 - © Quadient Classification: CONFIDENTIAL


Then, focus on your customer’s experience.
A Customer Makes a Request
Multi channel web, email, call centre.

2017 - © Quadient Classification: CONFIDENTIAL


The Request is Acknowledged

2017 - © Quadient Classification: CONFIDENTIAL


A Ticket is Created

2017 - © Quadient Classification: CONFIDENTIAL


The Customer Data is Identified

2017 - © Quadient Classification: CONFIDENTIAL


The Response Template is Populated

GDPR view in DataHub

12 Frank Erikson Acacia Avenue 17 OX4 7GY Oxford frank@gmail.com

System A 113 System B 76 System X P34

2017 - © Quadient Classification: CONFIDENTIAL


Company details
Categories of personal data
Unique reference

Dear xxx, Personal data held concerning :Bank account 12345, Consent given,
Lorem ipsum dolor sit amet, consectetur adipiscing elit,
sed do eiusmod tempor incididunt ut labore et dolore * Automated decision-making January 19th 2017
magna aliqua. Ut enim ad minim veniam, quis nostrud
How to request
exercitation ullamco laboris nisi ut * Marketing of banking product January 19th 2017

Aliquip ex earectification and deletion


commodo consequat. Duis aute irure dolor Details held
in reprehenderit in voluptate velit esse cillum dolore eu Data last edited on : 19th March 2016, based on
fugiat nulla pariatur. Excepteur sint information from “xyz”
Consent information he
Occaecat cupidatat non proident, sunt in culpa qui officia
deserunt mollit anim id est laborum Personal data held concerning : Home insurance for subject
None held
Your rights under the GDPR regulation are
Personal data collected when
• Right to xxxx
Data Controller details
• Right to yyy Personal data held concerning : Car insurance
and from whom
Data Controller 01552 1244242 dpo@company.com None held

Aliquip ex ea commodo consequat. Duis aute irure dolor Personal data held concerning : Life Insurance
in reprehenderit in voluptate velit esse cillum dolore eu
fugiat nulla pariatur. Excepteur sint None held
How to complain

2017 - © Quadient Classification: CONFIDENTIAL


Approval Processes are
Triggered

Customer Compliance Analyst Data Privacy Officer

2017 - © Quadient Classification: CONFIDENTIAL


Communication is Sent...

2017 - © Quadient Classification: CONFIDENTIAL


Via the Customer’s Preferred Channel

2017 - © Quadient Classification: CONFIDENTIAL


The key to establish customer trust

■ Our GDPR solution offers


• Clarity as to where and what personal data exists by consolidating disparate,
potentially redundant systems into a Single Customer View
• Standardized, simplified and automated processes to support consumer
data privacy rights and requests
• Approval processes to ensure the right stakeholders are involved in the
process to ensure compliance / eliminate risk
• Tracking and insight into consumer data requests which can be used for
reporting to senior management and regulators
• Compliant, omni-channel communication and interaction with your
customers

2017 - © Quadient Classification: CONFIDENTIAL


Your Questions

2017 - © Quadient Classification: CONFIDENTIAL


Thank you

Chris Hubbard, c.hubbard@quadient.com


François Ruiter, f.ruiter@quadient.com

2017 - © Quadient Classification: CONFIDENTIAL


Multi-Channel
Subject Access Request Document Template Risk Manager Approval Communication

Communication
Approval
Creation
Subject
Access
Request

Precision Matched Audit History


to create a GDPR view

Source Systems 1 - n

Potrebbero piacerti anche