MATERIALS
Sometimes it is good to confront the staff regularly, even if subconsiously, with data protection triggers.
Around 2005 Barclays developped a large scale data protection awareness program with a marketing bureau under the theme "Think Privacy" with wall-posters, standards, wobblers for the computer monitors, pins, messages in the toilets, ... The whole works.
It was presented on the 2008 ENG seminar on Strategic Data Protection and Privacy. The program got the CEO's buy-in because the CEO had to sign off under personal liability that Barclays was data protection compliant. For there on they could create, implement, support and control an action plan broken down in manageable business segments.
Barclays put a lot of money in that awareness campaign. To recover some of that investment, they looked for others to re-use the materials against a fee. And so the think privacy community was born. If you join, you can re-use the efforts.
But often the program doesn't have to be that heavy. The same can be implemented in smaller, lighter campaign, as long as they are fit for the organisation. It can even be wrong if you over-do it.
And by the way, all that effort, still is no guarantee. Barclays had some individual cases published: e.g. of an employee accessing customer data without a need to know in 2012 and in 2013. In February 2014 however Barclays was confronted with a(nother) big data breach which was reported on in quite some media (e.g. the Daily Mail, Reuters, the Guardian). But they can argue that they have made data protection awareness a priority in their organisation.
REPEATED SERIES INTRO
Raising awareness
amongst your company's staff is key as the human factor is quite often
cited as the weakest link in data protection and security "in the
field". Raising awareness also is not a one-off thing. You have to keep
hitting the same nail. Preferably though, you try out different angles
every time again, as information overload and boredom settle in quite
rapidly. So let me periodically and in no particular order share some
awareness raising materials. Let's aim for once per week and we'll see
where we can get.
No comments:
Post a Comment