With the EU General Data Protection Regulation (GDPR) in effect as of May 25th, 2018, KnowledgeWorks Global Ltd. implemented a GDPR-readiness program and has completed a priorities risk assessment with the help of TrustArc, a privacy consulting firm. KGL has also hired security and compliance firm ControlScan to help meet industry ISO standards and implement security controls relative to data security.
As a supplier and data processor, KGL takes data privacy and information security very seriously across the organization. As such, we have a dedicated internal compliance team working closely with our external consultants to assess security policies and procedures that improve our ability to safeguard personal data being collected, processed, or stored across any of the KGL sites. Even though KGL does not generally collect or store sensitive personal information, we treat all customer data as sensitive. We have organized our GDPR compliance efforts in the following areas:
- Business Process Review
- System/Workflow Impact Assessment
- Governance, Risk, and Compliance
Business Process Review
We have assessed many of our internal processes and are continuously working on improving and updating the following areas:
- Incident response and breach notification policy
- Privacy Notice (Articles 12, 13, and 14)
- Cookie Policies
- Developing Data Protection Agreements (DPAs) for Sub-Processors and Vendors
- Implementing records of consent from data subjects (Articles 7 and 8)
- Developing processes for protecting personal data, including privacy and information security policies and procedures
System/Workflow Impact Assessment
KGL has completed various privacy impact assessments (PIAs) to help identify potential areas of risk. The compliance team is currently remediating and implementing appropriate security controls that align with industry standards such as ISO 27001 and help improve our overall security posture.
Governance, Risk, and Compliance
KGL, and more broadly the CJK Group, know that Data Privacy and Information Security responsibilities go well beyond the scope of GDPR. In order to help drive this continuous effort, the CJK Group has established a Data Privacy Office (DPO) that will be responsible for all GRC (Governance, Risk Management, and Compliance) efforts pertaining to organizational policies and procedures that are supported by our Information Security Management System.
Any GDPR related questions can be submitted to KGL’s Compliance Team at info@kwglobal.com.
Latest Insights
Kevin Lomangino discusses the importance of conducting a strategic assessment before renewing a contract or issuing a Request for Proposal (RFP). He highlights how this assessment can prepare your program for growth and greater impact in the next contract term and beyond.
India is rapidly emerging as a global research hub, driven by policy reforms and strong public-private collaboration meaning that beyond ONOS, there will be even more opportunities for publishers to explore. ONOS is set to provide 6,400+ institutions and millions of students and researchers in India with access to 13,000+ journals from 30 publishers.
Since our last Essential AI Reading post back in October 2023, a number of exciting new titles have been released, offering all kinds of fresh perspectives on this rapidly changing landscape.