DATA PROTECTION AND PRIVACY

From business-critical data to personal information, data breaches & compliance gaps present financial and legal risks that threaten brand and future business viability across all industries.

Although differing in scope and context, regulations such as GDPR, CCPA, the SHIELD Act, PCI, HIPAA, SOX, Gramm-Leach Bliley and more share many concepts and principles from data protection & privacy best practices that can be leveraged across regulations if implemented strategically.

PCG has been providing data privacy and protection services for over 20 years and brings a wealth of experience and insights to the table.

WHAT IS DATA PROTECTION AND PRIVACY?

CONSULTING • EXPERTISE • SOLUTIONS • COMPLIANCE

Data protection is about securing data through a variety of means to ensure it stays with those who are explicitly authorized to have it, while data privacy deals with the transparency of how data is used and defines who has access to it. Due to an everchanging environment of innovative technologies and regulatory requirements, data protection & privacy is a matter of maturity for every organization; there is no ‘finish-line.’

Focusing on protection and privacy for your company’s data must be a top a priority for every business and technology leader. Companies today are more vulnerable than ever. Not just from malicious actors and their often-sophisticated technologies, but also from incidental breaches perpetrated by employees – often completely by accident! Data breaches and compliance issues can cost companies millions from fines and other penalties, not including potential negative impacts to brand recognition and future business viability. 

There is no ‘silver bullet’ to data protection & privacy, but the companies that do it best understand the importance of following a risk-based plan for continuous improvement and maturity to balance their risk against technical, business & organizational demands. In many cases regulatory requirements apply, but where they don’t, leading practices with regard to the critical components of Data Protection & Privacy serve to differentiate the mature data protectors from the immature.

HOW CAN PROJECT CONSULTING GROUP HELP?

©               Project Consulting Group // All rights reserved 

Call Us Now

PCG’s services help companies assess, plan for, and improve their data privacy and protection maturity in line with, or above, various compliance standards and other leading practices. PCG’s component centered strategy along with extensive regulatory experience uniquely positions us to benefit companies of any size and complexity. Our service offerings range from assessments and analysis to full program support and implementation. We offer solution-based, project-based, deliverable-based, outsourced, and tailored service offerings.

The unique PCG service model not only provides our clients with specific domain expertise, but also value-added benefits such as extensive program and project management experience, thought leadership mindsets, technology agnostic viewpoints, pareto principle (80/20) approaches, risk-based prioritization concepts, return on investment consideration, uncompromising transparency, cross industry perspectives, research (Gartner) alliances, and 20-years of driving organizational change. 

We packaged some of the more common service offerings below, although PCG will provide a tailored service to meet your specific business needs.  These tailored offerings may cover one or more of the data protection and privacy components. If your need is related to data protection and privacy, we have you covered.  
  

GET DIRECTIONS
  • Inform & Advise

    Coach the organization and the employees who carry out personal information processing of their GDPR obligations.

  • Monitor Compliance

    Track compliance gaps and manage associated risks. Prioritize remediation activities including awareness campaigns, training, and implementations.

  • Oversee DPIAs

    Provide advice where requested regarding data protection impact assessments and monitor performance.

  • Regulator Engagement

    Act as the point of contact for the supervisory authority as needed.

510 N 1st Ave
Minneapolis, MN 55403

Keep scrolling to learn more about Data Protection & Privacy

800-731-7153

From business-critical data to personal information, data breaches & compliance gaps present financial and legal risks that threaten brand and future business viability across all industries.

PCG has been providing data privacy and protection services for over 20 years and brings a wealth of experience and insights to the table.

PCG’s services help companies assess, plan for, and improve their data privacy and protection maturity in line with, or above, various compliance standards and other leading practices. PCG’s component centered strategy along with extensive regulatory experience uniquely positions us to benefit companies of any size and complexity. Our service offerings range from assessments and analysis to full program support and implementation. We offer solution-based, project-based, deliverable-based, outsourced, and tailored service offerings.

The unique PCG service model not only provides our clients with specific domain expertise, but also value-added benefits such as extensive program and project management experience, thought leadership mindsets, technology agnostic viewpoints, pareto principle (80/20) approaches, risk-based prioritization concepts, return on investment consideration, uncompromising transparency, cross industry perspectives, research (Gartner) alliances, and 20-years of driving organizational change.

We packaged some of the more common service offerings below, although PCG will provide a tailored service to meet your specific business needs.  These tailored offerings may cover one or more of the data protection and privacy components. If your need is related to data protection and privacy, we have you covered.  

DATA PROTECTION AND PRIVACY

The global threat environment has intensified resulting in business continuity, disaster recovery, crisis management, and emergency response becoming an area of focus for board of directors, executive leaders, clients, customers, and regulators.  This increased focus has resulted in greater maturity and heightened expectations around response, recovery, and communication capabilities.

Business continuity management identifies these potential threats and impacts to your business, creates the organizational resilience and recovery capabilities for an appropriate level of response, and safeguards the interests of your customers, employees, reputation, and value.   Potential threats include items such as natural disasters, technological failures, data breaches, human error, fire, terrorism, lawsuits, misconduct, acts of violence, labor action, or drop in share price.

There are multiple components encompassing a robust business continuity program, in addition to several ancillary items such as event/incident management, disaster recovery, crisis management, and emergency response. The terminology used within industries, by regulations, and across vendors is inconsistent at best, so we recommend focusing on the components rather than debating the nomenclature.  Below are the components.

WHAT IS DPP?HOW CAN PCG HELP?

Contact us today to receive your complimentary discovery session 


YOUR COMPLIMENTARY DISCOVERY SESSION INCLUDES:

Dedicated time with a PCG Data Protection and Privacy Expert

A review of your Data Protection and Privacy current-state and desired future-state

A roadmap outlining your goals and strategies

REQUEST MY DISCOVERY SESSION

OR

Call Now: 800-731-7153

CALL NOW: 800-731-7153
800-731-7153

EXPERTISE • CONSULTING SERVICES • SOLUTIONS

CEO of a Global Manufacturing Company

PCG has done an excellent job at leading our multi-year project.

Manager at a Government Agency

PCG is very professional and has a broad range of abilities. They took great care to identify the help needed.

PCG did a tremendous job with our project. They built a strong rapport with the business owners, which helped create trust and confidence.

Manager at a Multinational Bank and Financial Services Company

- VP of an International Agricultural and Food Company

I wanted to reach out to PCG and say thank you for a job well done!

VP of Fortune 500 Bank

I can’t express how much I appreciate the leadership and guidance PCG provided to our program.

PCG was excellent in defining and implementing the framework that has helped provide significantly improved governance and transparency.

Director of Mid-Market National Retailer

Manager at a Fortune 500 Financial Services Company

I want to make sure to recognize the great work PCG did on the project, you have certainly surpassed my expectations.

Director at a National Insurance Corporation

You have no idea how nice it is to hand off something like this to someone you know will stay on top of it and communicate progress. Great job.

PCG has been a great partner to us and if we need consulting help, we reach out. Thanks!

National Health Insurance Company

Accountability

The establishment of clear Data Protection & Privacy leadership within an organization; a Data Protection Officer or others that create and pursue a data protection & privacy roadmap, and proactively articulate the organization’s stature regarding data protection & privacy. An effective governance framework helps organizations prepare for the developing patchwork of regulations and oversee the integrity, availability and security of their data.

Data & Process Management

Policies establish principles such as stewardship, master & meta data practices, protection standards, and quality controls, throughout a data element’s lifecycle. Data and process inventories help manage what information is being accessed, and where and with whom it resides. In combination, effective policies and inventories help companies meet compliance standards and maintain a holistic view of its data landscape.

Third Party Management

Relationships with any third parties that process data on your company’s behalf should be governed by contracts that require them to maintain appropriate technical & organizational measures for protecting and ensuring the privacy of that data. Additionally, companies should employ a risk-based, prioritized approach to validate audit their third parties on an ongoing basis that their third parties to ensure they are meeting the data protection & privacy obligations required of them.

Data Transfers

Many regulations specify enhanced security measures for international data transfers, but it is our view that companies should apply a similarly high level of care in the form of technical and organizational measures to domestic transfers and third-party transfers as well. Common solutions include secure transfer tools, encryption, tokenization, data masking, minimization, pseudonymization, anonymization, and more.

Risk Management

Leading companies understand that following a data protection & privacy roadmap is really a series of ongoing exercises in Risk Management, with the completion of projects and tasks prioritized by the amount of risk they pose to the company if left unresolved. All information related risks should be managed accordingly to ensure the company’s data is adequately protected.

Security

Recognized security frameworks such as NIST, CIS/SANS 20 and ISO 27001 provide accredited assurance that companies have appropriate technical and organizational security measures for safeguarding their data and other IT related assets. Security Policies, Incident Response Plans, Acceptable Use Policies and more, work in concert to weave a security posture that incorporates leading practices to safeguard your organization.

Regulatory Engagement

Regulations and restrictions dictating what companies may do with data are spreading around the globe. Nearly every data category – from health information, to credit card data, to financial data, to personal information and more – is governed by compliance requirements. Companies must understand those requirements and how to interact with the different governing entities.

Data Subjects, Privacy Policy, Purpose

Regulations such as GDPR, CCPA, Gramm-Leach-Bliley and others restore the balance of power between companies and data subjects by establishing rights for data subjects. Despite nuanced differences from regulation to regulation, companies can implement leading practices such as transparent and detailed privacy policies, and easy-to-use mechanisms available for data subjects to interact with the company.

Data Breach Management

Data breach management plans provide a repeatable framework for assessing breach impact, remediating issues, and notifying impacted parties and regulatory bodies. Leading practices indicate that organizations should implement and test their plans to verify they are able to evaluate breach exposure, establish remediation plans and notify parties within 72 hours of identifying the breach.

Provide Top Talent

PCG employs subject matter experts and leaders across all areas of Data Protection & Privacy.

Deliver Tailored Approaches

Every organization has unique challenges and demands that require flexible service offerings.

PCG solutions balance people, processes and tools to help drive change and stakeholder alignment.

Drive Organizational Change

"PCG is very professional and has a broad range of abilities. They took great care to identify the help needed.

- Manager at a Government Agency

IIBA Premier Sponsor

PMI Corporate Partner

THIRD PARTY AUDIT SOLUTIONS

This service analyses current practices, and the development of a right-fit, risk-based capability to ensure that the client can validate that their vendors or third-parties follow appropriate organizational and technical data protection & privacy measures. It’s commonly used by organizations with informal, burgeoning or maturing vendor management programs that lack data protection and privacy subject matter expertise.

CAPABILITIES AND SOLUTIONS

GAP ASSESSMENT

This service analyzes the current-state of data protection and privacy components, alongside required or best practices, to identify gaps and actionable recommendations. We offer two versions of the gap analysis; an accelerated approach for scoping or reporting purposes, and a deep-dive approach for detailed planning on larger initiatives.

ASSESSMENTS AND AUDITS

MATURITY ASSESSMENT

This service assesses the current-state of the data protection and privacy components and processes to determine the degree of maturity. The results of the assessment are mapped to a capability maturity model that also includes the findings, level designation, and roadmap to deliver upon stakeholder expectations.

CONTROL EVALUATION

This service evaluates the current-state of data protection and privacy control effectiveness with the goal of measuring or improving upon the desired result. We offer two forms of this evaluation; an "assessment of controls" through qualitative evaluation or an "audit of controls" through quantitative and statistically relevant sampling.

REGULATORY OR CERTIFICATION

This service provides an assessment focused on specific regulatory requirements such as GDPR, CCPA, PCI, or certification mechanisms such as ISO 27001, NIST, and SANS20. This assessment helps identify non-conformities and is designed for companies needing to undergo an audit or certification process.

MANAGED SERVICES

DATA PROTECTION AND PRIVACY LEADERSHIP SERVICES

Retainer based access to a data protection and privacy subject matter expert with cross-industry experience. This resource may partner with an organization’s data protection and privacy leadership or governance team to help prioritize work items, offer guidance on leading practices, and interpret regulatory requirements when applicable on a regular basis. 

IMPLEMENTATION

This service provides an opportunity to outsource the implementation of solutions or remediation of data protection and privacy gaps.  PCG’s team includes the required resources such as strategic advisors (senior practitioners), project oversight resources (program/project management), supporting team members (analysts, subject matter experts) and applicable third-party vendors. 

MANAGEMENT CONSULTANTS

PCG employs program and project managers that will help drive your data protection and privacy project to completion.  Our consultants bring a deep understanding of project management and years of experience leading projects. Their strategic and tactical knowledge allows them to seamlessly oversee the scope, schedule, budget, risk and quality.

STAFF AUGMENTATION

COMPONENTSTESTIMONIALS

Project Consulting Group

SERVICES

CCPA

Other Services

Contact Project Consulting Group

OPERATIONS

This service provides companies the ability to outsource operational components of data protection and privacy with the goal of attaining higher or equal value at a lower overall support cost.   Ancillary benefits include improving the core business focus, freeing up internal resources, and gaining access to world-class resources and capabilities.     

CORE TEAM MEMBERS

PCG employs a staff of data protection and privacy architects, analysts, and subject matter experts that play a key role in overall project success.  This service provides organizations an avenue to tap into these resources to help deliver the project.  Our team members will facilitate the collaboration leading to solutions for your most complex challenges.

Assessments & AuditsCapabilities & SolutionsManaged ServicesStaff Augmentation

Click below to learn more about our services:

DATA PROTECTION & PRIVACY COMPONENTS

DELIVERABLE BASED SERVICES

If you desire an individual or set of deliverables, PCG may provide template artifacts or hands-on support in drafting and implementing specific deliverables such as a privacy policy, information security policy, data breach plan (incident response plan) process inventories and more.

OUTSOURCED THIRD PARTY AUDIT PROGRAM

Ongoing outsourced management of the activities associated with validating that third parties have adequate organizational and technical security measures to protect the data with which your company entrusts. This service enables companies to leverage PCG’s experts and capabilities to vet their third parties prior to onboarding and on a regularly recurring basis as defined by the program. This service is commonly used by organizations that utilize many vendors and those that do not have established third party management programs.

EU GDPR

Data protection is about securing data through a variety of means to ensure it stays with those who are explicitly authorized to have it, while data privacy deals with the transparency of how data is used and defines who has access to it. Due to an everchanging environment of innovative technologies and regulatory requirements, data protection & privacy is a matter of maturity for every organization; there is no ‘finish-line.’

Focusing on protection and privacy for your company’s data must be a top a priority for every business and technology leader. Companies today are more vulnerable than ever. Not just from malicious actors and their often-sophisticated technologies, but also from incidental breaches perpetrated by employees – often completely by accident! Data breaches and compliance issues can cost companies millions from fines and other penalties, not including potential negative impacts to brand recognition and future business viability. 

There is no ‘silver bullet’ to data protection & privacy, but the companies that do it best understand the importance of following a risk-based plan for continuous improvement and maturity to balance their risk against technical, business & organizational demands. In many cases regulatory requirements apply, but where they don’t, leading practices with regard to the critical components of Data Protection & Privacy serve to differentiate the mature data protectors from the immature.

800-731-7103        www.pcg-usa.com