Data Privacy Governance for Multinational Organizations: A Challenge

With an increased global digital footprint, meeting regulatory requirements and customer expectations for data privacy has become the new normal in today’s world. On one hand, for the purpose of giving more control to citizens over their own data, countries across the globe are either making their data protection regulations more stringent or creating new regulations. On the other hand, organizations have also realized the importance of ensuring privacy of customers’ data – not just for compliance with data privacy regulations, but also to enhance customers’ trust and gain competitive edge.
With operations widely spread across geographies, it is often becoming a challenge for multinational organizations to meet data privacy requirements. Some underlying reasons for this include:
In parallel, organizations have started adopting cloud and agile cultures increasingly for flexible and high-quality delivery of customer-driven innovations. However, not all data can be quickly or easily moved to cloud. Therefore, most enterprises will need to simultaneously manage data privacy on-premise, in the cloud, and in hybrid (on-premise + cloud) architectures.
This blog post highlights some key aspects of data privacy management that organizations should adopt for such scenarios.
Enterprise data glossary: Be it business metadata or technical metadata, an organization should curate a digitized and centralized repository of metadata for consistent, secure, and efficient governance across data stores residing on-premise or in the cloud.
Sensitive data attribute discovery: Implement an automated solution to identify sensitive data in accordance to the applicable data protection regulations and map the same with relevant data protection policy. The solution should have built-in capabilities to easily reconfigure these policies in case of any change to the data privacy regulations or environment.
Policy-based data anonymization: Define data privacy policy for each geography in line with pertinent data protection regulations and digitize the policy for automated execution and monitoring.
Centralized monitoring with localized execution: Leverage an approach of centralized monitoring of the policy with localized policy processing of sensitive data, to address data privacy requirements pertaining to specific geography and data residency concerns. Cloud providers that enable hosting in multiple countries with secure channel for communication between on-premise and cloud data centers are a good fit in such scenario. In such a case, the data privacy solution should also have a capability to provision privacy-safe data by de-identifying sensitive data residing in on-premise, cloud, or hybrid architectures.
Role-based data access: In scenarios where access to the sensitive information is required for some specific business operations or function, organizations should ensure that access to such information is available only to authorized persons and managed via role-based methods.


