<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>article28 &#8211; B|KM &#8211; B2B SaaS</title>
	<atom:link href="https://bkmsoftware.com/tag/article28/feed" rel="self" type="application/rss+xml" />
	<link>https://bkmsoftware.com</link>
	<description></description>
	<lastBuildDate>Mon, 01 Jul 2019 16:15:17 +0000</lastBuildDate>
	<language>es</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://bkmsoftware.com/wp-content/uploads/2021/02/cropped-cropped-logo2020-black-32x32.png</url>
	<title>article28 &#8211; B|KM &#8211; B2B SaaS</title>
	<link>https://bkmsoftware.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>GDPR integration in contracts management</title>
		<link>https://bkmsoftware.com/gdpr-integration-in-contracts-management-opportunity-for-a-better-sensitive-data-management-and-compliance</link>
		
		<dc:creator><![CDATA[Lorenz Baermann]]></dc:creator>
		<pubDate>Mon, 01 Jul 2019 16:15:17 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[article28]]></category>
		<category><![CDATA[clm]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[gdprarticle28]]></category>
		<guid isPermaLink="false">https://info.bkmsaas.net/gen/gdpr-integration-in-contracts-management-opportunity-for-a-better-sensitive-data-management-and-compliance/</guid>

					<description><![CDATA[Contract Management tools and CLM (Contract Lifecycle Management) practices offer the opportunity to integrate managed processes from the very beginning of the data stream: the contracts. Article 28 of GDPR provides some guidelines that we develop in this paper. ]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading">An opportunity for a better sensitive data management and compliance</h2>



<p>Contract Management tools and CLM (Contract Lifecycle Management) practices offer the opportunity to integrate managed processes from the very beginning of the data stream: the contracts. Article 28 of GDPR provides some guidelines that we develop in this paper. </p>



<p><strong>Contracts
and GDPR</strong></p>



<p>Organizations
can almost easily identify the source of sensitive data in their contracts,
either because contracts <em>de facto</em> represent the data collecting events (B2C
and B2B) or because data treatment or manipulation is the <em>subject</em> of
contracts themselves (B2B). This latter is the case of third parties involved in
data manipulation or data treatment, the so-called “processors” by article 28
of the GDPR. Relationship with these parties is regulated by contracts. </p>



<p><strong>Article
28 </strong></p>



<p>EU
general data protection regulation 2016/679 (GDPR), in effect since 25 May 2018,
states in Article 28 that </p>



<p>“…<em>the controller shall use only processors providing <strong>sufficient
guarantees</strong> to implement appropriate technical and organizational measures
in such a manner that processing will meet the requirements of this Regulation
and ensure the protection of the rights of the data subject.</em>”&nbsp; </p>



<p>Wording
in bold characters in the above quoted text is not our personal typographic
choice. The impact of this article has not been overviewed by Brussels yet but
the concept is crystal clear: processor’s responsibility goes beyond his own organization;
it extends to <em>the whole</em> business network it relies on. This also affects
foreign companies and organizations that treat EU citizen’s data.</p>



<p>When
dealing with sensitive data the governance of relations with <em>processors</em>
by contracts is not a common-sense or best practice anymore but an <em>obligation</em>
as dictates Article 28, paragraph nr. 3:</p>



<p><em>“Processing by a processor shall be governed by a
contract or other legal act under Union or Member State law, that is binding on
the processor with regard to the controller […]”</em></p>



<p>From
a practical point of view, organizations should develop governance procedures
for managing the sensitive data chain and all relations with processors
assuring their compliance. This is where CLM can help.</p>



<p><strong>How
can CLM help?</strong></p>



<p>CLM’s
basic principle is taking <em>full control</em> of the contract lifecycle and all
contract related aspects impacting organizational issues. This means that by using
CLM practices companies have the ability to control and manage direct relations
between business processes and contracts, considering the latter as sources. </p>



<p>It
is a fact that Legal Audit is a fast and precise operation when CLM tools are
adopted. The same cannot be said about traditional or manual legal management:
in one of our customers the Legal Audit process was reduced, after adopting
CLM, from 2 or 3 days to 30 minutes.</p>



<p>All
the above can be translated into the following general actions:</p>



<ol class="wp-block-list"><li>Identifying
specific contracts and contract categories that represent sources of sensitive
data.</li><li>Identifying
IT and service contracts with third-parties and contractors related to a).</li><li>Collecting
contracts in b) for auditing the GDPR required guarantees and compliancy of the
involved parties for the whole data stream.</li><li>Integrating
CLM with Business Process Management and its link to the GDPR process
management: data treatment audit items should be <em>identified</em> with their
legal sources in order to guarantee their management and enhance all following
process maintenance.</li><li>Evaluating
the opportunity of sharing the same tools as common language between controller
and processor.</li><li>Managing GDPR processes (audit and maintenance) using the
legal perspective as a starting point.</li></ol>



<p><strong>Conclusions</strong></p>



<p>Organizations need support regarding EU sensitive data manipulation compliance; complex activities must be managed involving IT and service contracts review. Contract Lifecycle Management tools help organizations in the tedious task of identifying and collecting their processors for a correct GDPR risk management.</p>



<hr class="wp-block-separator"/>



<p>This article is also available in LinkedIn, in pdf format, <a href="https://www.linkedin.com/feed/update/urn:li:activity:6551485925355065344" target="_blank" rel="noreferrer noopener" aria-label="here (opens in a new tab)">here</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
