<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gdpr &#8211; B|KM &#8211; B2B SaaS</title>
	<atom:link href="https://bkmsoftware.com/tag/gdpr/feed" rel="self" type="application/rss+xml" />
	<link>https://bkmsoftware.com</link>
	<description></description>
	<lastBuildDate>Mon, 01 Mar 2021 13:34:48 +0000</lastBuildDate>
	<language>es</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://bkmsoftware.com/wp-content/uploads/2021/02/cropped-cropped-logo2020-black-32x32.png</url>
	<title>gdpr &#8211; B|KM &#8211; B2B SaaS</title>
	<link>https://bkmsoftware.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>BPM is better</title>
		<link>https://bkmsoftware.com/bpmgdpr</link>
		
		<dc:creator><![CDATA[Lorenz Baermann]]></dc:creator>
		<pubDate>Mon, 01 Mar 2021 13:34:48 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[bpm]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[tools]]></category>
		<guid isPermaLink="false">https://info.bkmsaas.net/?p=238</guid>

					<description><![CDATA[Why Business Process Management is a better choice than only process mapping in GDPR tools Companies and organizations are experiencing the first stage of a new digital support: GDPR management tools. We analyzed some of them. The problem In some cases the approach of the&#8230;]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading">Why Business Process Management is a better choice than only process mapping in GDPR tools</h2>



<p>Companies and organizations are experiencing the first stage of a new digital support: GDPR management tools. We analyzed some of them.</p>



<p></p>



<p><strong>The problem</strong></p>



<p>In some cases the approach of the solution is technological -systems designed as if they were independent or of static nature- while in other cases it’s functional, thus technical in compliance matters, still specific.</p>



<p>We classify both approaches as mainly marketing-oriented; not in order to criticize the quality of these tools as such but the fact that the solutions primarily are momentum-driven commercial opportunities for a sudden demand, which market is still not well versed on the subject. <em>This practice raises issues, indeed</em>.</p>



<p>Talking with GDPR experts it emerges that some entrepreneurs and executives have taken a vision which limits GDPR compliance to – a bureaucratic – document management or, even worse, they seem a one-shot maintenance-free operation. All despite the many and repeated warnings and risks of running into huge administrative fines.</p>



<p>Moreover, we have been confided that companies apparently prefer a non-matching real-world business processes above the presenting of&nbsp; ‘official processes’ and carry on with their usual ones. The bottom line: the risk and the purpose of the compliance audit is dispelled although time and money is expended, and at a high risk cost at the same time.</p>



<p><strong>Back to the past</strong></p>



<p>We note a remarkable parallel to the 90’s when ISO quality certification was fashionable. It was not uncommon to find entrepreneurs chasing contingently after a series of certificates, <em>however without any serious intention to change their company culture</em>.</p>



<p>We have worked with quite a few of them at that time and, unfortunately but not by chance, none of them had enlighten their future after such choices. (None of them exist anymore in the market, but this is just a personal account.)</p>



<p>Three decades later quality at large -finally- seems widespread in many business environments, and process mapping &amp; re-engineering is nothing new anymore. The resulting benefits are acknowledged as part of our business culture.</p>



<p><strong>An innovative approach – a golden opportunity</strong></p>



<p>Underestimating the interventions required to meet the GDPR or not taking advantage of all actions needed during this process, may lead companies to choose wrong tools that require serious compliancy efforts. Often this road also leads to the impossibility to become connected with other fundamental areas of competence such as Legal and Operations. Given all of the above, we raise a crucial question:</p>



<p><strong><em>Why should companies and organizations re-map their processes only for GDPR purposes?</em></strong><strong> <em>Why do GDPR tools not start from managed processes? </em></strong></p>



<p>Exchange standards are available, such as IDEFx, FFBD or BPMN 2.0 for modeling or universal standards like XML or Json, just to provide some examples. Then, how common it is actually the adoption of process mapping tools?</p>



<p>This lack of integration of best practices and previous investments leads to a costly attrition.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Il BPM è meglio</title>
		<link>https://bkmsoftware.com/process-mapping-attrition-in-gdpr-tools-or-bpm-opportunity%ef%bb%bf-2</link>
		
		<dc:creator><![CDATA[Lorenz Baermann]]></dc:creator>
		<pubDate>Sun, 14 Feb 2021 15:31:55 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[cumplimiento]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[Process Management]]></category>
		<category><![CDATA[Process Managementcompliance]]></category>
		<guid isPermaLink="false">https://info.bkmsaas.net/gen/process-mapping-attrition-in-gdpr-tools-or-bpm-opportunity%ef%bb%bf-2/</guid>

					<description><![CDATA[Perché il Business Process Management è meglio della sola mappatura ai fini del GDPR Aziende e organizzazioni stanno vivendo la prima fase di un nuovo supporto digitale: gli strumenti di gestione del GDPR. Ne abbiamo analizzati alcuni. Come per tutti i casi precedenti di nuovi&#8230;]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading">Perché il Business Process Management è meglio della sola mappatura ai fini del GDPR</h2>



<p id="tw-target-text">Aziende e organizzazioni stanno vivendo la prima fase di un nuovo supporto digitale: gli strumenti di gestione del GDPR. Ne abbiamo analizzati alcuni. </p>



<p id="tw-target-text">Come per tutti i casi precedenti di nuovi processi di conformità aziendale, oggi c&#8217;è un numero crescente di strumenti sul mercato che affrontano la nuovissima legge europea sulla privacy, il Regolamento generale sulla protezione dei dati, entrato in vigore il 25 maggio 2018. Il nostro principale conclusione:  <em>questi strumenti per la privacy hanno limitazioni di progettazione</em>. </p>



<h3 class="wp-block-heading">Il problema</h3>



<p>In alcuni casi l&#8217;approccio della soluzione è tecnologico -sistemi progettati come se fossero indipendenti o di natura statica- mentre in altri casi è funzionale, quindi tecnico in materia di compliance, ancora specifico.</p>



<p>Classifichiamo entrambi gli approcci come principalmente orientati al marketing; non per criticare la qualità di questi strumenti in quanto tali, ma il fatto che le soluzioni sono principalmente opportunità commerciali guidate dallo slancio per una domanda improvvisa, il cui mercato non è ancora esperto in materia. Questa pratica solleva problemi, anzi.</p>



<p>Parlando con gli esperti di GDPR emerge che alcuni imprenditori e dirigenti hanno adottato una visione che limita la conformità al GDPR a una gestione &#8211; burocratica &#8211; dei documenti o, peggio ancora, sembrano un&#8217;operazione one-shot che non richiede manutenzione. Il tutto nonostante i tanti e ripetuti avvertimenti e rischi di incorrere in enormi sanzioni amministrative.</p>



<p>Inoltre, ci è stato confidato che le aziende apparentemente preferiscono processi di business del mondo reale non corrispondenti rispetto alla presentazione di &#8220;processi ufficiali&#8221; e continuano con quelli abituali. Conclusione: il rischio e lo scopo dell&#8217;audit di conformità vengono dissipati nonostante si spenda tempo e denaro e allo stesso tempo con un costo di rischio elevato.</p>



<h3 class="wp-block-heading">Ritorno al passato</h3>



<p>Notiamo un notevole parallelo con gli anni &#8217;90, quando la certificazione di qualità ISO era di moda. Non era raro trovare imprenditori che inseguivano in modo contingente una serie di certificati, senza tuttavia alcuna seria intenzione di cambiare la loro cultura aziendale.</p>



<p>Abbiamo lavorato con un bel po &#8216;di loro in quel momento e, purtroppo ma non a caso, nessuno di loro aveva illuminato il proprio futuro dopo tali scelte. (Nessuno di loro esiste più sul mercato, ma questo è solo un account personale.)</p>



<p>Tre decenni dopo, la qualità in generale, infine, sembra diffusa in molti ambienti aziendali e la mappatura e la reingegnerizzazione dei processi non sono più una novità. I vantaggi che ne derivano sono riconosciuti come parte della nostra cultura aziendale.</p>



<h3 class="wp-block-heading">Un approccio innovativo: un&#8217;opportunità</h3>



<p>Sottovalutare gli interventi necessari per soddisfare il GDPR o non sfruttare tutte le azioni necessarie durante questo processo, può portare le aziende a scegliere strumenti sbagliati che richiedono un serio impegno di conformità. Spesso questa strada porta anche all&#8217;impossibilità di collegarsi ad altre aree di competenza fondamentali come Legale e Operativo. Considerato tutto quanto sopra, solleviamo una domanda cruciale:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow"><p><em>Perché le aziende e le organizzazioni dovrebbero mappare i propri processi solo ai fini del GDPR? Perché gli strumenti GDPR non partono dai processi gestiti?</em></p></blockquote>



<p>Sono disponibili standard di scambio, come IDEFx, FFBD o BPMN 2.0 per la modellazione o standard universali come XML o Json, solo per fornire alcuni esempi. Allora, quanto è comune l&#8217;adozione di strumenti di mappatura dei processi?</p>



<p>Questa mancanza di integrazione delle migliori pratiche e degli investimenti precedenti porta a un costoso logoramento.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>GDPR integration in contracts management</title>
		<link>https://bkmsoftware.com/gdpr-integration-in-contracts-management-opportunity-for-a-better-sensitive-data-management-and-compliance</link>
		
		<dc:creator><![CDATA[Lorenz Baermann]]></dc:creator>
		<pubDate>Mon, 01 Jul 2019 16:15:17 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[article28]]></category>
		<category><![CDATA[clm]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[gdprarticle28]]></category>
		<guid isPermaLink="false">https://info.bkmsaas.net/gen/gdpr-integration-in-contracts-management-opportunity-for-a-better-sensitive-data-management-and-compliance/</guid>

					<description><![CDATA[Contract Management tools and CLM (Contract Lifecycle Management) practices offer the opportunity to integrate managed processes from the very beginning of the data stream: the contracts. Article 28 of GDPR provides some guidelines that we develop in this paper. ]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading">An opportunity for a better sensitive data management and compliance</h2>



<p>Contract Management tools and CLM (Contract Lifecycle Management) practices offer the opportunity to integrate managed processes from the very beginning of the data stream: the contracts. Article 28 of GDPR provides some guidelines that we develop in this paper. </p>



<p><strong>Contracts
and GDPR</strong></p>



<p>Organizations
can almost easily identify the source of sensitive data in their contracts,
either because contracts <em>de facto</em> represent the data collecting events (B2C
and B2B) or because data treatment or manipulation is the <em>subject</em> of
contracts themselves (B2B). This latter is the case of third parties involved in
data manipulation or data treatment, the so-called “processors” by article 28
of the GDPR. Relationship with these parties is regulated by contracts. </p>



<p><strong>Article
28 </strong></p>



<p>EU
general data protection regulation 2016/679 (GDPR), in effect since 25 May 2018,
states in Article 28 that </p>



<p>“…<em>the controller shall use only processors providing <strong>sufficient
guarantees</strong> to implement appropriate technical and organizational measures
in such a manner that processing will meet the requirements of this Regulation
and ensure the protection of the rights of the data subject.</em>”&nbsp; </p>



<p>Wording
in bold characters in the above quoted text is not our personal typographic
choice. The impact of this article has not been overviewed by Brussels yet but
the concept is crystal clear: processor’s responsibility goes beyond his own organization;
it extends to <em>the whole</em> business network it relies on. This also affects
foreign companies and organizations that treat EU citizen’s data.</p>



<p>When
dealing with sensitive data the governance of relations with <em>processors</em>
by contracts is not a common-sense or best practice anymore but an <em>obligation</em>
as dictates Article 28, paragraph nr. 3:</p>



<p><em>“Processing by a processor shall be governed by a
contract or other legal act under Union or Member State law, that is binding on
the processor with regard to the controller […]”</em></p>



<p>From
a practical point of view, organizations should develop governance procedures
for managing the sensitive data chain and all relations with processors
assuring their compliance. This is where CLM can help.</p>



<p><strong>How
can CLM help?</strong></p>



<p>CLM’s
basic principle is taking <em>full control</em> of the contract lifecycle and all
contract related aspects impacting organizational issues. This means that by using
CLM practices companies have the ability to control and manage direct relations
between business processes and contracts, considering the latter as sources. </p>



<p>It
is a fact that Legal Audit is a fast and precise operation when CLM tools are
adopted. The same cannot be said about traditional or manual legal management:
in one of our customers the Legal Audit process was reduced, after adopting
CLM, from 2 or 3 days to 30 minutes.</p>



<p>All
the above can be translated into the following general actions:</p>



<ol class="wp-block-list"><li>Identifying
specific contracts and contract categories that represent sources of sensitive
data.</li><li>Identifying
IT and service contracts with third-parties and contractors related to a).</li><li>Collecting
contracts in b) for auditing the GDPR required guarantees and compliancy of the
involved parties for the whole data stream.</li><li>Integrating
CLM with Business Process Management and its link to the GDPR process
management: data treatment audit items should be <em>identified</em> with their
legal sources in order to guarantee their management and enhance all following
process maintenance.</li><li>Evaluating
the opportunity of sharing the same tools as common language between controller
and processor.</li><li>Managing GDPR processes (audit and maintenance) using the
legal perspective as a starting point.</li></ol>



<p><strong>Conclusions</strong></p>



<p>Organizations need support regarding EU sensitive data manipulation compliance; complex activities must be managed involving IT and service contracts review. Contract Lifecycle Management tools help organizations in the tedious task of identifying and collecting their processors for a correct GDPR risk management.</p>



<hr class="wp-block-separator"/>



<p>This article is also available in LinkedIn, in pdf format, <a href="https://www.linkedin.com/feed/update/urn:li:activity:6551485925355065344" target="_blank" rel="noreferrer noopener" aria-label="here (opens in a new tab)">here</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Why Business Process Management is a better choice than only process mapping in GDPR tools﻿</title>
		<link>https://bkmsoftware.com/process-mapping-attrition-in-gdpr-tools-or-bpm-opportunity%ef%bb%bf</link>
		
		<dc:creator><![CDATA[Lorenz Baermann]]></dc:creator>
		<pubDate>Wed, 26 Jun 2019 14:29:21 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[cumplimiento]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[Process Management]]></category>
		<category><![CDATA[Process Managementcompliance]]></category>
		<guid isPermaLink="false">https://info.bkmsaas.net/gen/process-mapping-attrition-in-gdpr-tools-or-bpm-opportunity%ef%bb%bf/</guid>

					<description><![CDATA[Companies and organizations are experiencing the first stage of a new digital support: GDPR management tools. We analyzed some of them. As for all previous cases of new business compliance processes there is today a growing number of tools in the market addressing the all&#8230;]]></description>
										<content:encoded><![CDATA[
<p>Companies
and organizations are experiencing the first stage of a new digital support:
GDPR management tools. We analyzed some of them.</p>



<p>As
for all previous cases of new business compliance processes there is today a
growing number of tools in the market addressing the all new European privacy
law, the General Data Protection Regulation, which came into force on May 25,
2018. Our main conclusion: <em>these privacy
tools have design limitations</em>.</p>



<p><strong>The problem</strong><strong></strong></p>



<p>In
some cases the approach of the solution is technological -systems designed as
if they were independent or of static nature- while in other cases it’s
functional, thus technical in compliance matters, still specific. </p>



<p>We
classify both approaches as mainly marketing-oriented; not in order to
criticize the quality of these tools as such but the fact that the solutions
primarily are momentum-driven commercial opportunities for a sudden demand,
which market is still not well versed on the subject. <em>This practice raises issues, indeed</em>.</p>



<p>Talking
with GDPR experts it emerges that some entrepreneurs and executives have taken
a vision which limits GDPR compliance to – a bureaucratic – document management
or, even worse, they seem a one-shot maintenance-free operation. All despite
the many and repeated warnings and risks of running into huge administrative
fines. </p>



<p>Moreover,
we have been confided that companies apparently prefer a non-matching real-world
business processes above the presenting of&nbsp;
‘official processes’ and carry on with their usual ones. The bottom
line: the risk and the purpose of the compliance audit is dispelled although
time and money is expended, and at a high risk cost at the same time.</p>



<p><strong>Back to the past</strong><strong></strong></p>



<p>We
note a remarkable parallel to the 90’s when ISO quality certification was
fashionable. It was not uncommon to find entrepreneurs chasing contingently
after a series of certificates, <em>however
without any serious intention to change their company culture</em>. </p>



<p>We
have worked with quite a few of them at that time and, unfortunately but not by
chance, none of them had enlighten their future after such choices. (None of
them exist anymore in the market, but this is just a personal account.) </p>



<p>Three
decades later quality at large -finally- seems widespread in many business
environments, and process mapping &amp; re-engineering is nothing new anymore.
The resulting benefits are acknowledged as part of our business culture. </p>



<p><strong>An innovative approach – a golden opportunity</strong><strong></strong></p>



<p>Underestimating
the interventions required to meet the GDPR or not taking advantage of all
actions needed during this process, may lead companies to choose wrong tools
that require serious compliancy efforts. Often this road also leads to the
impossibility to become connected with other fundamental areas of competence
such as Legal and Operations. Given all of the above, we raise a crucial
question: </p>



<p><strong><em>Why
should companies and organizations re-map their processes only for GDPR
purposes?</em></strong><strong>
<em>Why do GDPR tools not start from managed
processes? </em></strong><strong><em></em></strong></p>



<p>Exchange
standards are available, such as IDEFx, FFBD or BPMN 2.0 for modeling or
universal standards like XML or Json, just to provide some examples. Then, how
common it is actually the adoption of process mapping tools?</p>



<p>This
lack of integration of best practices and previous investments leads to a
costly attrition.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
