NetApp makes data infrastructure intelligent. Their purpose is to create a world of opportunity for their customers. They provide a silo-less approach combining: 

  • Unified data storage with the only enterprise-grade storage service natively embedded in the world’s biggest clouds. 
  • Integrated data services with built in data resilience and policy-based governance.
  • Cloud-ops solutions with AI-powered optimisation of on prem and cloud infrastructure. 

By combining unified data storage, integrated data services and CloudOps solutions, data infrastructure is made more seamless, more dynamic, and higher performing than ever before. 

Project Goal(s)

  • Manage a global privacy legal operations program and implement a privacy compliance framework that is in compliance with GDPR and CCPA. 

Contributions

  • Successfully managed a global privacy legal operations program, overseeing a legal team 
  • Developed and implemented a comprehensive privacy compliance framework in accordance with GDPR and CCPA regulations, resulting in a drastic reduction in compliance risks and improvement in customer trust 
  • Utilised agile project management methodologies to streamline privacy operations and increase efficiency by 75% 
  • Designed and configured OneTrust data mapping and assessment automation tools from scratch to streamline privacy compliance processes and improve accuracy of risk assessments 
  • Reconfigured the information from TAP into the OneTrust Data Mapping module, Processing activities, Assessment automation (PIA), Asset register, Vendor register, Risk framework, configured legitimate interest assessment template, transfer impact assessment template, Rule engine
  • Completed a number of LIAs, PIAs, TIAs etc.,
  • Integrated various customer systems to OneTrust Data Discovery module and setup worker nodes
  • Implemented Cookies and Universal consent for all the Global countries
  • Implemented a data discovery and cataloguing system to enable effective management of personal data assets and support compliance with GDPR, LGPD and CCPA requirements.   
  • Developed a privacy risk registry to identify and assess potential privacy risks and vulnerabilities, enabling proactive mitigation and remediation efforts. 
  • Managed a high volume of data subject requests across multiple jurisdictions, maintaining a response rate of 
  • 100% compliance with all relevant regulations and timelines 
  • Implemented a centralised data subject request management system, resulting in reduction in response times and increase in customer satisfaction 
  • Developed standardised processes and documentation for data subject request handling, improving efficiency and reducing errors by 40% 
  • Led efforts to ensure compliance with a range of global privacy regulations, including GDPR, CCPA, PIPEDA, and HIPAA 
  • Developed and implemented a comprehensive privacy compliance program that achieved compliance across  all relevant regulations and jurisdictions 
  • Conducted regular privacy risk assessments and audits to identify and address compliance gaps and vulnerabilities, resulting in a reduction in regulatory fines and penalties 
  • Prepared and delivered regular reports as part of the Data Protection Officer duties to senior stakeholders, providing timely and accurate insights into privacy compliance performance and risk management activities
  • Developed and implemented an accountability framework to ensure effective governance and oversight of  privacy compliance activities, resulting in improved transparency and accountability across the organisation 
  • Led efforts to align privacy compliance policies and procedures with ISO 27002 controls, enabling effective risk management and compliance with international privacy standards.’

Technologies/Framework/Platform for data/management/delivery

  • OneTrust 
  • MitraTech TAP

Outcomes

The Contributions above were all successfully implemented and NetApp were very happy with out contribution in provided them a global privacy compliance framework that not only increased efficiency within their company in relation to data protection matters but also increased the trust from their customers and hence their reputation/brand name.