MX:Monitor
  • Home
  • UX:Inspector
  • DP:Monitor
  • About
  • Contact
  • Blog
A DP:Monitor case study

Putting data protection processes

to the test

 
An objective assessment of how data protection processes were being executed gave the DPO peace of mind and improved the organisation's implementation of the GDPR
 

The DPO in a medium-sized organisation in the leisure sector knew that his organisation had put a good set of processes in place to meet the requirements of UK data protection legislation, but had concerns about how these processes were being carried out.

Specifically, he wanted to know whether the interaction between the organisation and its customers and prospects was happening in the way that he was expecting it to, and that personal data was not being shared around the organisation or leaving the organisation unlawfully.

This customer operated six different databases to manage customer and prospect details, including databases for bookings, wi-fi access, chat, and customer and supplier finance.

Tracker insertion and interaction
We used a hybrid approach for the tracker insertion, to test each method of data acquisition by the organisation.

We prepared 40 trackers for direct insertion into the different databases by the customer's IT team, making sure that each set was unique. In addition, we inserted further unique trackers by entering competitions and using their chat bot. This meant that we would be able to get an indication of how data was flowing around the organisation.

The staff processing personal information were not aware of the presence of trackers so as not to influence in any way their processing of the information in their day-to-day jobs.

For the duration of the three-month contract that we had with the customer, we monitored the tracker accounts to see what communications they received. We were also able to determine how staff responded when we exercised the various subjects' rights via the trackers, such as the right to access, rectify or erase their data.

Review and reporting
As part of our work for the customer, we reviewed their privacy notice. We advised the customer to amend the notice since it stated that access requests would be charged for, and there were also an issue relating to consent to the international transfer of data, which was in breach of the GDPR.

Our investigation of the exercising of subjects' rights uncovered that the way access requisitions were handled was found to be not legitimate, and we advised the customer on how to rectify this.

We were also able to show that we could not find any evidence of data breaches, since we received no emails to the tracker accounts from anyone other than the customer, and none of the tracker email addresses were found on the dark web.

The databases were also found to be secure and did not pass information from one to the other, so that those who were in the wi-fi database, for example, were not being passed to general marketing if they had not expressed a wish to be communicated with.

We provided the customer with monthly reports to demonstrate our findings.

Reassurance for the DPO
Our findings and advice reassured the DPO that the processes and procedures that he had put in place were working effectively, and with a few minor tweaks, were fit for purpose. He could allow the marketing and other teams to proceed with the confidence that their implementation actions had been thoroughly tested. 
Site powered by Weebly. Managed by SiteGround
  • Home
  • UX:Inspector
  • DP:Monitor
  • About
  • Contact
  • Blog