Multidisciplinary team or full stack? The who's who of privacy.

Estimated reading time: 2 minutes

Summary

People are always the key element when it comes to compliance with the General Data Protection Law. Always. It doesn't matter the volume of data, the format in which it is stored, the level of risk to which it is exposed, or the technology that supports the privacy project or program.

As I've already said, if one swallow doesn't make a summer, a single professional also cannot maintain or improve suitability. It's necessary to find the right spaces for the professional types that support all aspects. It's necessary to create a functional identity for the program. It's necessary to be clear that conflicts of interest also operate at this level and will interfere with the outcome. 

This reflection stems from closely observing the emergence of "silos" that house the area or department of privacy and data protection. Frequently, the approach is seen from a technological or legal perspective, which translates into addressing vulnerabilities in systems or legal frameworks and contractual issues. But what about the processes? And adherence to principles? And the data subject? And everything else that governance entails?

It seems simplistic to view it through the aforementioned biases, and in a way, it is. But in practice, that's what you often find out there. The goal here isn't to debate the reasons why or to consider exceptions to the law, as the focus is precisely on environments that demand results but don't deliver. A "full stack" privacy professional doesn't juggle all the plates and, consequently, doesn't ensure all the requirements of the law are met. And that's okay.

In this context, based on my professional experience and my vision of both the market and the business, I always consider interdisciplinary and multidisciplinary work to be essential. This means that there is room and a need for the involvement of information and governance professionals, lawyers, information security specialists, process specialists, project management specialists, risk management specialists, IAPP/EXIN/other certified professionals, and so on…

Considering the actions of the National Data Protection Authority and its future prospects, there is no longer room for the treatment afforded in the early stages of the Law. It is necessary to expand the vision holistically and consider that although some professionals have a more specific and intermittent role, others act consistently to ensure the adequacy and protection of personal data and corporate information, and the proper management of the privacy program.

Looking for connections in other areas of knowledge, we can affirm that "privacy is not an isolated responsibility, but rather an orchestra where each professional, like a musician, plays their part to guarantee the harmony and security of all data."

About the Author

Meet the author of this article.

Want to see how Privacy Tools can help your company in practice?

Request a personalized demonstration and see how our solutions adapt to your needs.

Related articles section

Read also