About the Company
One of the largest banks in Europe, our client is a French international banking group currently operating with a presence in 72 countries and with over 200,000 employees.
The Challenge
The client’s main challenge was in providing unified, consistent privacy processes across the whole organisation. As they are such a big complex organisation, each country operated slightly differently, and each division of the business worked in different ways. This meant the client struggled with transparency, and ultimately made consistent reporting extremely difficult. It was clear that they needed to implement consistent processes, as well as automating where possible to keep the costs down.
The secondary challenge for the client was the importance of aligning risk management with data privacy management. The internal challenge for the client was defined as “How can we align all of the different operations across our multiple countries in one tool?”
The client’s main pain points were:
- Inconsistent privacy processes across the organisation
- Aligning risk management with data privacy/protection
- Aligning all the countries in one tool
- Different maturity levels in different divisions
- Difficult to report clearly and efficiently to the Board
Previously, they weren’t using a ‘data privacy management’ tool, with everything being done manually via spreadsheets. Having reviewed their organisation they had encountered different data privacy management solutions, multiple methodologies and disparate execution, underlining why it was incredibly difficult to create the transparency and consistency that the Board desired.
Our Approach
We delivered a holistic solution for the customer that included the ServiceNow Integrated Risk Management module and Wrangu’s own data privacy management product, Privacy Hub. To ensure success at each stage, the delivery was broken down into phases, with each phase having a parallel stream.
Phase I involved starting with Data Protection Impact Assessment and Data Breach modules in Privacy Hub and in the parallel stream implementing the ServiceNow IRM module.
Phase II followed with the focus being implementation of Record of Processing Activities in Privacy Hub, with the parallel stream enhancing the risk management processes.
Using the flexibility of ServiceNow and Privacy Hub we used the customer’s own pre-defined questionnaires and decision making structures and work flows whilst working with them to create a consistency that could provide significant automation ensuring cost savings and ease of business implementation.
We also implemented some customised enhancements, such as a DPO dashboard that is specific to their needs and includes issue management, thus enabling a joint view of risk and data privacy across all divisions.
The client has successfully implemented the solution in France and the UK, the roll out took place globally in the summer of 2020.
“A big thank you for Wrangu’s flexibility in helping us managing the different resources on the different projects. We see many efforts done on the planification and on providing the required data within a short time. In addition to flexibility, Wrangu have demonstrated empowerment in driving the consultants to deliver. With all the different projects that our teams face/are involved in, Wrangu and the team go beyond their remit and help our teams to prioritize the user stories, define acceptance criteria, clarify any user story, which makes this Sprint very valuable.”
Head of Group Data Management, French Banking Group