GDPR: Are you a Controller or a Processor (Part VI)

Today’s guest post is from Tony Bridger, an experienced provider of Procurement Consulting and Spend Analysis services across the Commonwealth (as well as a Lean Six Sigma Black Belt) who has been delivering value across continents for two decades. He is currently President of UK-based TrainingWorx Ltd, a provider of a wide range of Procurement and Analytic business training programs (inc. GDPR, spend analysis, project management, process improvement, etc.) and focussed short-term consulting solutions. Tony can be contacted at tony.bridger@data-trainingworx.co.uk.

It was Glen Hoddle (English Soccer player) that wrote:

“I have a number of alternatives, and each one gives me something different”.

For many spend analysis providers (or other procurement tools providers) and their clients that manage personal data, the alternative may be simply to change nothing technically – and keep going with the status quo. In effect, implement the requirements of the GDPR regulations.

Like most alternatives there are trade-offs. If eliminating personal data is practicable – then that may be the first viable alternative for suppliers. However, leaving the process as-is and implementing the EU required controls may be the better option longer term.

However, there are several key changes required by 25th May. To be GDPR compliant requires those controls to be in place prior to that date.

The key concept in this article is ensuring that analytics suppliers understand the difference between a controller and processor. For commercial data that contains no personal data, this concept is inapplicable and no further action is required.

Under GDPR, the controller means:

“ … the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.”

In most cases, the controller will simply be the client.

After all, they will supply the data and direct what they want to happen with those transactions.

The processor is defined as:

“ … a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.”

To all intents and purposes, most spend analytics providers within (and external) to the EU may be either a controller or provider (or both).

For companies that use serviced systems outside of the EU, providers are therefore processors. Being outside of the EU creates a number of key criteria that need to be met for compliance.

There is also a very clear definition in the Regulation about what constitutes processing:

“ … It means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.”

Therefore, by default, any serviced analytics provider generically meets the definition.

So, what does this mean? Come back tomorrow for out next installment!

Thanks, Tony.

One Thousand One Hundred and Fifty Years Ago Today

A copy of the Chinese version of the Diamond Sutra was dated (before, at some point being lost to history until their rediscovery in in the Mogao Caves of Dunhuang on June 25, 1900.)

So why do we care about an old book?

First of all, it’s the oldest known dated book in existence, at least 585 years before Gutenberg printed his first bible. Because, even though the invention of the printing press was attributed to Gutenberg, he was just the first person to create a press out of metal. Woodblock printing was developed in China approximately 1200 years before Gutenberg developed his press, with examples of woodblock-based cloth printing dated back to pre 220 AD and the earliest examples of woodblock-based text-printing dating back to the Tang dynasty in the 600s. However, books were not dated at that time, making the Diamond Sutra, from 868 AD the first dated book.

However, it’s not just relevant to us that this was the first dated book, which is quite relevant to copyright and legal systems — that now use dates to determine inventorship, ownership, and so on — and to those of us that want to understand the origination of a work.

What’s really relevant to us is that accompanying the date was a dedication that said “for universal free distribution”, making it the first known creative work with an explicit public domain dedication. It seems that formally dedicating work to the public domain to ensure it’s continued free usage may not be as recent an occurrence as we may think.

And its another example of just how rich and innovative the cultures of the east have been over time, and why we should learn all we can instead of putting up trade barriers.

Supply Management Priorities are Hard to Define

As per yesterday’s post, figuring out your priority can be particularly painstaking because the maximum benefit is only realized when certain supporting systems are in the mix.

If we reverse our last post, you might well think that you need the following core modules to benefit from the indicated modules, and you might well be right.

Spend Analysis –> Product Management, Category Management
e-Negotiation –> Spend Analysis, SSDO, Guided Buying
SSDO –> Spend Analysis
Contract Management –> Spend Analysis, Requirements Definition, Product Management
Catalog Management –> Supplier Management, e-Negotiation, Guided Buying
Purchase Order / Invoice Management –> SSDO, Guided Buying, Catalog Management, Supplier Management
Supplier Management –> Opportunity Analysis, e-Negotiation
Risk management –> Opportunity Analysis, Contract Management
Product Management –> Contract Management, Guided Buying

But something interesting falls out of this. You don’t really need anything to get started on supplier management, and the only thing you need to benefit from e-Negotiation is a way to make use of the data (be it spend analysis, optimization, category-management based guided buying, etc.). And when you start on your supplier management journey, it’s supplier information management (followed by data-backed supplier performance management).

What does this tell us? The starting point is a (set of) solution(s) that helps you get your supply management master data under control. After that, the primary buying categories, the market, the internal situation, and a host of other factors will need to be balanced to select your next (set of) priority(ies), but without data, you’re not going anywhere.

What’s Your Supply Management Priority?

Supply Management Mastery is an elusive goal. As SI has been documenting for years, in order to master supply management, you have to manage a slew of Source to Pay processes as well as related Operational, Finance, and Risk processes.

But this is not easy when you consider the many steps involved in even source to pay. Spend Analysis. Opportunity Analysis. Requirements Definition. e-Negotiation. Strategic Sourcing Decision Optimization. Contract Negotiation Management. Catalog Creation. Guided Buying. Purchase Order Management. Invoice Management. Supplier Management. Risk Management. Product Management. And so on.

You have to master all of them, but you can’t work on them all at once. You have to make priorities, and eliminate all but the top three (3). And even then, you might not be able to tackle all three if each would require a separate system.

So what’s your priority?

Spend Analysis gives you insights, but you have to be able to act on them. That requires e-Negotiation, SSDO, contract management, etc.

Opportunity Analysis goes beyond just spend to determine if your opportunities are spend related, supply base related, process related, or otherwise.

Requirements Definition helps crystalize organizational needs and helps the buyer zero in on what really matters. But then it has to create good contracts and statements of work.

e-Negotiation helps capture all of the back-and-forth between both parties so that the organization can build supplier profiles and take advantage of that. Provided the organization has deep supplier master data management.

SSDO can find the optimal cost allocation across suppliers, products, and carriers and delivers an average savings year over year that exceeds 10%. But it requires deep models and lots of data. And where does that data come from? Typically from e-Negotiation.

Contract negotiation management is great for creating great contracts. But you need product details, SOWs, risk management and liability clauses, and other data.

Catalog management software is great, as long as you have a supplier management portal to manage the supplier the catalog comes from.

Guided buying is even better, but only if you have the solutions to guide the buyer to that captures the majority of organizational spend. Guided buying that only works in an incomplete catalog is more of a frustration than a solution.

Purchase Order Management can eliminate a lot of paper, provided there are catalog, sourcing, etc. systems to integrate with to auto-generate those POs on buyer actions.

Invoice Management systems are great, as long as you have POs, contracts, goods receipts, and other documents to m-way match against! Otherwise, they just collect e-paper that still has to be manually reviewed. (And in the average organization, that still typically results in them being printed.)

Supplier Management is great for managing information, relationships, and performance, provided their are networks and portals to collect the data from, and internal systems to create and manage scorecards to define performance improvements on.

Product Management is key to understanding the product and category dynamics, but then you need category management strategies to map to.

And, these days, instantiations and realizations of risk can wipe out the savings from 10 sourcing projects, so risk management is paramount, but detecting and monitoring for risks requires a slew of systems internal and external and lots of data.

In other words, every system is great, but generally only if you have one or more systems to collect the data it runs on or supplement key functionality.

Which again begs the question, what are your priorities? Otherwise, you’ll never know where to start.