Category Archives: Guest Author

GDPR: The Legal Side of the Equation (Part IX)

Today’s guest post is from Tony Bridger, an experienced provider of Procurement Consulting and Spend Analysis services across the Commonwealth (as well as a Lean Six Sigma Black Belt) who has been delivering value across continents for two decades. He is currently President of UK-based TrainingWorx Ltd, a provider of a wide range of Procurement and Analytic business training programs (inc. GDPR, spend analysis, project management, process improvement, etc.) and focussed short-term consulting solutions. Tony can be contacted at tony.bridger@data-trainingworx.co.uk.

As they used to say at the start of the Star Wars Movies, the saga continues. Having explored the physical options of minimisation and anonymisation, information security standards and certification –- we have the option of just, well … complying.

So, what has to be done? If you are a large global vendor in the analytics space -– binding rules is the key option as we have already suggested. For smaller, niche vendors, the regulations are a little more complex. However, not insurmountable. As we have highlighted in several posts, for US providers –- Privacy Shield is a great start.

It is illegal from 25th May to move personal data outside of Europe without the right data controls and contractual agreements in place. The UK based Information Commissioners Office (ICO) as the supervisory authority of the UK is a good place to start for detail. The ICO has written several key documents on how commercial relationships are supposed to work if personal data is moved outside of the EU. The most common arrangement is likely to be the Controller-Processor relationship. In effect, data is controlled within the EU — but processed externally. As we mentioned in a previous post, processors must have representation within the EU if they reside outside of the European Union. This is for notices from client — this contact must be published and available.

The second group of conditions relates to processor operations. The ICO documentation on this is clear. Processors must:

  • only act on the written instructions of the controller (unless required by law to act without such instructions). This means that controllers need to be clear what operations and processing will take place on the supplied data;
  • ensure that people processing the data are subject to a duty of confidence. This means that supplier organisations cannot simply state that staff “stole the data”. This means that data access in processor organisations needs to be contractually managed;
  • must take appropriate measures to ensure the security of processing. This is where the notion of certification and standards becomes prevalent.
  • must only engage a sub-processor with the prior consent of the data controller and a written contract.

None of these conditions are insurmountable –- many procurement practitioners within the European arena will have started to scrutinise a wide range of non-EU supplier contracts. Many vendors may have already been engaged on this process.

In the next post we will continue the controller-processor theme. There are several additional conditions that are required for processors.

We will post these in small doses — this keeps reading and understanding the changes a little more digestible.

We do need to warn you that from here, the GDPR starts to appear somewhat incomplete.

However, it’s a big change that has yet to be combat tested.

Thanks, Tony.

Transformation, Transmogrification …. or business as usual?

Today’s guest post is from Tony Bridger, an experienced provider of Procurement Consulting and Spend Analysis services across the Commonwealth (as well as a Lean Six Sigma Black Belt) who has been delivering value across continents for two decades. He is currently President of UK-based TrainingWorx Ltd, a provider of a wide range of Procurement and Analytic business training programs (inc. GDPR, spend analysis, project management, process improvement, etc.) and focussed short-term consulting solutions. Tony can be contacted at tony.bridger@data-trainingworx.co.uk.

The web is a fascinating place, your capacity to search, ponder and read is unlimited in reality. However, whilst rummaging around I happened to read an article in Forbes from 2015 entitled Why Business Transformation Fails and How to Ensure It Doesn’t.

There is little or no doubt that the “T” word has appeared in all functional areas of business life – Finance, Operations, Procurement, Human Resources and just about any type of business. Forbes suggests most transformations that fail are due to inefficient execution (41%), followed by resource and budget constraints (35%). It is likely that failure levels are much higher – but how do you define failure? Forbes also suggest that many failures are due to a “lack of buy-in”. Sadly, that phrase is largely overused — and meaningless if you think about it for a moment or two.

Many employees go to work for income — they may not see buying-in to changes as a high priority. The article also suggests that everyone needs to be “on the same page”. Again, there is a difference in understanding and interpretation by individuals of the reason why a change is occurring and what it means for them. As with many things — there is large scale charity, change and transformation fatigue – people just see inefficient execution as the same internal muddle repeated on a regular basis. Meanwhile, every day of the week the transformation word continues to bounce back. It is clearly a fad with some time to run.

Having been part of, and subject to, a considerable number of transformations over a number of years, the best performing companies (large and small) take changes in their markets and competitive environment as business as usual drivers. Change or die. There is no such thing as transformation. It’s simply good business management. No fanfare, just outcomes, jobs and profits.

In the procurement space in particular, social media articles exhort many large organisations who have managed to deliver “empowered staff within a learning organisation” and yet very little on “the net hard savings from this transformation were … $X”. In an analysis of some (as yet un-published) recent survey data, around 43% of Chief Procurement Officers in large companies had no analytics capability. However, many had advanced contract management, e-procurement and other sourcing capability. But no analytics numbers. One can assume the usual array of uncoordinated spreadsheets.

Whilst it is easy to accept the premise that executives inherit environments, the procurement focus should be on numbers and savings or realized value (if Procurement helped with an initiative that increased sales, that should be captured too). If you don’t have the numbers, get them. The issue may simply be that inefficient transformation execution means that little or no rigour is attached to the expected outcomes. It starts with a pre-change number and ends with a post-change number. What gets measured gets attended to. What people need to read are change strategies that they can emulate to drive down costs.

As will emerge shortly, the collapse of Carillion is likely to have been driven by managers who were transforming visionaries. They just needed to manage the business through market and competitive change. In effect, just get on with it.

Thanks, Tony.

GDPR – still avoiding the problem? (Part V)

Today’s guest post is from Tony Bridger, an experienced provider of Procurement Consulting and Spend Analysis services across the Commonwealth (as well as a Lean Six Sigma Black Belt) who has been delivering value across continents for two decades. He is currently President of UK-based TrainingWorx Ltd, a provider of a wide range of Procurement and Analytic business training programs (inc. GDPR, spend analysis, project management, process improvement, etc.) and focussed short-term consulting solutions. Tony can be contacted at tony.bridger@data-trainingworx.co.uk.

In our last post we noted that those with extensive risk management experience know that avoidance is a key strategy for risk minimisation.

We also noted that this may well be a very feasible option f-or those analytics suppliers outside of the European Union.

The GDPR actively supports the anonymisation approach:

The principles of data protection should …. not apply to anonymous information, namely information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable. This Regulation does not therefore concern the processing of such anonymous information, including for statistical or research purposes.”

By removing or replacing data elements this satisfies another element of the Regulation – pseudonymisation:

the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.” (Article 4).

Credit card or card account numbers can be used to identify a person – many card systems encrypt or hash the card number if expense managers are used. Once again, it pays to do the data homework.

The salvation for many spend analytics providers is to encourage the client to set data extract routines that eliminate these types personal data.

However, that still leaves us with the less easily manageable data component of personal data buried within invoice line descriptions or other ERP free text fields.

Once GDPR becomes recognised as the “new paradigm”, analytics providers are likely to claim that they have all sorts of (chargeable) capability to remove this data or anonymise it. This is more likely to revert to a line by line manual check as opposed to anything technically complex or ground breaking.

There is nothing intrinsically wrong with this approach. It may be time consuming but will follow the usual pattern of spend analytics data management. The first stage of the dataset build is historical data construction. If all historical spend data is checked and anonymised, then monthly refresh data is much lower volume – and patterns where personal data may exist may have already made their presence known – a pattern.

Vendors and clients are therefore taking all reasonable precautions with the data. If the data can have all personal elements removed, then GDPR does not apply. The “shotgun approach” for web providers is to use full access encryption…but this could be prohibitive in cost terms.

So, what is the risk? Spend data with personal data content has to align with the Regulation both within the EU — and transferring data outside of the EU. The use of surgical data techniques can reduce the risk and perhaps even reduce the data to non-personal in nature.

The alternative option is to leave the personal data and adhere to the range of controls that are required to manage that information. We have yet to cover these controls in any detail.

As we will discuss later in a later post, staff, employee data and personal data may also be subject to consents. A considerably more complex issue under GDPR. With new elements like right to be forgotten it may be simpler just to remove the data components.

No one said this was going to be easy.

Thanks, Tony.

GDPR – avoiding the problem? (GDPR Part IV)

Today’s guest post is from Tony Bridger, an experienced provider of Procurement Consulting and Spend Analysis services across the Commonwealth (as well as a Lean Six Sigma Black Belt) who has been delivering value across continents for two decades. He is currently President of UK-based TrainingWorx Ltd, a provider of a wide range of Procurement and Analytic business training programs (inc. GDPR, spend analysis, project management, process improvement, etc.) and focussed short-term consulting solutions. Tony can be contacted at tony.bridger@data-trainingworx.co.uk.

For those with extensive risk management experience, avoidance is a key strategy for risk minimisation.

For those analytics suppliers outside of the European Union, this may well be a very feasible option. If we assume that spend data could contain P Card holder names, personal data in staff reimbursements and personal details in invoices – what are the avoidance options?

A myriad of options exist that analytics providers can deploy to avoid the personal data problem in risk terms. The first, and most obvious option (and least acceptable) is to refuse to take data from clients that that may contain personal data. However, the old adage applies that “some will always take the business, and someone will always do it cheaper”. Its also not a tenable under the GDPR, the fact that the client says the data is “personal data free” may not stand up if a breach occurs.

There is an old English adage that simply states that “you can’t eat a horse at one sitting”. If we start to break the problem up in to manageable components the potential issues become less intimidating.

One of the major areas of concern is P Card data. In the UK, many local councils and authorities publish their P card data for public access (in Excel files) on their websites – but with no personal cardholder data. It really focuses on the core question – does the client really need the name of the cardholder/Card number – or is the supplier spend the key focus? If the card data is extracted post reconciliation (if an Expense Manager is used for card management), the data will contain a cost centre. If the cost centre structure is loaded as a hierarchy it can be relatively easy to see where spend is occurring within the organisation – but not who incurred the cost.

The second key area is staff reimbursements. Many companies still set staff up as vendors to pay reimbursements. This spend too is quite insightful and may deliver several sourcing opportunities. However, it still leaves the personal data in the file that may be extracted from the ERP. For this element of the data, it may be far simpler to create a data mechanism that identifies those vendor master entries on the client ERP with a data flag of some kind. For statutory tax reporting purposes, many corporate clients are required to account for reimbursements for staff (for taxation purposes e.g. Fringe Benefits). So, if the client can remove staff names or attributable identifiers– then that will eliminate or avoid the data issue. In effect, there is the possibility that the problem can be eliminated on the client extract, but you must ask the client more about how they are extracting their data and guide them as to how they can better manage their data for GDPR compliance to prevent getting data you don’t want. .

In many respects, spend analysis providers have had it really easy up until now. They simply give the client a data extract request, the client provides what they can, and the provider builds the dataset. GDPR for EU clients makes this process less simple from 25th May. Why?

To be continued!

Thanks, Tony.

GDPR and non-EU Spend Analytics Providers … Mortal Peril? (GDPR Part III)

Today’s guest post is from Tony Bridger, an experienced provider of Procurement Consulting and Spend Analysis services across the Commonwealth (as well as a Lean Six Sigma Black Belt) who has been delivering value across continents for two decades. He is currently President of UK-based TrainingWorx Ltd, a provider of a wide range of Procurement and Analytic business training programs (inc. GDPR, spend analysis, project management, process improvement, etc.) and focussed short-term consulting solutions. Tony can be contacted at tony.bridger@data-trainingworx.co.uk.

While there has been much debate within EU countries around the preparation for GDPR on the 25th of May, the level of knowledge and preparation for those suppliers of analytics platforms and services outside of the EU remains largely an unknown. Controversially, our assessment is that many customers/suppliers will have ignored it and assumed that it doesn’t apply.

If your spend analysis provider is a large, well-known brand name with a global presence, it is highly likely that they will have opted for the binding corporate rules option. This is a complex and intricate process but is essentially a means of larger data service/analytics providers applying to the EU to establish the provision. The supplier applies a BCR to one of the EU Supervisory bodies (one of the 27 EU members). These are termed Lead Authorities. Once the checks have been completed and the Lead Authority is satisfied with the adequacy of the data privacy safeguards in place, the Lead Authority decision is binding across all Supervisory authorities in other European states. However, as in much European Legislation member states may have additional requirements.

Once Binding Corporate Rules (BCR) status has been achieved:

Binding Corporate Rules (BCRs) are designed to allow multinational companies to transfer personal data from the European Economic Area (EEA) to their affiliates located outside of the EEA in compliance with the 8th data protection principle and Article 25 of Directive 95/46/EC.

However, what of smaller providers? No so easy – and it can become rapidly more complex.

The EU has two other provisions for managing data that contains personal information – the rule of adequacy and safeguarding.

Not surprisingly (shock) all 27 EU members meet the rule of adequacy. Adequacy is simply defined around the level of protection at national level.

For other countries who are non-EU, the EU will judge this on the national rule of law; respect for human rights, fundamental freedoms and relevant legislation, both general and sectoral, including public security, Defence; National security and Criminal law. Simple enough …

Now the bad news. There are only some 11 countries globally that are deemed to meet this level of adequacy. These include Andorra, Argentina, Canada, Faroe Islands, Guernsey, Isle of Man, Israel, Jersey, New Zealand, Switzerland and Uruguay. If your spend analysis provider lives in any of these countries – that’s fine. Happy days.

However, what if they don’t? The new Regulation is simple in objectivity. The GDPR change removes a controller’s (or data owner, we will explain controller and processor in the next few posts) previous ability to transfer personal data outside the EU where this is based only on your own assessment of the adequacy of the protection afforded to personal data. More work to do.

This brings us to the last option – safeguarding.

Safeguarding means just that – can the supplier offer sufficient safeguards with data containing personal information?

However – can the problem be eradicated and avoid GDPR regulations?

We will cover these areas in the next post. Our advice as always – find a lawyer who understands the regulations and can guide you either as a customer or supplier. If you are in doubt, get advice.

If you breach the regulations – it could get expensive.

Thanks, Tony.