Category Archives: Market Intelligence

GDPR – Consents (Part XIV)

Today’s guest post is from Tony Bridger, an experienced provider of Procurement Consulting and Spend Analysis services across the Commonwealth (as well as a Lean Six Sigma Black Belt) who has been delivering value across continents for two decades. He is currently President of UK-based TrainingWorx Ltd, a provider of a wide range of Procurement and Analytic business training programs (inc. GDPR, spend analysis, project management, process improvement, etc.) and focussed short-term consulting solutions. Tony can be contacted at tony.bridger@data-trainingworx.co.uk.

You will have to forgive us for this post – this is not an easy topic. The topic is quite broad and, as with most elements of the GDPR, takes a little thought and consideration.

Consents need to be considered as a key privacy factor across many elements of procurement business.

There are several ways we can discuss consents – but we thought that to demonstrate the complexity of the legislation – and some of the care that needs to be taken, we would use a fictional human resource or temporary labour company in Europe.

If you have any doubts whatsoever as to the complexity of the legislation for this category of supplier, drop on to the site of one of the larger UK based recruitment company websites and enjoy a leisurely afternoon coming to terms with their Privacy notice.   All of them have had to:

  • Map out where personal data is held – files, paper, spreadsheets, databases;
  • Understand who they share it with;
  • Centralise and control their access to personal data;
  • Define the who, what, why, when and where of holding candidate data – and make that clear to candidates;
  • Ensure candidates are informed of how their data is managed – stored and used;
  • Provide consent to send their personal resumes to clients as needed – however, for differing clients, it is likely that individual consents will be required
  • If the recruiter provides psychological testing, they will need to be clear how long those results are retained for, their use and how the results are used.

For example, in 2016-17, the New South Wales government allowed psychological testing of candidates for key roles.  However, the results of these tests were made available across all government agencies on demand – some 30+ of them.    If this was Europe – and a breach occurred – it could be a costly exercise.  Is the Government the agency – or each individual state agency or body?   The differences in how data is used (and associated consents) varies considerably across the globe.   Ironically, the NSW Department of Industry has just issued a warning to candidates that may have applied for roles could have has their personal details exposed in a potential breach – a breach that may have occurred on a much wider basis.

For procurers, if temporary labour agencies are used (and consultants are in the same domain , whether they like it or not)), many will insert contractor or employee names into invoices.   As the initial consent to disclose, and offer of work would have been consent based, it does rely on all parts of the consent process working to specification.   Perhaps that, as the old saying goes, could be a verloen hoep or “forlorn hope”.

With spend analysis data, recruitment agencies would no doubt use the legitimate processing clause – in combination with contractual processing requirements.  No harm there we suspect.   The customer would have the data – and for analysis purposes would need to review that data for contractual reasons.   All seems sensible enough.

However, if you think about the number of if-then-else processes and sub-processes that need to comply, then statistically it will be hard to ensure that all consents are in place in a fast-moving business.   At a later date, if a contractor submits a Data Subject Access Request this could involve recovering information that an agency has supplied to former contractor employers – again it is unclear.  It could be made worse if relationships between agency and customer have broken down.

We don’t have the answers, sadly.  However, it is, sadly, almost inevitable that someone will fall foul of the legislation in a supply chain as complex and high volume as temporary labour.  We shall see.

Thanks, Tony.

Make Sure Your Perishables Don’t Perish!

With natural disasters on the rise, and late frosts already minimizing or eliminating the crops that will be available in the fall, it’s more important than ever to minimize food waste throughout the supply chain.

Thus, SI would like to remind you of some important tips that can have a big impact on keeping your perishables from perishing!

  • Do not load produce at night.
    When it’s easy for insects and other pests to get in unnoticed. Not only can a family of spiders ruin the grapes, but they might be banned in the country you’re importing into, which would result in your truck getting stopped at the border and turned around.
  • Always home-source during harvest season.
    Unit prices might be higher, but shipping will be lower, and loss will be lower still as you won’t risk losing product in long shipments, which happens regularly when trucks break down and/or get held up at the border. Plus, many people will pay a slight premium for local produce.
  • Know the seasonality for key staples in every region, not just the ones you generally source from.
    This will make sure you’re always sourcing from the region with the most supply, which will help you to get you the lowest costs as you will be able to negotiate better unit prices and secure transportation in advance when prices are low.
  • If the perishables will be processed, re-optimize the processing network.
    If you’re going to can, freeze, or otherwise process the perishables into a less perishable product, do it as close to the source as possible, even if it means using new suppliers or investing in new manufacturing plants. These refined products, which are typically denser, and which may not even require refrigeration, will be much cheaper to ship and suffer a lesser risk of loss.
  • Have a plan to sell excess perishables once they reach their prime before they perish.
    50% off at the store is not always good enough, especially if they are marked down an hour before closing on a Tuesday night and will not be saleable tomorrow. For example, even overripe, tomatoes are still great for pastes and soups. You could have each store strike a deal with local restaurants that allow them to buy perishables at prime at a discount before they are unuseable, or, if you are socially responsible, setup a donation program with a local shelter or soup kitchen where the shelter can pick up perishing items each day before close before they perish (and take your cash with them). Done right, you could probably even get a charity tax write off (as long as the items were donated while still edible). You may consider these ideas beyond the scope of sourcing, but you shouldn’t when you consider that 1 in 7 people in the world are undernourished and almost 40% of food is wasted in North America. Fix this. You have the power.

GDPR: Record … Record … Record (Part XIII)

Today’s guest post is from Tony Bridger, an experienced provider of Procurement Consulting and Spend Analysis services across the Commonwealth (as well as a Lean Six Sigma Black Belt) who has been delivering value across continents for two decades. He is currently President of UK-based TrainingWorx Ltd, a provider of a wide range of Procurement and Analytic business training programs (inc. GDPR, spend analysis, project management, process improvement, etc.) and focussed short-term consulting solutions. Tony can be contacted at tony.bridger@data-trainingworx.co.uk.

On of the key failings of the EU legislation is the apparent lack of standard EU approved clauses. They will arrive – at some point. For now, many vendors both inside and external to the EU will need to manage as best they can. We have covered the main contractual relationships required between processors and controllers. However, in brief they are:

  • Controllers must only use processors which are able to guarantee that they will meet the requirements of the GDPR and protect the rights of data subjects.
  • Controllers must ensure that they put a contract in place which meets the requirements set out in the available guidance.
  • They must provide documented instructions for the processor to follow.
  • Controllers remain directly liable for compliance with all aspects of the GDPR, and for demonstrating that compliance. If this isn’t achieved, then they may be liable to pay damages in legal proceedings or be subject to fines or other penalties or corrective measures

One of the major contractual changes between Controller–Processor is going to be the need to keep processing records. Given the nature of the change, if the provider is outside of the European area, this would be an important contractual requirement. It is also an important record of activity if a breach or error occurs.

It seems logical that most companies in the data business would see keeping records of processing activity as a normal standard business practice. Not so it seems.

For analytics (or any procurement platform provider), it may well be worth keeping some form of record of processing activity — if this is not currently a part of operational management. This may cover elements like data refresh receipt, refresh activity, new report generation and any other activity that takes place on the data. Remember, it would make sense to have one processing record for every processing requirement made by a controller. What would this take? A simple spreadsheet entry in most cases.

This may seem onerous, but if suppliers are anonymising or removing data from the transactions records, the who, what, why, where and when of processing maintained in records will allow tracking and follow up of errors if a breach occurs. It is an overhead – but is the basis of managing data more carefully and being able to cope with an audit.
However, as we will explain in a later post, the bureaucracy of the EU knows no bounds. We will introduce the concept of the DPIA, (Data Protection Impact Assessment) shortly.

The DPIA is an interesting concept — quite what anyone would do with these assessments at Supervisory Bodies (given the likely volumes) has to be questionable.

However, prior to that, we have to cover the thorny subject of consents.

Thanks, Tony.

GDPR: STOP THE PRESSES! (PART XII)

Today’s guest post is from Tony Bridger, an experienced provider of Procurement Consulting and Spend Analysis services across the Commonwealth (as well as a Lean Six Sigma Black Belt) who has been delivering value across continents for two decades. He is currently President of UK-based TrainingWorx Ltd, a provider of a wide range of Procurement and Analytic business training programs (inc. GDPR, spend analysis, project management, process improvement, etc.) and focussed short-term consulting solutions. Tony can be contacted at tony.bridger@data-trainingworx.co.uk.

It had to happen. In fact, almost inevitable really.

Within a week of the GDPR being implemented, the news story broke.

‘Embarrassing’ leak shows EU falls short of own GDPR data law

Without access to the full article on the UK Daily Telegraph Premium, it is difficult to assess the details of the breaches.

However … the response from a Commission spokesperson suggested that:

The European Commission is not subject to the strict new data protection law that it has imposed across Europe”.

Well, no surprises there. Given no published EU Commission accounts and constantly changing legislation it does appear somewhat Orwellian.

Ironically, the approach that many EU member state governments have deployed specifically rules them out of breach fines. The Irish government being one. (Source)

There is some logic in this approach.

It makes little or no sense to fine public bodies –- after all, they will pay the fine, reach a point in the annual budgeting cycle where they have a significant deficit –- and be topped up by central government. Take funding from one hand, pass it back with the other.

The United Kingdom has chosen not to follow this option — yet. However, one could predict that it will not take long for prosecutions to occur given government departments track record of personal date and cyber security breaches (within the National Health Service for example).

Not much of a deterrent and a massive public cost to prosecute and collect a revolving door fine.

Like much legislation the EU creates, it is clumsy, lacks detail and confusing. But it’s the law.

Taking a far more cynical approach, the GDPR appears to be legislation that is a Tax Collectors dream ticket.

There is the pretence of “protecting the rights and freedoms of EU citizens” –- whereas the reality is that it is a foolproof way of collecting what is essentially a data-tax from businesses for breaches.

A classic case of a cast iron fist in a velvet glove.

Will post more if the story evolves.

Thanks, Tony!

GDPR: The “Contract” (Part XI)

Today’s guest post is from Tony Bridger, an experienced provider of Procurement Consulting and Spend Analysis services across the Commonwealth (as well as a Lean Six Sigma Black Belt) who has been delivering value across continents for two decades. He is currently President of UK-based TrainingWorx Ltd, a provider of a wide range of Procurement and Analytic business training programs (inc. GDPR, spend analysis, project management, process improvement, etc.) and focussed short-term consulting solutions. Tony can be contacted at tony.bridger@data-trainingworx.co.uk.

Marvin Ammori, the US innovation lawyer suggests that:

one goal of law — as we learn in Law School from the first day of Contracts, is to deter bad behaviour”.

There is some truth in this statement. The GDPR has largely been a response to the failure of legislation to control data privacy issues. The UK Data Protection Act (1998) was deemed, in many respects, to have a series of major shortcomings — as did other EU member state privacy legislation. There was also the issue of Commission wide inconsistency between member states. So, the GDPR was born and ratified quickly by all 27-member states – a miracle in its own right.

So how are contracts likely to be framed?

There has been much dialogue on supervisory body sites around the notion of model clauses. The UK ICO website contains a range of links that have been carefully and studiously followed. The site makes very clear that any model clauses cannot be altered if they are used by organisations.

Eventually, despite searching, it is clear that there are still no model clauses that have been agreed and issued by the EU. The ICO website clearly states:

The GDPR allows for standard contractual clauses from the EU Commission or a supervisory authority (such as the ICO) to be used in contracts between controllers and processors – though none have been drafted so far.” Source: ICO.org

Implementation of the regulation is history — and yet there is still little guidance for companies on these contracts.

However, the site does provide a broad and wide-ranging series of guidance states for processors (we covered these in the last posting).

The guidance is confusing. However, over the next few posts we will attempt to try and provide some of the core elements that processors, both within and outside of the EU should provision for contractually during this transition period.

Given the impact and wide-ranging nature of the regulations it does tend to communicate that the implementation of the detail of the EU legislation is still underway — but is still literally an unfinished symphony (or cacophony).

However, over we will try and rationalise some next steps while the clauses are drafted. In many respects, most companies can take the available guidance – and create compliant contracts. Like most of the posts — we suggest you take legal advice if you are in doubt.

We did say it wasn’t easy.

Thanks, Tony!