{"id":1048,"date":"2018-07-10T12:09:33","date_gmt":"2018-07-10T10:09:33","guid":{"rendered":"https:\/\/staging.techgdpr.com\/?p=1048"},"modified":"2024-02-22T18:21:36","modified_gmt":"2024-02-22T17:21:36","slug":"gdpr-compliance-its-a-process-not-a-product","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/gdpr-compliance-its-a-process-not-a-product\/","title":{"rendered":"GDPR Compliance: It&#8217;s a Process, Not a Product"},"content":{"rendered":"\n<p><span style=\"font-weight: 400;\"><\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">GDPR compliance mandates can be tricky to interpret for companies handling advanced technology. For leaders in tech, it can be tempting to look at the new rules laid out by Europe\u2019s GDPR and seek a simple, one-size-fits-all solution to the problem of sustained compliance. As any good <\/span><a href=\"https:\/\/www.alienvault.com\/blogs\/security-essentials\/a-ciso-perspective-on-gdpr\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">CISO<\/span><\/a><span style=\"font-weight: 400;\"> will tell you, however, such solutions do not exist. Instead of approaching the GDPR as a box to tick, a hurdle to jump, or even an eloquent privacy agreement with an anxious little \u2018I agree\u2019 button at the bottom, it is best to see GDPR compliance for what it truly is \u2013 a process, not a product. The price of not doing so can prove as much a threat to a company\u2019s competitive advantage as it is to its ability to avoid those 20 million euro fines. <\/span><\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><b>The Current Perception<\/b><\/h4>\n\n\n\n<p><span style=\"font-weight: 400;\">Proof of perception impacting preparedness can be found everywhere. Often presented in the form of regulatory <\/span><a href=\"https:\/\/www.theverge.com\/2018\/5\/25\/17393894\/gdpr-news-websites-down-europe\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">horror stories<\/span><\/a><span style=\"font-weight: 400;\">, it is perhaps little surprise that the rollout of the GDPR has caused many businesses to react with a mix of fear, frustration, and at times, outright confusion. This mindset has already led to bad results. With <\/span><a href=\"https:\/\/www.gartner.com\/newsroom\/id\/3701117\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">half of affected companies<\/span><\/a><span style=\"font-weight: 400;\"> predicted not to be fully GDPR compliant by the end of 2018 and <\/span><a href=\"https:\/\/www.businesswire.com\/news\/home\/20180417005296\/en\/Companies-Prepared-GDPR-Data-Privacy-Compliance-Deadline\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">60% of affected US companies<\/span><\/a><span style=\"font-weight: 400;\"> being unprepared, it is painfully apparent that a fog of reluctance still hangs in the offices and meeting rooms of more than a few vulnerable firms. Companies interpreting new mandates as something that can be cleaned up with a bit of legal paperwork and some new privacy updates is a mistake. In fact, practical measures for integrating the compliance process into daily operations will make businesses more competitive, rather than less. <\/span><\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><b>The Scope of Work \u2013 Beyond Only Tech<\/b><\/h4>\n\n\n\n<p><span style=\"font-weight: 400;\">Whether collecting user consent, <\/span><a href=\"https:\/\/techgdpr.com\/consultancy\/appointing-a-data-protection-officer\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">appointing a DPO<\/span><\/a><span style=\"font-weight: 400;\">, or identifying sensitive data, this consultancy recognizes that each company has different needs in terms of GDPR compliance, and each case involves its own unique scope of work that must be identified. GDPR compliance is about tech, but it\u2019s not all about tech. When we first speak with companies, we are looking to understand several other important factors before diving into their use of technology. We initially need to map out the scope of their compliance issues. Some companies are well on their way, but other companies have problems that go beyond the GDPR. In these cases, going through the compliance process can help with planning projects, communicating across teams, and measuring long-term success. If you can measure key performance indicators, you can be GDPR compliant.<\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">Regardless of company size, sector or current compliance needs, these are the four primary questions we ask ourselves as we begin providing support to the compliance processes of the companies we work with: <\/span><\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><b><i>What has the company done before in service to data protection? <\/i><\/b><\/h5>\n\n\n\n<p><span style=\"font-weight: 400;\">Does the company have methods in place to secure the privacy of their customers, or is data being collected without a consistent plan for what will be done with it later? Has the company considered the human, as well as the financial cost of data breaches? Do they have team members who understand, through lived experience, the security concerns of their customers? The more complete the answers to these questions, the more beneficial any risk assessment will be to the company.<\/span><\/p>\n\n\n<div class=\"wp-block-image is-style-rounded\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-03-1024x439.png\" alt=\"abstract image created by Jesse van Mouwerik for TechGDPR\"\/><\/figure>\n<\/div>\n\n\n<p><\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><b><i>Is the company\u2019s leadership willing and able to make necessary changes?<\/i><\/b><\/h5>\n\n\n\n<p><span style=\"font-weight: 400;\">Data protection may require a change in business practices, and some team leads may not be at ease with the pace or direction of such changes. Data protection may necessitate changing vendors, hiring a Data Protection Officer, or spending time on training essential staff to meet new challenges. All of this costs time and money, which must be accounted for. Someone with the authority to devote resources to compliance needs to be willing, or else there will be significant delays to the compliance process. <\/span><\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><b><i>What is the company\u2019s management structure like?<\/i><\/b><\/h5>\n\n\n\n<p><span style=\"font-weight: 400;\">What sort of project management processes have been adopted? Are there any processes in place to deal with time-sensitive issues? What are they? When employees spot problems, is there a defined process for reporting their concerns? How does the team usually respond? &nbsp;Companies that ignore critical vulnerability reports may be in for a shock when they read about the responsibilities of a Data Protection Officer, including being a point of contact for Data Protection Authorities that must be notified about breaches even when there is no customer impact. <\/span><\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><b><i>What role should software play?<\/i><\/b><\/h5>\n\n\n\n<p><span style=\"font-weight: 400;\">Many companies may be familiar with a particular kind of software that they would like to use in order to keep their compliance protocols consistently monitored, maintained, and documented. &nbsp;For these purposes, software can be fantastic. It can scan large systems of data, support project management goals, assist in data-mapping, and streamline certain administrative tasks. That being said, even the best programs cannot train your people, design your products, or configure your data collection practices to automate subject access requests. Here, human-led procedural oversight must be instituted. Software can enhance well-established compliance practices \u2013 not replace them.<\/span><\/p>\n\n\n<div class=\"wp-block-image is-style-rounded\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-13-1024x439.png\" alt=\"abstract image created by Jesse van Mouwerik for TechGDPR\"\/><\/figure>\n<\/div>\n\n\n<p><\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><b>Continuing the Process<\/b><\/h4>\n\n\n\n<p><span style=\"font-weight: 400;\">When it comes to GDPR compliance, perhaps the easiest thing to lose sight of is the fact that just like technology, the law is constantly evolving in response to people\u2019s wants and needs. &nbsp;Keeping a vigilant eye on existing procedures and being transparent to customers about data usage is something that any capable company should already be doing \u2013 even without the GDPR. But more must be done to maintain compliance through an ongoing process. As technologies reliant on <\/span><a href=\"https:\/\/coincentral.com\/can-blockchain-rescue-our-identity-from-the-digital-abyss\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Blockchain<\/span><\/a><span style=\"font-weight: 400;\"> or <\/span><a href=\"https:\/\/techgdpr.com\/blog\/gdprs-big-issue-with-big-data\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Big Data <\/span><\/a><span style=\"font-weight: 400;\">continue to develop, so too must our understanding of how to implement compliance within new platforms and services. <\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">At present, we must relegate thoughts of data protection as a one-time event to the cobwebbed catacombs of a pre-GDPR world. <\/span><a href=\"https:\/\/www.networkworld.com\/article\/966000\/while-no-one-was-looking-california-passed-its-own-gdpr.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">New laws<\/span><\/a><span style=\"font-weight: 400;\"> outside of Europe demonstrate that the public demand for privacy isn\u2019t going anywhere. Companies that rise to the occasion and recognize GDPR compliance as an ongoing process in service to their customers rather than a patchwork appeasement product for regulators will have everything to gain. It appears no agree button can offer that yet. <\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">To stay up to date on how GDPR affects technology, <\/span><strong><a href=\"https:\/\/twitter.com\/techgdpr\" target=\"_blank\" rel=\"noopener\">follow TechGDPR on Twitter<\/a><\/strong>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>GDPR compliance mandates can be tricky to interpret for companies handling advanced technology. For leaders in tech, it can be tempting to look at the new rules laid out by Europe\u2019s GDPR and seek a simple, one-size-fits-all solution to the problem of sustained compliance. As any good CISO will tell you, however, such solutions do [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":1049,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[14],"tags":[],"class_list":["post-1048","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-dpo"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-12.png",1408,604,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-12-150x150.png",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-12-300x129.png",300,129,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-12-768x329.png",640,274,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-12-1024x439.png",640,274,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-12.png",1408,604,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-12.png",1408,604,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-12.png",200,86,false]},"post_excerpt_stackable":"<p>GDPR compliance mandates can be tricky to interpret for companies handling advanced technology. For leaders in tech, it can be tempting to look at the new rules laid out by Europe\u2019s GDPR and seek a simple, one-size-fits-all solution to the problem of sustained compliance. As any good CISO will tell you, however, such solutions do not exist. Instead of approaching the GDPR as a box to tick, a hurdle to jump, or even an eloquent privacy agreement with an anxious little \u2018I agree\u2019 button at the bottom, it is best to see GDPR compliance for what it truly is \u2013&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/dpo\/\" rel=\"category tag\">DPO<\/a>","author_info":{"name":"Jesse van Mouwerik","url":"https:\/\/techgdpr.com\/blog\/author\/jesse\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-12.png",1408,604,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-12-150x150.png",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-12-300x129.png",300,129,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-12-768x329.png",640,274,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-12-1024x439.png",640,274,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-12.png",1408,604,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-12.png",1408,604,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-12.png",200,86,false]},"post_excerpt_stackable_v2":"<p>GDPR compliance mandates can be tricky to interpret for companies handling advanced technology. For leaders in tech, it can be tempting to look at the new rules laid out by Europe\u2019s GDPR and seek a simple, one-size-fits-all solution to the problem of sustained compliance. As any good CISO will tell you, however, such solutions do not exist. Instead of approaching the GDPR as a box to tick, a hurdle to jump, or even an eloquent privacy agreement with an anxious little \u2018I agree\u2019 button at the bottom, it is best to see GDPR compliance for what it truly is \u2013&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/dpo\/\" rel=\"category tag\">DPO<\/a>","author_info_v2":{"name":"Jesse van Mouwerik","url":"https:\/\/techgdpr.com\/blog\/author\/jesse\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>GDPR Compliance: It&#039;s a Process, Not a Product - TechGDPR<\/title>\n<meta name=\"description\" content=\"Written by Karen Reilly and Jesse Van Mouwerik. Whether collecting user consent, appointing a DPO, or identifying sensitive data, each company has different needs in terms of GDPR compliance, and each case involves its own unique scope of work that must be identified by professionals.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/gdpr-compliance-its-a-process-not-a-product\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"GDPR Compliance: It&#039;s a Process, Not a Product - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"Written by Karen Reilly and Jesse Van Mouwerik. Whether collecting user consent, appointing a DPO, or identifying sensitive data, each company has different needs in terms of GDPR compliance, and each case involves its own unique scope of work that must be identified by professionals.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/gdpr-compliance-its-a-process-not-a-product\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2018-07-10T10:09:33+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-02-22T17:21:36+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-12.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1408\" \/>\n\t<meta property=\"og:image:height\" content=\"604\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Jesse van Mouwerik\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jesse van Mouwerik\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-compliance-its-a-process-not-a-product\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-compliance-its-a-process-not-a-product\\\/\"},\"author\":{\"name\":\"Jesse van Mouwerik\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/ed52e9335eb8595eb0f8e79e6f65ffb1\"},\"headline\":\"GDPR Compliance: It&#8217;s a Process, Not a Product\",\"datePublished\":\"2018-07-10T10:09:33+00:00\",\"dateModified\":\"2024-02-22T17:21:36+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-compliance-its-a-process-not-a-product\\\/\"},\"wordCount\":1051,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-compliance-its-a-process-not-a-product\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/07\\\/TechGDPR-Main-Graphics-12.png\",\"articleSection\":[\"DPO\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-compliance-its-a-process-not-a-product\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-compliance-its-a-process-not-a-product\\\/\",\"name\":\"GDPR Compliance: It's a Process, Not a Product - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-compliance-its-a-process-not-a-product\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-compliance-its-a-process-not-a-product\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/07\\\/TechGDPR-Main-Graphics-12.png\",\"datePublished\":\"2018-07-10T10:09:33+00:00\",\"dateModified\":\"2024-02-22T17:21:36+00:00\",\"description\":\"Written by Karen Reilly and Jesse Van Mouwerik. Whether collecting user consent, appointing a DPO, or identifying sensitive data, each company has different needs in terms of GDPR compliance, and each case involves its own unique scope of work that must be identified by professionals.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-compliance-its-a-process-not-a-product\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-compliance-its-a-process-not-a-product\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-compliance-its-a-process-not-a-product\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/07\\\/TechGDPR-Main-Graphics-12.png\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/07\\\/TechGDPR-Main-Graphics-12.png\",\"width\":1408,\"height\":604},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-compliance-its-a-process-not-a-product\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"GDPR Compliance: It&#8217;s a Process, Not a Product\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/ed52e9335eb8595eb0f8e79e6f65ffb1\",\"name\":\"Jesse van Mouwerik\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1e7fb7b2990004e218286bf8d448bf9b74ab57af9fe19f72ec2b80f7f7237108?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1e7fb7b2990004e218286bf8d448bf9b74ab57af9fe19f72ec2b80f7f7237108?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1e7fb7b2990004e218286bf8d448bf9b74ab57af9fe19f72ec2b80f7f7237108?s=96&d=mm&r=g\",\"caption\":\"Jesse van Mouwerik\"},\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/jesse\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"GDPR Compliance: It's a Process, Not a Product - TechGDPR","description":"Written by Karen Reilly and Jesse Van Mouwerik. Whether collecting user consent, appointing a DPO, or identifying sensitive data, each company has different needs in terms of GDPR compliance, and each case involves its own unique scope of work that must be identified by professionals.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/gdpr-compliance-its-a-process-not-a-product\/","og_locale":"en_US","og_type":"article","og_title":"GDPR Compliance: It's a Process, Not a Product - TechGDPR","og_description":"Written by Karen Reilly and Jesse Van Mouwerik. Whether collecting user consent, appointing a DPO, or identifying sensitive data, each company has different needs in terms of GDPR compliance, and each case involves its own unique scope of work that must be identified by professionals.","og_url":"https:\/\/techgdpr.com\/blog\/gdpr-compliance-its-a-process-not-a-product\/","og_site_name":"TechGDPR","article_published_time":"2018-07-10T10:09:33+00:00","article_modified_time":"2024-02-22T17:21:36+00:00","og_image":[{"width":1408,"height":604,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-12.png","type":"image\/png"}],"author":"Jesse van Mouwerik","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Jesse van Mouwerik","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/gdpr-compliance-its-a-process-not-a-product\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/gdpr-compliance-its-a-process-not-a-product\/"},"author":{"name":"Jesse van Mouwerik","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/ed52e9335eb8595eb0f8e79e6f65ffb1"},"headline":"GDPR Compliance: It&#8217;s a Process, Not a Product","datePublished":"2018-07-10T10:09:33+00:00","dateModified":"2024-02-22T17:21:36+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/gdpr-compliance-its-a-process-not-a-product\/"},"wordCount":1051,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/gdpr-compliance-its-a-process-not-a-product\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-12.png","articleSection":["DPO"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/gdpr-compliance-its-a-process-not-a-product\/","url":"https:\/\/techgdpr.com\/blog\/gdpr-compliance-its-a-process-not-a-product\/","name":"GDPR Compliance: It's a Process, Not a Product - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/gdpr-compliance-its-a-process-not-a-product\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/gdpr-compliance-its-a-process-not-a-product\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-12.png","datePublished":"2018-07-10T10:09:33+00:00","dateModified":"2024-02-22T17:21:36+00:00","description":"Written by Karen Reilly and Jesse Van Mouwerik. Whether collecting user consent, appointing a DPO, or identifying sensitive data, each company has different needs in terms of GDPR compliance, and each case involves its own unique scope of work that must be identified by professionals.","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/gdpr-compliance-its-a-process-not-a-product\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/gdpr-compliance-its-a-process-not-a-product\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/gdpr-compliance-its-a-process-not-a-product\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-12.png","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2018\/07\/TechGDPR-Main-Graphics-12.png","width":1408,"height":604},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/gdpr-compliance-its-a-process-not-a-product\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"GDPR Compliance: It&#8217;s a Process, Not a Product"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/ed52e9335eb8595eb0f8e79e6f65ffb1","name":"Jesse van Mouwerik","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1e7fb7b2990004e218286bf8d448bf9b74ab57af9fe19f72ec2b80f7f7237108?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1e7fb7b2990004e218286bf8d448bf9b74ab57af9fe19f72ec2b80f7f7237108?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1e7fb7b2990004e218286bf8d448bf9b74ab57af9fe19f72ec2b80f7f7237108?s=96&d=mm&r=g","caption":"Jesse van Mouwerik"},"url":"https:\/\/techgdpr.com\/blog\/author\/jesse\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/1048","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=1048"}],"version-history":[{"count":16,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/1048\/revisions"}],"predecessor-version":[{"id":8169,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/1048\/revisions\/8169"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/1049"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=1048"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=1048"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=1048"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}