GDPR and Business Process Management (BPM)
Your processes need to be understood before they can be improved. Model activities, exchanges and responsibilities to make friction points visible. Develop a BPM approach that supports dialogue between business teams and those responsible for transforming how the organisation works.
- Duration
- 3 days 21 hours
- Code
- GDPR01FR Code
Presentation
The General Data Protection Regulation (GDPR) is a European regulation through which the European Parliament, the Council of the European Union and the European Commission seek to strengthen and standardise data protection across EU countries, while also controlling transfers outside the Union. Its main objectives are to give citizens control over their personal information and unify the regulatory framework for multinational businesses.
Adopted in April 2016, it will enter into force on 25 May 2018 after a two-year transition period. Unlike directives, it does not need to be incorporated into national legislation and is directly applicable.
The GDPR provides for penalties of up to €20 million or 4% of annual worldwide turnover, whichever is higher.
The GDPR stipulates that companies must appoint a Data Protection Officer (DPO), a person responsible for data protection who must not also be the Chief Information Officer (CIO) and is not the person accountable for the risk incurred.
This European regulation affects all companies serving customers and users located in the EU, even temporarily. What matters is not where a company is headquartered, but the personal data it processes.
Objectives
This course aims to help you:
- understand the impact and value of a process-based view in the context of the European GDPR;
- understand how Business Process Management (BPM) contributes to protecting companies' employee data;
- discover the BPMN (Business Process Model & Notation) standard for describing processes in a structured, effective way;
- learn a methodology for introducing a process-based approach within a company, implemented in stages to reflect the complexity of business environments;
- understand the relationship between GDPR and cybersecurity.
Program
Module 1: GDPR
- Overview of the regulation.
- New requirements for businesses.
- Examples of GDPR-related processes:
- Acquiring, accessing and maintaining personal data.
- Routine GDPR processing: responding to access requests and deleting data on request.
- Exceptional GDPR processing: notifications of irregularities.
Module 2: How a BPM perspective supports GDPR implementation
- GDPR as an organisational and process challenge.
- What is BPM?
- Classifying business processes.
Module 3: Process modelling
- Approaching process modelling.
- Introduction to Signavio™ Quick Model.
- Introduction to Bizagi™ Modeler.
- Basic components of BPMN 2.0.
Workshop: simple modelling of a GDPR process. The workshop can use the process included in the course or a process requested by participants.
Module 4: Phased implementation
- Auditing the current GDPR situation.
- Simple modelling of GDPR processes.
- Advanced modelling of GDPR processes.
- Executing processes.
- Monitoring processes with Business Activity Monitoring (BAM).
Workshop: considering implementation in a practical case and identifying the resulting deliverables. The workshop can use the process included in the course or a process requested by participants.
Module 5: GDPR and cybersecurity
- Cybersecurity and its impact on BPM.
- Types of cybersecurity processes:
- operational processes, such as penetration testing campaigns;
- governance processes, such as reviewing a risk management tool.
Workshop: considering cybersecurity measures needed to ensure GDPR compliance.
Audience
This course is for anyone involved in processing data:
- data controllers;
- CIOs and CISOs;
- project managers;
- more broadly, anyone involved in personal data processing, including legal and HR professionals.
Prerequisites
No prerequisites are required for this course.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
fr
en