Communication is Key??
Photo by jemastock on Vecteezy.com

Communication is Key??

Be sure to join us on our next LinkedIn Live special event, where I’ll be talking DPAs - top tips for legal pros - with Victoria Hordern and Dr. Avishay Klein - signup free here!

One of the key relationships in any organization is the one between the legal team and the privacy function. How do you ensure good communication between these two key functions and make sure everyone is on the same page? Here’s a recap of a recent LinkedIn Live chat between my colleague Dr. Avishay Klein and Daniel Neiger , VP Legal at HiBob .

  1. The privacy function. Privacy is complex, the challenges differ from company to company, and so does the necessity for a privacy specialist. Whether the company decides this function should be filled in-house or externally (or both) there’s no one-size-fits all solution and each company needs to figure out what works best.?
  2. The interface between legal and privacy. Understanding the business, understanding the industry, and understanding the “risk appetite” of the organization is crucial - both for in-house, but especially for external advisors. It’s key for the privacy function to be in sync with the goals of the legal team, but also know where the limitations and “red-lines” are.?
  3. Business vs. regulatory considerations. It can be helpful to create internal policies, procedures and playbooks, but these should be a baseline for how things should operate, and?must not be treated as “gospel”. This is where the privacy pro's experience comes into play. It’s important to leave room for discretion and rely on the experience of the professionals in any given case. The playbook should cover 80% of the scenarios, with 20% left to the discretion of the privacy professional, without the GC needing to get involved.
  4. Setting expectations for the privacy role. The in-house function needs to have deep knowledge of both privacy laws and of the company’s documentation (policies, DPAs, etc.). They need to know where the sensitive areas are, the issues that are business-critical, and they need to walk the tightrope between the regulatory requirements and allowing the business to propel forward. Another crucial skill for the in-house privacy pro is to know when and how to escalate issues to the external consultants, be they DPO or external counsel. The external advisor on the other hand needs to know when to “raise the flag” and say “hey, you should think about that again before you sign off”.?
  5. Cooperation and coordination. GCs have many many risks to manage, privacy being just one of them. One of the best ways to cooperate is to ensure the internal and external functions are in constant contact, getting updates, collaborating, keeping each other informed and up to date. The external function must stay up to date on trends in the market and in the regulation and update the internal teams, including legal and product. External advisors shouldn’t just “drop knowledge” on their client, they should actually take an interest, go the extra mile, and give their client practical tools and solutions as opposed to simply imparting knowledge and “dumping” templates on them.
  6. Building a compliance culture. Some “old school” companies have a long-standing culture of compliance, which is less common in contemporary startups. Hibob is an example of a company that started from day one with a great organizational compliance culture, which keeps maturing and improving as the company grows. The legal team is by no means everyone’s favorite, but over time it has demonstrated that it isn’t a business blocker but an enabler, and this is true for privacy compliance as well. Culture is deep-rooted. When companies IPO or have an M&A event, compliance and privacy become a big ticket item. Adopting this type of “compliance culture” early on (e.g. putting in place “privacy steering committees”) is super helpful, and ensures the process goes smoothly.

Here is the full recording (in Hebrew).?

Cheers,

Avishai

P.S. Did I mention this is part of a series of content I’m putting together leading up to our course, in collaboration with Taylor Wessing , Barnea and Microsoft, starting June 19th? Check out the course details and register here.

#privacy #dataprivacy #DPO #GDPR #CCPA #legal #GC

Florin G.

? Legal Counsel | Chief Privacy Officer | Information Security Governance

6 个月

True, trust could be everything, but it depends on how deep it goes. Trust is built over time, as it takes years, sometimes even generations, to build... and could be lost in a blink of an eye... And while communication (that is, the honest and transparent one) might be a (major) key factor in building trust, the reliability, continuity and dependability of a product/service need also to be considered, as they also have a major say in the trust building process. [my 2 (euro)cents]

要查看或添加评论,请登录

Avishai Ostrin的更多文章

  • LI Live - AI Governance in Practice

    LI Live - AI Governance in Practice

    Last week I had the pleasure of moderating a panel of three very intelligent privacy and AI governance professionals:…

  • There's a New Sheriff in Town!

    There's a New Sheriff in Town!

    Texas's brand new consumer data privacy law - The Texas Data Privacy and Security Act (TDPSA) - comes into force today!…

    5 条评论
  • DPAs - Top Tips for Legal Pros

    DPAs - Top Tips for Legal Pros

    Last week I had a great chat with Victoria Hordern and Dr. Avishay Klein where we gave some top tips about DPAs.

  • Free LinkedIn LIVE - Top DPA Tips for Legal Pros

    Free LinkedIn LIVE - Top DPA Tips for Legal Pros

    Join me today for a free LinkedIn Live to hear Dr. Avishay Klein & Victoria Hordern's DPA top tips for legal pros…

    1 条评论
  • AI Vendor Management

    AI Vendor Management

    This article was written in collaboration with Dr. Avishay Klein and Ran Karmi from Barnea, Jaffa, Lande The adoption…

    10 条评论
  • The American Privacy Rights Act (APRA) – It’s Like Déjà Vu All Over Again!

    The American Privacy Rights Act (APRA) – It’s Like Déjà Vu All Over Again!

    On April 7, 2024, we got a peak at the newest attempt at a US federal privacy law - the American Privacy Rights Act…

    5 条评论
  • How to Draft Great AI Terms

    How to Draft Great AI Terms

    Lawyers are accustomed to using templates and precedents when drafting legal documents. This is especially helpful…

    4 条评论
  • AI Terms - How to Draft Them & What to Look Out For ??

    AI Terms - How to Draft Them & What to Look Out For ??

    Imagine this scenario – you’re a General Counsel at a fast-growing tech company. Sales in the last quarter have been…

    25 条评论
  • Meta's Privacy Fine (in Plain English)

    Meta's Privacy Fine (in Plain English)

    I've read a lot of posts and articles about the €390m fine that was announced yesterday against Meta in Ireland…

    39 条评论
  • DC vs. Marvel and What it Can Teach Us About Data Privacy?

    DC vs. Marvel and What it Can Teach Us About Data Privacy?

    As a kid I loved Superman. How could you not? A man who could transform into a superhero who possesses great powers and…

    38 条评论

社区洞察

其他会员也浏览了