• Imprint
  • Privacy
    • Privacy statement (CA)
    • Cookie policy (CA)
    • Privacy statement (US)
    • Cookie Policy (US)
    • Disclaimer
    • Cookie policy (EU)
    • Privacy statement (EU)
  • German: e-3.de
e3zine - Independent SAP Community Webzine
  • Home
  • Business
      • Compliance
      • Customer Relationship Management
      • Digital Transformation
      • E-Commerce
      • Finance
      • Human Resources
      • License and Price
      • Logistics
      • Management
      • Security
      Big Data • Blog • Digital Transformation • Hana

      S/4 Transformation: Data Integrity Is the Biggest Risk

      2023-06-23
      Blog • Human Resources • Management

      Germany’s Most Popular Employers

      2023-05-19
      Business • SAP Community

      Digital Enterprise Show 2023

      2023-05-03
      Blog • Management

      Mahabharata, a Major Indian Epic

      2023-04-03
      Blog • Customer Relationship Management

      Walldorf, Germany Is the Center of The ERP Universe

      2023-03-05
      Blog • Digital Transformation

      Paperless, Turbulent, Hybrid, but Successful

      2023-02-05
  • Technology
      • Artificial Intelligence
      • Big Data
      • Blockchain
      • Cloud
      • DevOps
      • Hana
      • Internet of Things
      • Leonardo
      • NetWeaver and SolMan
      • Open Source
      • SOH and S/4
      Blog • Open Source

      Benefit from Linux Security

      2023-07-14
      Blog • Open Source

      Migration or Innovation

      2023-07-04
      Big Data • Blog • Digital Transformation • Hana

      S/4 Transformation: Data Integrity Is the Biggest Risk

      2023-06-23
      Blog • Cloud • Open Source

      The Modernization Challenge

      2023-06-13
      DevOps

      Valencia City Council Pioneers e-Government with Red Hat

      2023-05-31
      Blog • Hana

      Controlling SAP Hana Data Sprawl

      2023-05-16
  • Scene
      • Editor-in-Chief
      • Last and Least
      • Nomen Nescio
      • SAP Community
      Blog • Editor-in-Chief

      ERP Ideals 2025

      2023-06-29
      Blog • Last and Least

      Mountaineer

      2023-06-26
      Blog • Editor-in-Chief

      BTP at The Crossroads

      2023-06-22
      Blog • SAP Community

      Customer Satisfaction

      2023-06-21
      Blog • Nomen Nescio

      Composable ERP

      2023-06-19
      Blog • Editor-in-Chief

      ERP Prototypes

      2023-06-16
  • Webinars
  • Community
  • About
  • Contact Us
e3zine - Independent SAP Community Webzine
  • Home
  • Business
      • Compliance
      • Customer Relationship Management
      • Digital Transformation
      • E-Commerce
      • Finance
      • Human Resources
      • License and Price
      • Logistics
      • Management
      • Security
      Big Data • Blog • Digital Transformation • Hana

      S/4 Transformation: Data Integrity Is the Biggest Risk

      2023-06-23
      Blog • Human Resources • Management

      Germany’s Most Popular Employers

      2023-05-19
      Business • SAP Community

      Digital Enterprise Show 2023

      2023-05-03
      Blog • Management

      Mahabharata, a Major Indian Epic

      2023-04-03
      Blog • Customer Relationship Management

      Walldorf, Germany Is the Center of The ERP Universe

      2023-03-05
      Blog • Digital Transformation

      Paperless, Turbulent, Hybrid, but Successful

      2023-02-05
  • Technology
      • Artificial Intelligence
      • Big Data
      • Blockchain
      • Cloud
      • DevOps
      • Hana
      • Internet of Things
      • Leonardo
      • NetWeaver and SolMan
      • Open Source
      • SOH and S/4
      Blog • Open Source

      Benefit from Linux Security

      2023-07-14
      Blog • Open Source

      Migration or Innovation

      2023-07-04
      Big Data • Blog • Digital Transformation • Hana

      S/4 Transformation: Data Integrity Is the Biggest Risk

      2023-06-23
      Blog • Cloud • Open Source

      The Modernization Challenge

      2023-06-13
      DevOps

      Valencia City Council Pioneers e-Government with Red Hat

      2023-05-31
      Blog • Hana

      Controlling SAP Hana Data Sprawl

      2023-05-16
  • Scene
      • Editor-in-Chief
      • Last and Least
      • Nomen Nescio
      • SAP Community
      Blog • Editor-in-Chief

      ERP Ideals 2025

      2023-06-29
      Blog • Last and Least

      Mountaineer

      2023-06-26
      Blog • Editor-in-Chief

      BTP at The Crossroads

      2023-06-22
      Blog • SAP Community

      Customer Satisfaction

      2023-06-21
      Blog • Nomen Nescio

      Composable ERP

      2023-06-19
      Blog • Editor-in-Chief

      ERP Prototypes

      2023-06-16
  • Webinars
  • Community
  • About
  • Contact Us
e3zine - Independent SAP Community Webzine
  • Home
  • Business
      • Compliance
      • Customer Relationship Management
      • Digital Transformation
      • E-Commerce
      • Finance
      • Human Resources
      • License and Price
      • Logistics
      • Management
      • Security
      Big Data • Blog • Digital Transformation • Hana

      S/4 Transformation: Data Integrity Is the Biggest Risk

      2023-06-23
      Blog • Human Resources • Management

      Germany’s Most Popular Employers

      2023-05-19
      Business • SAP Community

      Digital Enterprise Show 2023

      2023-05-03
      Blog • Management

      Mahabharata, a Major Indian Epic

      2023-04-03
      Blog • Customer Relationship Management

      Walldorf, Germany Is the Center of The ERP Universe

      2023-03-05
      Blog • Digital Transformation

      Paperless, Turbulent, Hybrid, but Successful

      2023-02-05
  • Technology
      • Artificial Intelligence
      • Big Data
      • Blockchain
      • Cloud
      • DevOps
      • Hana
      • Internet of Things
      • Leonardo
      • NetWeaver and SolMan
      • Open Source
      • SOH and S/4
      Blog • Open Source

      Benefit from Linux Security

      2023-07-14
      Blog • Open Source

      Migration or Innovation

      2023-07-04
      Big Data • Blog • Digital Transformation • Hana

      S/4 Transformation: Data Integrity Is the Biggest Risk

      2023-06-23
      Blog • Cloud • Open Source

      The Modernization Challenge

      2023-06-13
      DevOps

      Valencia City Council Pioneers e-Government with Red Hat

      2023-05-31
      Blog • Hana

      Controlling SAP Hana Data Sprawl

      2023-05-16
  • Scene
      • Editor-in-Chief
      • Last and Least
      • Nomen Nescio
      • SAP Community
      Blog • Editor-in-Chief

      ERP Ideals 2025

      2023-06-29
      Blog • Last and Least

      Mountaineer

      2023-06-26
      Blog • Editor-in-Chief

      BTP at The Crossroads

      2023-06-22
      Blog • SAP Community

      Customer Satisfaction

      2023-06-21
      Blog • Nomen Nescio

      Composable ERP

      2023-06-19
      Blog • Editor-in-Chief

      ERP Prototypes

      2023-06-16
  • Webinars
  • Community
  • About
  • Contact Us
With the multitude of options available, finding the right way to GDPR compliance can be tricky. [shutterstock: 335819621, Ilya Images]
[shutterstock: 335819621, Ilya Images]
Roland Bullivant, Silwood Technology
Add Comment
    Share This!
    FacebookTwitterLinkedInEmailWhatsApp
Blog • Compliance

Eight Ways To Discover Personal Data For GDPR Compliance

2018-06-12
Add Comment
Roland Bullivant, Silwood Technology
As many companies around the globe are struggling with how to meet the new GDPR requirement, we are all receiving a flurry of opt-in emails asking for permission (consent) to continue to process Personal Data.

Unfortunately, one of the major difficulties encountered by organisations engaged in the consent process due to GDPR is to complete the seemingly simple task of locating and categorising Personal Data held across the enterprise. Often this is referred to as an Information Audit or Data Readiness exercise. For those who have been using a large ERP or CRM application packages to store and process data, meeting this challenge is even more acute.

Silwood Technology recently conducted research into five of the largest and most widely used information application packages. This revealed that the job facing organizations who are still trying to locate Personal Data in the coming weeks is significant. In SAP there are more than 900,000 fields, 140,000 in JD Edwards and 100,000 in Microsoft Dynamics AX 2012 that may (or may not) contain personal information that requires detection and risk assessment. In in short, businesses that are not well-advanced in data discovery or are undertaking manual discovery processes will not be ready on time for GDPR.

Many organisations are addressing the Personal Data challenge through software such as Information or Data Catalogue solutions within their overall Governance or Compliance programme, which often incorporate some form of scanner or crawler that connects to many sources, identifies the metadata and imports it automatically. Others may be using spreadsheet or more home-grown solutions to try to record Personal Data locations and understand how data flows through their organisation.

These solutions can be very effective for some IT systems. However, they will not be as successful for organisations running enterprise CRM or ERP applications from SAP, Oracle, Salesforce, Microsoft or other large application packages unless they incorporate specialist discovery software designed for the task. This is due to the size, complexity and level of customisation of the underlying data landscape of these systems as evidenced by Silwood Technology’s research.

Here we explore the eight main strategies available for organisations identifying Personal Data when starting the GDPR compliance process. Unfortunately, many are extremely time consuming and rely on extensive manual interrogation of databases and systems, a luxury that is not available to any enterprise that is not well advanced in the process.

1. Looking for documentation

Looking for documentation may seem a natural first port of call when trying to understand find Personal Data items in an application. However, even if the data models do exist in this static way, they will be of only limited use in anything but smaller, perhaps home-grown applications with simple data structures.

For those with large scale ERP and CRM packages, the task of navigating documentation to find individual tables and attributes from amongst thousands will be a significant challenge and of course any useful information cannot be shared easily with other tools as re-keying will be required.

2. Manual investigation

This typically involves someone tasked with scouring the relational database (RDBMS) system catalogue for any information which might provide clues as to what data the tables contain, what attributes and fields they include and crucially the relationships between tables.

This is a perfectly acceptable approach for small database systems, where a package is limited in scope or has been developed in-house, but is very labour-intensive in larger systems with a great many tables which do not have useful business names or descriptions.

3. Turning to application or technical specialists

Specialists are likely to have the most familiarity with the application and its underlying data model. They are also most likely to have access to any technical tools which are provided by software vendors which can be used in an attempt to locate the information required. However, their knowledge of the business context of a request for Personal Data may not necessarily be complete, and such specialists are often in very short supply and busy.

4. Hiring external consultants

Another common approach is to engage external consultants. Obviously, they may provide an expert resource, however there can be a significant cost as well as time to familiarise themselves with the data landscape and its customisations. In addition, this can contribute to lower in-house knowledge levels in the long term.

5.  Metadata driven software approach

Using software to identify the metadata associated with Personal Data across an organisation’s IT ecosystem can make the discovery process considerably faster and more effective. Many data catalogue and governance products have facilities to connect to source systems and import their metadata directly so that it can be investigated more fully.  Automating this process reduces the opportunity for error as there is only very limited manual intervention.

This approach does not work for large CRM and ERP systems because of the size, complexity and level of customisation of their data landscapes. There are a few advanced self-service metadata discovery tools, such as Silwood Technology’s Safyr, which provide a view into their metadata and allow users to navigate and search for Personal Data attributes and subset them into appropriate categories. That information can then be shared with Data Catalogue or Governance products or even used with Excel.

Metadata-based solutions can accelerate Personal Data discovery considerably, especially when compared to entirely manual or semi-automated processes.

6. Internet search

Using the internet to locate Personal Data attributes is only really of any value when the data models are in a format that can be published either by vendors or by customers. It would not make much sense to publicly exhibit data models of one’s own in house developed system.

However, it is possible to find metadata definitions for example for well-known social media platforms and occasionally data models from popular ERP and CRM packages which might point you in the right direction of the Personal Data you are seeking. This is often seen as a viable, low cost option, but is labour intensive and also questionable in accuracy terms.

There are also risks. The published information is unlikely to represent the system as implemented by the seeker either through version differences or individual customisations. In addition, it is often necessary to ask a technical specialist to interpret the model and augment it with relevant information from the application itself.

7. Best guess and hypothesis testing

When faced with the problem of Personal Data discovery, many companies use guesswork or hypothesis testing methods to try to find tables and attributes they need. They rely on data observation, insight and on trying to find an appropriate start point from which to launch a search – a strategy that can be frustrating, time consuming and potentially inaccurate.

8. Turning to software vendors

Data Modelling tools offer a good solution for finding Personal Data based on their ability to reverse engineer RDBMS and create a data model from the tables, fields and relationships they find. From there an analyst can try to find the items needed for GDPR.

Data Profiling software can also be useful as it provides the ability to look at data formats to determine if they are likely to contain Personal Data. Sometimes this uses a form of machine learning or other analysis techniques to surface what may be relevant.

ERP and CRM package vendors do have tools which can be used by technical specialists for more traditional database and metadata tasks.

However, the particular challenge of trying to locate Personal Data in large packaged CRM and ERP applications is not adequately met using these approaches.  This is because of the lack of meaningful metadata in their database schema, the size and complexity of the model and the numbers of attributes to be investigated.

GDPR is not a one-time event

For large organisations really struggling to find Personal Data for GDPR, it is too late to employ consultants or redirect staff away from their normal tasks to get through the work. Instead, it is time to look to software tools to automate as much of the Personal Data discovery work as possible.

Of course, Personal Data discovery is just one step towards GDPR compliance, however it is a vital one. It is also worth remembering that GDPR compliance is not a one-time event, maintaining compliance will be an essential business process in the future. A manual, intensive approach today may simply delay the inevitable data reckoning – can you afford to ignore the future?

Links:

Silwood Technology (external)

Source:
Silwood Technology

You may also like

Blog

SAP Startup Spotlight Series: goFlux

2023-08-22
Blog

SAP Startup Spotlight Series: Mention Me

2023-08-08
Blog

SAP Startup Spotlight Series: Velou

2023-08-08
Blog

SAP Startup Spotlight Series: Soley

2023-07-25
Blog • Open Source

Benefit from Linux Security

2023-07-14
Blog • Open Source

Migration or Innovation

2023-07-04

About the author

View All Posts

Roland Bullivant, Silwood Technology

Roland Bullivant is Sales and Marketing Director at Silwood Technology.

Add Comment

Click here to post a comment

Cancel reply

GDPR & Cloud Act Might Mean The Cloud Exit for ERP/ECC 6.0 & S/4
GDPR: The Time Has Run Out!
Comment
    Share This!
    FacebookTwitterLinkedInEmailWhatsApp
Sign up for e3zine´s biweekly newsbites

Please do not use administrative mail adresses like "noreply@..", "admin@.." or similar as these may get blocked for security reasons.

We use rapidmail for dispatching our newsletter. By signing up, you agree that the data you have entered will be transmitted to rapidmail. Please take note of their terms and conditions and privacy policy.termsandconditions.

Copyright © 2021 e3zine.com, All rights reserved.

Our mailing address is:
e3zine.com
Griesgasse 31
Salzburg 5020
Austria

Thanks for subscribing!
To make sure it is you we have sent you an confirmation email. Please klick on the link inside that mail to finish your subscription.
Back to homepage
Copyright © 2021 e3zine.com, All rights reserved.

Our mailing address is:
e3zine.com
Griesgasse 31
Salzburg 5020
Austria

Our Authors
GDPR: The Time Has Run Out!

© Copyright by B4Bmedia.net AG, Freilassing (Germany)
  • Twitter
  • Facebook
  • LinkedIn
  • Mail
  • Imprint
  • Privacy
    • Privacy statement (CA)
    • Cookie policy (CA)
    • Privacy statement (US)
    • Cookie Policy (US)
    • Disclaimer
    • Cookie policy (EU)
    • Privacy statement (EU)

Wir verwenden Cookies, um Ihnen die beste Erfahrung auf unserer Website zu bieten Sie können mehr darüber erfahren, welche Cookies wir verwenden oder diese in den ausschalten.

e3zine - Independent SAP Community Webzine
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

If you disable this cookie, we will not be able to save your preferences. This means that every time you visit this website you will need to enable or disable cookies again.