Five Ways To Keep Your BI Team On The Right Side Of GDPR

Erica Lailhacar

There’s been a lot of press coverage on GDPR, spurring organizations to proactively audit their data. But there’s been far less coverage and media noise on how to responsibly manage analytics, business intelligence processes, and reporting on sensitive data. And that’s a problem, especially for users who use BI tools to access sensitive data on a regular basis.

How do you ensure there’s no maverick behavior – even when it’s done without malice, such as importing a database into Excel for a “quick project” – and ensure that everyone manipulating data understands what can and cannot happen and why?

GDPR regulators will be quick to act

Chances are that regulators will be looking to make early examples of companies that breach GDPR requirements, which puts BI teams and analytics activity in the hot seat. How data records are stored and deleted, and how they are encrypted and transferred internationally, will all have to be reassessed. For business intelligence teams, this is even more acute, given the level of sensitive data at their disposal.

It’s a conversation I seem to be having more frequently with customers, so I thought I’d use this blog to outline five key points that BI teams need to consider as we approach the GDPR deadline in May.

1. Conduct training and risk assessment

It may sound obvious, but all BI users need to understand the changes and implications of GDPR with regard to how reports are run, managed, stored, and destroyed. This is not business as usual. Risk-based obligations are spread throughout GDPR. This can be a positive development; low-risk systems shouldn’t need the same level of protection as high-risk systems. But it will mean that companies will have to go through the process of actually doing risk assessments on lines of business and departments that process EU personal data – and that includes BI activity.

2. Classify your data

Make sure your records are clearly labeled, as well as the BI assets such as reports and dashboards, especially if they contain sensitive information. Businesses need a policy in place to make sure sensitive data is handled in keeping with GDPR guidelines, particularly when that data is used for analysis and self-service BI. For example, if an individual triggers the right to be forgotten and requests that the company delete personal information, BI teams must have the confidence to know it’s not been duplicated in users’ personal folders or shared outside the organization.

3. Monitor data usage

Companies will to need to audit and monitor how users are working with data. What analytics are taking place, and who is exporting data to Excel? In other words, you need to be doing BI on your BI system. Your BI team must have sight of any potential for data leaks, regardless of whether it’s deliberate behavior or accidental oversights.

4. Shut down ungoverned silos

Identify all the potential places where data is stored to ensure that there are no ungoverned silos and no one is setting up an ad hoc database for a one-off campaign or copying data for a “quick report.” This is important, because old habits can be hard to break for some people. Anything not governed by the IT department that is subject to cause regulatory exposure need to be shut down. No exceptions.

5. Delete or archive old reports

Reporting tends to pile up, and as users continue to build new reports, it’s important to delete or archive what’s no longer relevant or required. If the data is sensitive, it must be destroyed if necessary and not sit idly in old reports. Having a system in place to manage the process is essential to ensure that nothing slips through the net undetected. While chief data officers and compliance teams may be in the firing line if something goes wrong, ultimately it is the responsibility of the whole business to understand and embrace the changes, ensuring that if any mistakes are made, they don’t turn out to be too costly. BI teams have much greater responsibility for that than ever before, and have an obligation to identify and root out potential weak links, cut away unnecessary systems, and implement BI governance practices to stay on the right side of the law.

Find out more about turning GDPR compliance into a growth opportunity.


About Erica Lailhacar

Erica Lailhacar is analytics go-to-market strategy lead for SAP Global Channels and Platform.