With data becoming the new cyber currency and data-gathering activities accelerating, companies are expected to demonstrate a commitment to accountability, lawfulness, transparency, and data protection. The rising tide of regulatory compliance and expansion of data across the extended enterprise requires organizations to re-engineer their business practices, redesign their data privacy policies and practices, and rearchitect their applications and backend infrastructure.
CohnReznick takes a strategic approach to helping organizations implement a comprehensive data privacy program. Using a proven data privacy framework, we help organizations establish an effective governance structure, improve policies and regulatory awareness, enhance data management practices, and devise a robust privacy strategy and roadmap. A holistic privacy management program can give organizations a differentiating, competitive advantage.
Policy & regulation awareness
CohnReznick helps organizations assess the validity of the mechanisms and resources in place to manage privacy within the organization. We do this by helping identify applicable laws, regulations, and gaps.
CohnReznick helps companies with the complete data governance lifecycle by conducting a comprehensive and accurate inventory of its data assets with appropriate classification, determining the different levels of access, implementing protection mechanisms, documenting retention requirements, and establishing secure disposal practices of the data and the assets across the organization’s environment.
Privacy strategy architecture and development
We help design an applicable privacy roadmap tailored to the company’s ecosystem to make certain the organization’s privacy strategy allows the company to continuously measure and improve operations and ensure continued adherence to changing privacy policies. It is imperative that the privacy strategy and architecture are well-defined and documented, and that policies, standards, and procedures are well-documented and communicated.
CohnReznick helps companies develop privacy policies and procedures in alignment with privacy laws and regulations.
Many principles affect the operationalizing of a comprehensive privacy program. CohnReznick helps companies monitor compliance according to internal and third-party privacy policies. We help put a process in place for how to respond to requests from individuals (rights of “to be informed,” “access,” “rectification,” “erasure,” “stop processing,” and “data portability”) and conduct privacy awareness campaigns and training.
We help organizations ensure that privacy requirements are embedded in the organization’s information security policies and procedures, and that there is a process in place to respond to privacy-related data breaches.
Our privacy lifecycle framework helps companies develop their privacy programs through six strategic phases.
Select a stage to learn more.
GovernanceEstablish the overarching organizational roles and responsibilities to help ensure the appropriate governance is in place to manage privacy within the organization.
Policy and regulation awarenessEnsure the organization understands and plans to meet applicable laws, regulations, and other requirements related to privacy.
Data managementEnsure that the company has a complete and accurate inventory of data assets, that it grants access to personal data only to authorized people, that the data is used, ethically, only for the purposes in which it has been collected, and that the data is secure.
Strategy and architectureDefine and document privacy strategy, solutions architecture, and roadmap. The policies, standards, and procedures should also be defined, documented, published, and maintained.
Prioritize and implementImplement the privacy roadmap, solutions architecture, policies, standards, and procedures in a timely manner within organizational, technical, resource, and budgetary constraints.
OperationsRespond to privacy-related data breaches and monitor compliance with internal and third-party privacy policies while also responding to requests from individuals (rights of “to be informed,” “access,” “rectification,” “forgotten,” “stop processing,” and “data portability”).
Continuous improvementContinuously measure and improve privacy operations to help ensure continued adherence to changing privacy requirements.
Webinar: California Consumer Privacy Act (CCPA) Update
InsightThe CCPA requires ‘reasonable security.’ What exactly does that mean?Shahryar ShaghaghiOn Jan. 1, 2020, California consumers will wake up to a new era of expansive data privacy rights. Businesses that serve them will more likely greet the new year with compliance headaches induced by the California Consumer Privacy Act of 2018, or CCPA.
Press ReleaseCohnReznick expands Cybersecurity and Privacy Practice; Forms Privacy Advisory GroupCohnReznick LLP, one of the leading advisory, assurance, and tax firms in the United States, announces a strategic expansion of its Cybersecurity and Privacy practice with the establishment of the Privacy Advisory Group.
On-demandHow to effectively align your cybersecurity program to your business strategyShahryar Shaghaghi, Doug Grindstaff, Greg WitteAs cyber-attacks and data breaches continue to make headlines and shake whole industries, organizations are learning that an effective cybersecurity program must be aligned with the company’s business strategy and board expectations. Strategic alignment needs to occur between the board, the infrastructure investment, and the actions being taken at the very front lines of the organization.
InsightNew Nevada privacy requirements go into effect Oct. 1Alison Bird, Judy SelbyWhile the California Consumer Privacy Act (CCPA) has attracted a lot of media attention, when it comes to privacy compliance, companies selling consumer information should keep their eye on the state of Nevada. Beginning on Oct. 1, 2019, amendments to NRS 603(A), Nevada’s existing privacy law, will allow consumers to direct operators of internet websites and online service providers to refrain from selling consumers’ personal information.