Privacy & Data Protection
Doing the Right Things | Complying with International and US Data Privacy Laws and Regulations
A principles-based approach to operationalizing your compliance program to a fluid data-privacy regulatory landscape.
Many countries and an increasing number of US states have passed comprehensive privacy legislation. BRG works with clients to achieve compliance with these international privacy regulations, which include the European Union’s General Data Protection Regulation (GDPR), Brazil’s General Data Protection Law (LGPD), Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), and Korea’s Personal Information Protection Act; the US Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act (GLBA), and Federal Trade Commission Act (FTCA); state privacy laws, including the California Consumer Privacy Act (CCPA) and Nevada’s Senate Bill 220; and state data-breach notification and data-disposal laws.
Combining our data-privacy principles-based approach and our data-privacy model, we deliver compliant, sustainable privacy programs that not only achieve compliance with GDPR and CCPA but are scalable and flexible enough to grow with your business and keep up with this dynamic area of law. Depending on the needs of your business, BRG can provide advice and support or can serve as your outsourced privacy officer or EU data protection officer, building your program from the ground up and providing ongoing services to fulfill data-subject requests, respond to potential data breaches, and otherwise manage the day-to-day requirements of maintaining compliance.
BRG prides itself on providing intelligence that works. We begin by rolling up our sleeves and mapping your systems and processes that involve personal data, and we work from there to create a right-sized, effective program for your business. Our simple, self-correcting, and sustainable “Discover-Build-Communicate-Evaluate” model can be tailored to your specific business environment.
- Gap assessment
- Data and application mapping
- Business process map
- Multidirectional data flows
- Identify proper program structure
- Program model
- Register of processes
- Data-subject request fulfillment strategy
- Manual or application-based tools
- Data-disposition model
- Contract terms
- Policies and procedures
- Consent and notices
- Training and awareness
- Risk and mitigation reporting
- Metrics to establish monitoring
- Audit data-subject access request fulfillment
Explore Related Insights
DPO as a Service Let's YOU DO YOU
DPO-as-a-Service: A Compliant and Cost-Effective Way to Protect Your Company’s Personal Data
June 25, 2020
The Six Data Privacy Principles of the GDPR
March 23, 2018
California’s Consumer Privacy Act: GDPR with Extra Litigation
European Data Protection Board Issues COVID-19 Statement
March 24, 2020
COVID-19 Checklist for Protecting Employee Health and Privacy
March 18, 2020
Countdown to 2020: Are You Ready for the California Consumer Privacy Act to Go Live?
July 18, 2019
What the California Consumer Privacy Act of 2018 Means for Your Business
August 8, 2018
Our industry knowledge is broad and deep.
BRG combines intellectual rigor with practical, real-world experience. We have an in-depth understanding of industries and markets, with expertise spanning the major sectors of the global economy. Following are some of the many sectors that we know inside and out.