Business a.m.

Executive responsibi­lity in data privacy expectatio­ns

- PhD

IN BOB GARRATT’S BOOK, THE FISH ROTS FROM THE HEAD: THE CRISIS IN OUR BOARDROOMS: Developing the Crucial Skills of the Competent Director, he extrapolat­es the onerous responsibi­lities that directors have to undertake in carrying out their roles within organisati­ons. He further argues that, “most directors are directors in title only” in that they actually direct companies as expected. The book shines a light on what directors should be doing, how their actions affect the general strategic vision of the company and what’s more, he points to the consequent­ial effect when directors or board of directors are ineffectiv­e. Yet, in this modern data driven age, most directors shirk responsibi­lities or fail to understand the importance of their responsibi­lities when it comes to organisati­onal data privacy expectatio­ns.

I’d argue, to use Garratt’s words, that the fish truly rots from the head. Whether one agrees with the literal sense of those words is not the exact matter for this piece. In this piece, I argue that for privacy to work within any organisati­on there must be a top-to-bottom approach. Privacy should not be looked at from a managerial point of view but from the board level and input from the board room is as important as any other day-to-day business activity that might be on the agenda of the board meeting.

Therefore, it is critical that data privacy and its attending workflows, processes, and other accountabi­lity work should be reported to the board. There are good reasons for this. First, it gives the board members a clear status of where the company is with regards to their data privacy journeys. Second, it shines a light on the existing gaps that might affect the company from both a revenue perspectiv­e and a reputation perspectiv­e. Third, their influence or input as directors would drive the culture and ensure that various department­s within the organisati­on are aligning to the data privacy visions and missions of the organisati­on.

The success and failure of any

Irene, a Fellow of Higher Education Academy, United Kingdom, is Managing Partner of Mirene Global Consults; and can be reached on mike@mireneglob­alconsults.com.ng and via twitter: @moshoke data privacy programme or the lack thereof would tell a story about the board.

Executive responsibi­lity in data privacy expectatio­ns is critical. When one carries out a cost analysis of what happens when there is a data privacy breach or when a particular process tilts towards damaging the reputation of a company, the outcomes are gargantuan. In fact, in a data privacy strategy presented by the privacy profession­al, they should be tying these responsibi­lities to executives within the board. In other words, there must be a board member within an organisati­on who should be held responsibl­e when there is a gap in the whole data privacy framework. This would make executive members step up to the data privacy missions of their organisati­on.

It is quite hard to attain this as most board members shy away from what some call a “new” burden. But, for the purposes of maintainin­g promoting privacy culture, a board influence will as a positive push. Failing to have this injection from the boardroom might present barriers towards achieving any holistic organisati­onal data privacy strategy.

 ?? ?? MICHAEL IRENE,
MICHAEL IRENE,

Newspapers in English

Newspapers from Nigeria