2021-10-21-安永_中国_-IAPP-EY_Annual_Privacy_Governance_Report_2021_107页_4mb
报告摘要
Privacy and data governance for organizations continued to evolve in 2021, with significant challenges and adaptations influenced by regulatory changes, technological advancements, and the ongoing COVID-19 pandemic. Key trends include:
-
Budget and Staffing Growth: Privacy budgets averaged $873,000, up significantly from previous years, reflecting increased organizational investment. Organizations plan to hire more staff, with 45% expecting hires over six months, driven by growing compliance needs.
-
Compliance Challenges: Cross-border data transfer laws (e.g., post-Schrems II) remain the most difficult task for privacy professionals, with issues like localizing data or halting transfers reported by 10% of firms. Compliance with GDPR, CCPA/CPRA, and other laws showed varying levels, with GDPR being more widely compliant due to its global reach.
-
COVID-19 Impact: Remote/hybrid work became standard, with 81% of privacy pros working mostly from home in 2021. Data collection decreased in some areas (e.g., travel history), but health data like vaccination records increased. Business travel is expected to normalize in 2022.
-
Leadership and Structure: Privacy leaders often hold roles like Chief Privacy Officer (CPO), frequently reporting to legal or executive teams. EU regions show more DPO adoption than the US, with structural variations based on firm size and location.
-
Responsibilities and Priorities: Core duties include privacy policy development, training, incident response, and compliance monitoring. Top priorities are regulatory compliance, with GDPR leading in EU firms and CCPA in US-based organizations. Technology adoption for DSRs and data mapping is increasing.
-
Data Subject Requests: Access and erasure requests are most common, with response times averaging a few days. About 60% of organizations have dedicated teams for handling DSRs, and automation is growing.
-
Vendor Management: Contracts, questionnaires, and audits are key tools for ensuring vendor accountability, with certifications like SOC2 and NIST Privacy Framework widely used.
-
Overall Trends: Privacy functions are maturing, with firms investing in technology and expertise to address complex regulatory environments. The profession is expanding, supported by growing credential adoption and workforce development.
This evolution underscores the critical role of privacy in business strategy and risk management amidst a dynamic legal and operational landscape.
试读结束,高清完整版pdf/doc/ppt,请点下载