"More than a third of organizations still 'consider privacy aspects in an ad hoc fashion' and it is surprising that so many companies are saying that they are not conducting privacy impact assessments before major projects. Sixty-two percent do not scan websites and applications, or conduct an organization-wide privacy audit every year. Organizations must put these activities on their to-do list for 2014," said Carsten Casper, research vice president at Gartner.
These results are based on 221 respondent organizations surveyed in April and May 2013 in the U.S., Canada, the U.K. and Germany that are responsible for privacy, IT risk management, information security, business continuity or regulatory compliance activities.
"Organizations continue to invest more in privacy due to ongoing public attention and a number of new or anticipated legal requirements," said Mr. Casper. "They also show that previous investments have not always paid off and that organizations need to refocus their privacy efforts if they want to raise the maturity level of their privacy programs back to that of 2011."
Mr. Casper added that many organizations are looking to boost their privacy activities through increased staffing and budgets to initiate comprehensive privacy programs to deal with cloud, mobile, big data and social computing challenges. Creating the right staffing model is crucial to the long-term success of privacy programs and central to that is the role of a privacy officer.
"Gartner's consistent observation is that privacy programs are only successful if someone is driving them. Almost 90% of organizations now have at least one person responsible for privacy. However, having privacy programs that are owned by this individual is still not the norm," said Mr. Casper. "Only 66% of survey respondents said they have a defined privacy officer role - although the number is as high as 85% in Germany and similar countries where this role is a legal requirement."
Mr. Casper added that a privacy officer should have broad expertise and solid relationship management and communication skills, because they must monitor a variety of (sometimes conflicting) business and IT requirements and collaborate with different internal and external business functions. In larger organizations, privacy officers will not only require a budget and a team, their success is also dependent on support from senior management.
Fortunately, it seems that the need to address privacy concerns more decisively is already being reflected in the amount of investment by organizations. Thirty two percent of survey respondents said that their organizations have increased privacy-related staff from 2012 to 2013 -- the most significant increase since Gartner started its privacy surveys in 2008.
Once the right team is in place, businesses must prioritize privacy programs as the number one objective. This will enable effective monitoring of privacy-related performance and allow suitable adjustments processes and technologies, particularly for data masking, encryption, data storage and document retention.
The handling of personal information for employees, customers and citizens tops the list of requirements respondents believe should be included in a privacy program. Some organizations -- concerned about violating domestic privacy laws and the risk to their reputations -- do not store personal data in locations where it can be seized by foreign authorities or is at great risk from cyber attacks. However, central global storage of personal data is becoming increasingly widespread. For the first time this year, more organizations stored their customer data in a central global place rather than in a regional or local data center, which was the dominant model previously.
The survey found that 38% of organizations transform personal data before transmitting it abroad (with masking, encryption or similar), thus keeping sensitive data local, while allowing some functionality abroad. This is the preferred option compared to domestic storage (29 percent), remote storage with only local access (27 percent) and with a focus on legal protection (22 percent).
"When storing and accessing personal data, organizations face a number of options. They can store data locally or in a low-cost country, allow access to domestic or remote staff, use a provider for application management or for infrastructure management, or implement legal and technical controls, such as data masking, tokenization and encryption," said Mr. Casper. "There is no right or wrong answer. Organizations have to decide which type of risk they want to mitigate, how much money they want to spend and how much residual risk they are willing to accept."
Privacy trends and strategies will be discussed in more detail at Gartner Symposium/ITxpo 2013.
About Gartner Symposium/ITxpo
Gartner Symposium/ITxpo is the world's most important gathering of CIOs and senior IT executives. This event delivers independent and objective content with the authority and weight of the world's leading IT research and advisory organization, and provides access to the latest solutions from key technology providers. Gartner's annual Symposium/ITxpo events are key components of attendees' annual planning efforts. IT executives rely on Gartner Symposium/ITxpo to gain insight into how their organizations can use IT to address business challenges and improve operational efficiency.
Additional information for Gartner Symposium/ITxpo 2013 in Orlando, October 6-10, is available at www.gartner.com/us/symposium. Members of the media can register for the event by contacting Christy Pettey at [email protected]
Additional information from the event will be shared on Twitter at http://twitter.com/Gartner_inc and using #GartnerSym.
Upcoming dates and locations for Gartner Symposium/ITxpo 2013 include:
· October 6-10, Orlando, Florida: www.gartner.com/us/symposium
· October 15-17, Tokyo, Japan: www.gartner.com/jp/symposium
· October 21-24, Goa, India: www.gartner.com/in/symposium
· October 28-31, Gold Coast, Australia: www.gartner.com/au/symposium
· November 4-7, Sao Paulo, Brazil: www.gartner.com/br/symposium
· November 10-14, Barcelona, Spain: www.gartner.com/eu/symposium
Gartner, Inc. (NYSE: IT) is the world's leading information technology research and advisory company. Gartner delivers the technology-related insight necessary for its clients to make the right decisions, every day. From CIOs and senior IT leaders in corporations and government agencies, to business leaders in high-tech and telecom enterprises and professional services firms, to technology investors, Gartner is a valuable partner in more than 13,000 distinct organizations. Through the resources of Gartner Research, Gartner Executive Programs, Gartner Consulting and Gartner Events, Gartner works with every client to research, analyze and interpret the business of IT within the context of their individual role. Founded in 1979, Gartner is headquartered in Stamford, Connecticut, USA, and has 5,500 associates, including 1,402 research analysts and consultants, and clients in 85 countries. For more information, visit www.gartner.com.