Building a GDPR compliance management system in low-code
The challenge
UK Power Networks own, construct and maintain the electricity infrastructure across London, the Southeast and East of England. The General Data Protection Regulation (GDPR) is key to protecting individuals’ fundamental rights and freedoms, particularly the right to protect personal data and ensuring it’s treated properly and fairly.
With all the privacy controls already in place to ensure adherence to the regulations, but with very manual processes – managed across emails, forms and excel spreadsheets and other disparate systems, the Data Protection Officer (DPO) wanted to reduce complexity, enforce a consistent process and reduce the compliance impact on workloads across the business. As regulatory regimes become tighter and volume and breadth of regulation increases, doing more for less is critical.
Streamlined, fast and failsafe
UK Power Networks wanted the processing to be more transparent, keeping everything in one place with the assurance that nothing was ever missed. It also needed to be easier for the Data Protection team, as well as other staff who champion data protection in their departments, to keep on top of compliance alongside their day-to-day tasks and responsibilities.
Liberty Create, our low-code platform, had been used on multiple projects and systems within UK Power Networks and members of the Data Protection Team had experience of using it to develop applications. It was the natural selection to build a Compliance Management application.
“The new digital processes ensure adherence and compliance, rather than the team spending a high proportion of their time chasing activities to meet the necessary compliance steps. It provides us with the framework to minimise the potential for any breaches or fines, as well as reducing admin time for colleagues across the business. We’ve moved from labour intensive and manual processes to a system that’s automated, organised, easy to track and audit, highly visible and ‘all under one roof’.”
Lee Warwick
Data Privacy Advisor, UK Power Networks
The solution
As a longstanding partner, Netcall demonstrated a working example of a GDPR compliance system to UK Power Networks, showing a framework of how this might be structured and how this can evolve over time as new regulatory requirements come along. This acted as a catalyst, providing different members of the buying group with confidence that Liberty Create was a perfect fit for this complicated and highly regulated business function.
The solution has already enabled UK Power Networks to centralise the following processes:
New Data Incidents
Data Breach Assessment and Categorisation
Remediation Action Planning
Data Protection Impact Assessments and Risk Categorisation (DPIAs)
Data Subject Access Requests (SARS)
Erasure Requests including removing identifying details from the GDPR Management System
Record of Processing Activities (RoPA)
UK Power Networks needs to process many Data Protection Impact Assessments and Subject Access Requests and their Data Protection Team and Data Champions are spread throughout the organisation. As such, the GDPR management system needed to support a decentralised way of working. All business users can raise tasks to be undertaken within the platform and access resources and guidance on how to best report incidents. They have visibility of their ongoing impact assessments, they can track progress, whilst the system ensures consistency and integrity of the data. Using Netcall’s Intelligent Automation capability, the system enables timely alerts, faster processing and true collaboration enhancing the employee experience as well as improving controls and processes.
Automated emails make everything faster and easier to manage. Everything relevant is contained in one system, rather than disparate spreadsheets, inboxes and lists. The Data Protection team can now easily pull reports to provide accurate visibility of all cases and associated documentation, plus track progress to ensure adherence to SLAs especially in line with Information Commissioner Office (ICO) expectations.
The entire aim of GDPR is to protect customers and their data. UK Power Networks is now able to centralise the capture of all the necessary information against an impact assessment ensuring a consistent way of reporting, which in turn, ensures that the customer’s data is more effectively protected.
Where practical, the Data Protection Team has automated processes.
An example of this type of intelligent automation is the way the Erasure Requests are handled. This is where a customer does not want UK Power Networks to hold their data. The team built a form to enable customers to quickly request that their data is erased. In the past, the customer would have had to email the data protection inbox and a member of staff would have to process the request.
Once all applicable systems have been updated, the GDPR Management platform itself then removes customer’s identifying details, without any human intervention. The customer receives an immediate response confirming that their details have been erased, giving them confidence in the efficiency of UK Power Networks and the importance they place on keeping customer’s data safe, accurate and only used for the purpose it was intended.
The Data Protection Team is now looking to leverage the Liberty Open Database Connectivity (ODBC) to integrate Power BI and enable further insights to be shared throughout the organisation.
The team is also working on centralising resources to aid the Data Protection Champions to keep up to date their skills and knowledge.
“The GDPR Management System simply does the job it’s supposed to do – reliably, securely, quickly and efficiently. There’s transparency and visibility on all cases, enabling management to be more involved in decision making. It allows for collaboration on issues within the same tool, without sharing documents back and forth. It’s streamlined, reducing business risk and providing clear evidence of our compliance with all GDPR requirements.”
Nick Zentner
Data Protection Officer & General Counsel, UK Power Networks
The result
Efficiency: Automated processes reduce errors, admin time and speed up data processing
Unified information: All data is in one system for easy access for all
Audit trail: Full compliance evidence is provided
Collaboration: Data Champions engage more with processes, suggesting improvements due to seeing the speed of improvements
Automated logs: Register of processing activity is automatically generated, replacing a manual spreadsheet.
Total confidence
Liberty Create has enabled UK Power Networks to support their ideal process, rather than having to adapt their processes to fit an off-the-shelf compliance system. UK Power Networks has total confidence that they have a platform that can flex and mould around their current and future needs.
Tackling project after project – Hear it for yourself
UK Power Networks can equip people in the business, those who really understand the process, with the tools that they need to automate existing processes. They are using Liberty Create to develop many new digital journeys which deliver award-winning customer experience – watch the video to find out more.
As part of their onboarding process, Cielo reviews a client’s current recruitment process, identifies improvement opportunities, aligns with best practice models. The introduction of Liberty Spark, our process discovery solution, led to an enhanced and improved user experience.
If Carte Blanche was to benefit from greater clarity and understanding of their processes, they would need to be clear on the current state of the organisation, before they started to make any changes. They used Liberty Skore, our process discovery solution, to embark on this initiative.
To maintain and grow its position as the assurance and certification partner of choice to the UK rail industry, NCB needed to update existing inefficient IT systems for managing assessment service delivery.