
Symptai Consulting, thought leaders in cyber security and data protection, recently hosted its Data Privacy and Protection webinar, Unmasking the Monster.
The webinar, which took place on January 10, was put on to highlight the legal, technical and compliance aspects of data privacy and protection and offer guidance on meeting the November 30, 2023 deadline for data controllers in Jamaica to register with the Office of the Information Commissioner.
The online seminar included panelists Stuart Hylton, senior manager – IT Compliance and Privacy; Andrew Nooks – chief risk officer; and Alicia Perez, director – Transformation, Assurance and Compliance, all from Symptai Consulting. Joining them were Grace Lindo, partner at Carto Lindo; and Jason Cronk, privacy and trust consultant at Enteprivacy Consulting Group.
REQUIRED SKILLSET LIMITED ACROSS GLOBE
With just over 300 participants in attendance at the virtual forum, Andre Palmer, director of research & engagement at Symptai, incorporated pressing questions from the attendees with the running order of the webinar.
The panelists were asked if there was still time for companies to start their preparations for the deadline. All agreed that it is imperative to begin immediately if no prior provisions have been made, and companies should focus on the critical things needed to submit to register with the office of the Data Commissioner.
“The required skillset across the globe is limited, and there is a lot of competition to get those scarce resources to assist companies with their programs. Therefore, don’t wait until the last minute to reach out to the experts,” Nooks added.
“From a technical and implementation standpoint, organisations should start with the security governance framework and an adequate information management system, as this will ensure sufficient administrative controls.”
Stuart Hylton, senior manager – IT Compliance and Privacy
Hylton highlighted that a common concern is that companies aren’t sure where to start.
“From a technical and implementation standpoint, organisations should start with the security governance framework and an adequate information management system, as this will ensure sufficient administrative controls,” Hylton stated.
Another mistake seen while supporting companies with their data protection programme is that companies struggle to determine the ownership of the data privacy and protection function within their organisations.
“Put together a cross-functional team to include information security, legal, compliance, risk, regulatory management, customer service and business intelligence to manage your privacy programme,” said Hylton.
EDUCATE ALL EMPLOYEES
He added that companies should seek the support of a third party to validate their privacy programmes as this provides them with an independent perspective.
The statistics around data breaches and data leaks reveal that a vast number of these result from human error or negligence due to ignorance. The law does not care how it happens – the penalties and fines are the same regardless. Legislators presume that organisations will take all the necessary steps to educate all employees on sound data privacy practices so that they can operate in compliance with the law.
In responding to a question asked by an attendee, Lindo asserted that the law doesn’t prohibit data controllers and processors from using the data. Still, they ought to be responsible, “… so this is a rights-based law which is trying to balance their [data subjects] rights with your [data controllers] commercial demands”.

At the end of the virtual session, attendees were able to grasp all the moving parts needed in journeying the roadmap to compliance. The discussions stemmed from the importance of privacy in your organisation and the responsibilities of the data controllers; to design and implement a data privacy and protection programme to include accurate controls, systems and tools for your organisation.
Symptai Consulting offers a range of data privacy and protection services that will support companies with the necessary knowledge and tool to comply with the JDPA, as well as educate all staff members about the Act, their responsibilities and the implications of any breaches to the Act should they arise.
Data privacy and protection has moved beyond being just a compliance requirement to a business need that establishes trust among all stakeholders. Therefore, consideration should be given to establishing a data privacy and protection programme that will continuously mature within the company.
Comments