Challenges and Opportunities in GDPR Implementation for TwentyCi

Verified

Added on  2020/02/24

|31
|7491
|50
Report
AI Summary
This report provides an in-depth analysis of the challenges and opportunities that TwentyCi faces due to the implementation of the General Data Protection Regulation (GDPR). The report begins with an executive summary and introduction to GDPR, highlighting its significance in replacing the 1998 data protection regulation in the UK. It then delves into the challenges and opportunities concerning business reputation, company survival, timing, data volume, and new business prospects. The analysis emphasizes the importance of proactive planning and preparation for GDPR compliance, focusing on areas such as direct marketing, employee data, and technology infrastructure. The report underscores the potential impact on TwentyCi's operations, management, and leadership. Recommendations are provided for workforce training and a smooth implementation process to ensure the protection of UK citizens' personal data. The report concludes by stressing the need for TwentyCi to adapt its management system and customer relationship management (CRM) to meet the demands of GDPR, and to maintain its reputation while navigating the complexities of the new regulations.
Document Page
Assignment One1
CHALLENGES AND OPPORTUNITIES IN PLANNING AND IMPACT OF GDPR
IMPLEMENTATION ON TWENTYCI
Student by (Name)
Professor’s (Name)
College
Course
Date
tabler-icon-diamond-filled.svg

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
Assignment One2
1. Executive summary
General Data Protection Regulation (GDPR) has in the present UK meant to replace the
old data protection regulation of year 1998. The UK data protection act was passed by the 1995
EU Data Protection Directives and attracts various immense fines for non-compliance and breach
of the act by any organization. The act also presets rights to various clients on what and what not
firms managing their personal data can do with their personal data. The main aim of the
implementation of General Data Protection Regulation (GDPR) is to allow more rights to the
people on how their personal data can be used and many of companies are yet to face challenges
and also have various opportunities at the same time. The implementation of the General Data
Protection Regulation (GDPR) implementation by TwentyCi will shake the operations of the
firm, management, leadership, timing and survival of the organization as key business deals are
personal data. The content of this report therefore majors on the discussion of various challenges
and opportunities which TwentyCi will experience due to General Data Protection Regulation
(GDPR) implementation.
Implementation of General Data Protection Regulation (GDPR) presents opportunities in
various sectors in the management, company survival, and finance and in other sectors within the
organization. However, the organization is likely to face challenges in direct marketing, support
employee information as well as within the technology information area and finance. As result of
the challenges and opportunities, the content further presents recommendations for General Data
Protection Regulation (GDPR) implementation planning. The organization is recommended to
Document Page
Assignment One3
offer proper training to their workforce on the changes made within the system by the new
regulation. The report concludes with another recommendation that the organization should
employ smooth implementation process with an understanding that the personal data of citizens
in UK is protected.
Table of Contents
1. Executive summary.....................................................................................................................2
2. Introduction..................................................................................................................................4
3. Analysis.......................................................................................................................................5
3.1 Challenges and opportunities of General Data Protection Regulation (GDPR)
implementation.............................................................................................................................5
3.1.1 Business Reputation........................................................................................................5
3.1.2Survival............................................................................................................................7
3.1.3Timing..............................................................................................................................8
3.1.4 Volume............................................................................................................................9
3.1.5 New Opportunities..........................................................................................................9
4. Conclusion.................................................................................................................................11
5. Recommendation.......................................................................................................................12
Document Page
Assignment One4
Assignment one
2. Introduction
The content of this paper provides information to TwentyCi an organization which is
likely to face challenges and opportunities due to the full implementation of GDPR by 2018.
The content also discusses the General Data Protection Regulation (GDPR) with regards to
TwentyCi as an organization that handles EU citizen’s personal information and doe marketing
through the use of phones and mail. TwentyCi as one of the organizations which deals with data
and information according to the case study should comply with the General Data Protection
Regulation (GDPR) by 25th May the year 2018. Various business organizations such as
TwentyCi due to the constant changing nature of the market has over the time relied on personal
data for the development (Carey 2009). The company based on the their choice of operations
must therefore comply to the various demands set by General Data Protection Regulation
(GDPR).The compliance with the regulation will therefore ensure the effectiveness of the work
done by TwentyCi and increase and sustain high level of performance.
General Data Protection Regulation (GDPR) according to the analysis almost similar to
the UK Data Protection act of 1998 and will affect all the organization which will have not
complied by 25th May 2018. This therefore means that the main obligation and line of operations
by various organizations dealing with data is gathering of the data. If the organization can
tabler-icon-diamond-filled.svg

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
Assignment One5
explain clearly the reason why they are accumulating data and to what level they are doing so,
the organization to this perspective is in very much compliance to regulations except for various
political inclinations, opinions of religion as well as generic data. The regulations also demands
deletion of data after its main purpose is meant. Being that TwentyCi as an organization fully
rely on collection of personal data, the regulations will therefore affect the firm’s customer
relation management (CRM), direct marketing, support service providers, financial management
sectors, support employee information as well as information technology. The implementation of
General Data Protection Regulation (GDPR) will also present various opportunities as presented
within the discussion below. TwentyCi is one of the organizations which is controlling the data
and information industry in the UK and failure to prepare for the implementation of General
Data Protection Regulation (GDPR) may destroy the company reputation in case other firms plan
is perfect compared its plan (Christer 2017). The implementation of General Data Protection
Regulation (GDPR) will require TwentyCi to change the management system in order to comply
with the demand of the regulation and maintain their reputations. The company will therefore
improve and make appropriate changes on how to manage
3. Analysis
3.1 Challenges and opportunities of General Data Protection Regulation (GDPR)
implementation
3.1.1 Business Reputation
The full implementation of the General Data Protection Regulation (GDPR) will result
present a lot of challenges and opportunities in relation to the survival of the TwentyCi as an
organization dealing with the gathering of data in UK. In relation to the reputation of the
Document Page
Assignment One6
organization, failure to fully prepare for the implementation may destroy the organizations
reputations. However, with proper planning and preparation for the full implementation of the
General Data Protection Regulation (GDPR by 25th may 2018 will result into an improved
organizational reputation. Making proper changes in terms of management and organization of
the human resource sector within the firm to secure reputation is one of the challenging issues
the organization have to deal with before 25th May 2018. In order to secure the customer trust
and loyalty which rely much on the firm’s reputation, TwentyCi will have to and must adopt a
much strict as well as costly process in dealing with data. The management of the organization
will have to appoint skilled labor force to ensure that the firm’s reputation is maintained during
the implementation process and after the implementation. The process of preserving their
reputation and the desire to remain at the top of the game is likely to be cost and may reflect on
the cost of service provision.
Increased prices may in turn not be taken positively by some customers leading to
reduced loyalty and poor reputation of TwentyCi as an organization. The cost of maintaining an
organization such as that of TwentyCi which is one of the top marketers in UK is high and the
management of the organization has a serious obligation to meet. TwentyCi will have to review
their whole system to comply with the requirements of General Data Protection Regulation
(GDPR). The review of the whole process as already mentioned is likely to reflect to the cost of
operations increasing the sales price. When sales prices of the services offered by a leading firm
in the industry increases, the reputation of the firm goes own as it may lose customers to other
firms destroying its reputations in the local market an internationally. The reputation of the firm
is directly linked to the number of customers, where there few customers the reputation of the
Document Page
Assignment One7
company goes down. For TwentyCi to maintain their reputation as one of the top marketers in
the industry, the organization must develop a plan on how to cost effectively implement Data
Protection Regulation (GDPR).
3.1.2Survival
The survival of any organization in an industry highly depends on various factors within
the industry and the general market. With the scale of the fine indicated within the Data
Protection Regulation (GDPR) requirements, the survival of any firm within the marketers
industry has been threatened. The set penalties by the Data Protection Regulation (GDPR) for
the breach and non-compliance is quite high for any firm caught or not caught on the wrong side
of the regulation by GDPR. TwentyCi survival is therefore at a stake due to the high penalties on
any offense in relation to Data Protection Regulation (GDPR). This is because any firm within
the marketer industry is responsible for the transgression of Data Protection Regulation (GDPR)
requirements. The survival of any firm while preparing and implementing the requirements of
Data Protection Regulation (GDPR) is at a stake based on the kind of transition a firm has to go
through before becoming in full compliance of the set regulation (De Hert and Papakonstantinou
2012).
TwentyCi being one of the firms in UK preparing for the implementation of Data
Protection Regulation (GDPR) will have to go through a full transition to meet the regulations,
the organization will have to absolutely renovate their system of gathering data, processing
methods, securing and storage of information, sharing and securely delete a personal data. The
renovation of the system will require a special team whose main objective is to manage Data
tabler-icon-diamond-filled.svg

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
Assignment One8
Protection Regulation (GDPR) for the company to survive. Data Protection Regulation (GDPR)
has similar requirements meaning same standards for all firms within the industry. With similar
standards the survival of TwentyCi is threatened based on the increased competition as a result
of similar standards. The organization should therefore invest a lot on the appointment and
establishment of a right team which is a key factor to the firm’s survival and successful Data
Protection Regulation (GDPR) preparedness (De Hert and Papakonstantinou 2012).
. The organization will therefore be faced with several challenges in relation to the
preparedness and survival. TwentyCi should come up with a proper management team to remain
at the top of the game which requires training and this may be a challenging to the firm to
appoint.
3.1.3Timing
TwentyCi is one of the organizations which are required by the Data Protection
Regulation (GDPR) to comply with its regulations prior to 25th may 2018. There are only a few
months left and TwentyCi will need to come up with new policies and proper planning, test the
procedure and the plan in order to ensure that they are able to comply fully with various data
rights within the time limits. The timing may be challenging to the organization based on the
number factors they have to consider while preparing to implement Data Protection Regulation
(GDPR). In such cases of urgency the firm will not only be required to make important
investments financially but consider investments in time as an important factor (Gilbert 2011).
The process will involve portability of data thus time is required. The preparation for the
implementation of Data Protection Regulation (GDPR) will affect various sectors within the firm
Document Page
Assignment One9
which then require proper time allocation. TwentyCi will have to appoint various teams to
manage Data Protection Regulation (GDPR) implementation, the will need to appoint new sales
team or train the former team to proper inform their customers on the new order of the day.
Appointment and allocation of resources for the preparation and management will need proper
time allocation and the firm will need to have proper planning with the given time limits by
GDPR.
3.1.4 Volume
In relation to the volume, the firm will have to gather reduced volume of data during the
implementation preparation. This is due to the new system of data managements procedures
created based on the Data Protection Regulation (GDPR). The volume of the data that the
company will be able to handle will reduce as they will have to adopt a much strict procedure as
required by GDPR. The procedure to be followed by organization will increase the volume of
work to be done by the employees and reduce the quantity of the output. The firm according to
the research conducted will need to come up with a system named A-Z which will help with data
control (Kshetri and Murugesan 2013). TwentyCi will also need to perform data mapping prior
to the implementation and analyse the whole process after receiving information or data from
their clients to identify where the data comes from as well as document every procedure for data
gathering (Gilbert 2011). This complex procedure may reduce the volume of data managed by
the firm after the implementation of Data Protection Regulation (GDPR). Data obtained by the
firm will passed through a technical security protocol which may then also reduced the volume
of work to be done by the firm. The company therefore to some extent will have reduced volume
of work in terms of client data management but will have to go through a large volume of work
Document Page
Assignment One10
in relation preparation and implementation of Data Protection Regulation (GDPR) and this will
be a challenge to the firm.
3.1.5 New Opportunities
Preparations and implementation of Data Protection Regulation (GDPR) does not only
present challenges to TwentyCi but also presents a number of various opportunities that the
organization can exploit to remain on the top of the game. According to various sources
preparation and implementation of the Data Protection Regulation (GDPR) could be the right
time for TwentyCi to come out of their comfort zone as an organization to move further top
within the industry. The management of the organization should not have a negative thinking
that implementation of Data Protection Regulation (GDPR) will restrict their operations. The
firm should take this opportunity to make distinctions between the marketing strategy, privacy of
personal data as well as technology (Kshetri and Murugesan 2013). Based on the regulation
requirements, TwentyCi as an organization will have an opportunity to upgrade their system in
terms of the data science and insight of the of the business, the organization will have to develop
their data translation system to meet their customers’ demands in accordance with the data
regulations.
The procedure for implementing the new regulation set by the UK government requires
firms to come up with proper management team for the implementation in order to avoid fines
set by the GDPR. The process and planning for the implementation of the Data Protection
Regulation (GDPR) presents TwentyCi with an opportunity to appoint new management team
and improve their performance. TwentyCi will have to reprogram their system to meet the Data
Protection Regulation (GDPR) in order to improve the company information sales (Kshetri and
tabler-icon-diamond-filled.svg

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
Assignment One11
Murugesan 2013). As an organization which is a marketer, improvement in the data
management, organization and security will enable TwentyCi as a firm to attract various
customer firms who are interested in information sold by TwentyCi. The company has the
opportunity to develop data subject access system that will enable them to respond first enough
to various client demands. Moreover, the company has been presented with the chance to come
up with new Web and non-Web based access that will then enable the firm to limit any
possibility of being hacked. Securing the firm’s system from various hack attempts will increase
the firm’s reputation as well as their customer loyalty. With proper preparedness and
implementation Data Protection Regulation (GDPR) by TwentyCi, the organization therefore
stands a chance to remain at the top of the marketing industry. The company has been presented
by a number of opportunities in relation to the management of the firm based on GDPR
regulations, increase the firm’s reputations, and implement new marketing strategies and ways to
retain the consumer.
4. Conclusion
Various challenges and opportunities discussed within the content above justify the
wrong perception by various data dealing firms in relation to the GDPR regulations. Many firms
have over the present past viewed the new requirements by the UK government as being over
stricken. Implementation of the new Data Protection Regulation (GDPR) has presented firms
such as TwentyCi with a lot opportunities compared to the challenges. The firm in process of
preparing itself to the full implementation of Data Protection Regulation (GDPR) requirements is
face with several challenges in relation to timing, work volume, labor organization and survival
Document Page
Assignment One12
but at the end, the whole process has learnt several opportunities which are likely to help the firm
survive at the top of the game (Kshetri and Murugesan 2013). According to the research
conducted within the firm, implementation of Data Protection Regulation (GDPR) by TwentyCi
s at the right time and the firm should fully comply. Instead of seeing the whole process as being
strict, TwentyCi should take the opportunity to redeem itself and become one of the most to
firms within the industry. As just mentioned earlier, the management team of TwentyCi should
come up from their comfort zone and become one of the best firms dealing with data in whole
global market. The application of the rules set within Data Protection Regulation (GDPR), will
help the firm to operate within the demands and rights of their customers developing further the
firm’s loyalty and maintain customer loyalty. Based on the discussion above, it can be conclude
that Data Protection Regulation (GDPR) does create pain and challenges to firms such as
TwentyCi, but if they come up with a proper way of compliance and show value of privacy to
their clients personal data they will then improve on their data management ways and remain
firm within the industry.
5. Recommendation
Data Protection Regulation (GDPR) implementation preparedness though presents
various challenges as discussed above on firms which rely on personal data management. The
firms are therefore recommended to come up with a clear and proper Data Protection Regulation
(GDPR) implementation strategy. It is recommended for firms such as TwentyCi to first appoint
a proper management team with the required management skills to ensure full implementation of
Data Protection Regulation (GDPR) prior to the set date of 25th may 2018. Based on the research
chevron_up_icon
1 out of 31
circle_padding
hide_on_mobile
zoom_out_icon
[object Object]