The Solution
The client urgently needed an aggressive implementation timeline for launching clinical trials in the EU. To help them meet this goal, Kroll joined forces with Red Clover Advisors, a trusted privacy operations partner. We collaborated closely with the client’s compliance team and EU-based data protection officer to assess the company's core business, marketing activities and employee practices against the stringent requirements of the EU GDPR and various U.S. data privacy laws. To gather insight, our team interviewed key stakeholders to identify the scope of activities that process personal information, documenting the client’s collection, storage and access practices.
We subsequently configured the OneTrust Data Mapping module, tailoring it to fit the client’s specific needs. This comprehensive data map inventory became the cornerstone of our approach, enabling us to prioritize a holistic privacy compliance initiative. It allowed us to review the client’s data collection, sharing and consent practices thoroughly. In addition, our collaboration supported a variety of supplementary activities and best practices, including but not limited to:
- Developing external and employee privacy notices
- Establishing processes for individual rights requests
- Building operational workflows, policies and training aligned with the OneTrust configuration
- Customize general employee privacy awareness and training programs supported with standard operating procedures (SOP)