Three Best Practices to Drive Collaboration and Innovation in Data Privacy
CIOREVIEW >> Enterprise Information Management >> NEWS

2022

Jennifer Garone, Sr. Director, North American OpCo Privacy Leader, Carnival Corp Dec.19

Three Best Practices to Drive Collaboration and Innovation in Data Privacy

Jennifer Garone, Sr. Director, North American OpCo Privacy Leader, Carnival Corp Dec.19
Jennifer Garone, Sr. Director, North American OpCo Privacy Leader, Carnival Corp Dec.19, 2022

As the adage goes, a rising tide lifts all ships. At Carnival Corporation, the world’s largest cruise company, we believe this applies not just at sea but to all global companies looking to elevate their approach to information and privacy governance. Today’s world of information privacy is extremely complex, driven by advanced technology and evolving regulations. Large global organizations increasingly need to work in lockstep across all key departments to continually “raise the tide” in protecting data and privacy. Utilizing best practices in collaboration and communication across the organization will enable global privacy teams to enhance education, engagement and integration throughout the company and drive innovation in information and privacy governance.

At Carnival Corporation, we align around our company mission to create happiness and deliver the best possible experience for our guests, which includes their trust in our effective handling of data, all fueled by shipboard and shoreside employees eager to do the right thing day in and day out. Information and privacy governance is a key piece of an overall positive guest experience. Our common goals enable us to meet the highest levels of privacy expectations from both employees and guests, who trust us to handle and protect their information as if it were our own.

For a cruise company operating on a global scale like Carnival Corporation – with nine global cruise brands, an Alaska-based tour company, several island resorts and over 100,000 global employees serving millions of guests each year – successfully optimizing information and privacy governance presents its own unique set of challenges. Layering maritime law, immigration law, port authority and other multi-national regulations with always-evolving policies and procedures for the information and privacy governance creates a challenging environment. It requires a commitment to optimizing your privacy programs by working together to build relationships across teams worldwide, consistently communicating and constantly monitoring data and team feedback to support world-class data security risk management.

  ​Utilizing best practices in collaboration and communication across the organization will enable global privacy teams to enhance education, engagement and integration throughout the company and drive innovation in information and privacy governance

Our teams work diligently to successfully meet these ongoing challenges by pushing innovation and collaborating across multiple departments from ship to shore, driven by our Global Information Security & Compliance Services (GISCS) group working in close partnership with our technical teams led by our chief information officer (CIO) and chief information security officer (CISO). This collaborative framework enables us to capitalize on multiple perspectives and areas of expertise to adapt quickly to changing circumstances and develop new solutions for continuous improvement in privacy and information governance while keeping pace with business and regulatory changes. This helps us execute our strategic plans and meet the obligations of our global privacy policy to properly manage, delete and share information while minimizing overall risk across the company.

Best Practices: Maximizing Cross-Department Collaboration to Drive Innovation

Based on our overall approach and experience navigating data privacy in a fast-moving global community, we’ve derived three key areas of cross-department collaboration and innovation that serve as best practices to help global companies mature their programs designed to expand the reach and success of information and privacy governance.

Build Companywide Relationships: Scaling governance globally requires consistent application of policy and technology across the company. Proactive, companywide engagement to build relationships across departments and all levels of leadership helps people know where to go with privacy questions or concerns, pushes innovative thinking and promotes collaboration to strengthen risk management and data awareness and infuse privacy into everything you do.

Right Message, Right Time, Right Vehicle: Develop a comprehensive internal communications effort across multiple, effective channels to consistently inform and educate employees about privacy and information governance and make it personal to them, which connects the dots between training efforts and real-time execution. Equipping employees with the robust knowledge and skills needed to recognize and respond appropriately to potential risks keep training knowledge in mind and empowers positive decision-making on all levels.

Listen & Learn: Regardless of how your organization is structured, partner closely with your CISO and CIO to promote every interaction and transaction as an opportunity to listen, learn, and share resources. Making best practices and insights available across departments sets a foundation and expectation that compliance and security are not just about lawful action but a priority behavior as part of a company’s culture, which is ingrained on an individual and personal level to encourage everyone to do the right thing in every situation.

In our case, by aligning these best practices with our company’s six key “Culture Essentials” – which include active listening to learn from each other and a commitment to continual improvement – we have matured our global information and privacy governance initiatives organization. We have also collaborated to enhance our data capabilities through our innovative global connectivity platform implemented across our nine cruise brands, worked to optimize employee work-from-home security experiences and devised cutting-edge employee data privacy training, among many other initiatives! As a result, we have been able to execute integrated internal campaigns that boosted employee engagement with privacy by multiple percentage points in just one year.

These practices can significantly raise the tide of innovation while building trust across departments, employees and guests. As regulations continue to evolve, the global organizations that become privacy leaders of the future will need to be flexible and responsive and use advanced collaboration and communication techniques across key elements of privacy, security, and data management to keep employee and customer information safe.

 

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.