Understanding the Subsurface of the Energy Landscape
CIOREVIEW >> EAM >> NEWS

PGS

Daphne Bjerke, Chief Global Data Protection Officer

Understanding the Subsurface of the Energy Landscape

Daphne Bjerke, Chief Global Data Protection Officer
Daphne Bjerke, Chief Global Data Protection Officer, PGS

Daphne Bjerke is the Chief Global Data Protection Officer at PGS. She coordinates PGS Group’s personal data and with the legal and compliance team to manage questions related to data protection and privacy.

1. What is the biggest data privacy related challenges that you observe in your business on a day-to-day basis?

As we are a seismic processing company, we have vessels located all over the world so, more than half of our employees are working offshore. As a result of that, we need to send a lot of information and personal data to our agents when people are going on or offboard a vessel through emails and attachments. To secure important or personal information, we were using Kiteworks, but that is not very user-friendly and not everyone knows how to use the receivers. So, we have implemented something called the data protection loss policy and sensitivity labels and educated our employees to use sensitivity labels to send emails outside of the company and on attachments. That is the most important thing for our company because there is so much personal information of our crew that we are sending to other people or another company, we have to make sure that they only use it for the intended purposes only.

2. How much time are you devoting, as a transformational leader, to look into the things the future trends that is going to impact and work on it beforehand?

We have a group in our company called the General Data Protection Regulation (GDPR) workgroup, and it consists of four different departments: legal, HR, compliance, and IT. We meet on a regular basis monthly to review all the new changes in legislation. We go through all the different requirements when transferring data in places like Europe, Asia, and America, to make sure we are on top of everything. Additionally, we schedule an external company to come into our company and do an audit on all of our different GDPR processes, policies, and procedures. They also check where we’re storing the information, how we process the information, personal data breaches, and how we process new application systems to make sure that all the data is in compliance. Now, our processes have been in place for four years in May, and now would be a good time to check in and see if we are in compliance with all new rules and regulation

 We go through all the different requirements when transferring data in places like Europe, Asia, and America, to make sure we are on top of everything 

3. In terms of adoption of any kind of solution or technologies, when you're vetting different kinds of providers, what are the usual things that you look at? In other words, when you look at a new application system that you’re thinking of purchasing, how do you process it?Usually, before we sign a contract, firstly, we have our procurement look at it. We also have our legal GDPR expert review the terms and conditions because, very often, most vendors have a data privacy section, data processing section, or an index. We also have a notification form that all potential owners of the system need to fill. We review them, ask specific questions, see the kind of data that is going to be sent, and how it is going to be sent. We also see if the application system has a built-in delete function for when the employee is no longer working in the company. So, it's programmed to be compliant, and once we have that reviewed, we usually need to conduct a data processing impact assessment. But, if we don't feel like it meets our compliance rules, we need to set up a data processing agreement with the vendor to see what they have in their terms and conditions. If there's any other outstanding action points, then we need to have those completed before we can actually implement the new application system. And then what we do every other year is an audit of our application systems, because some of them are no longer in use or maybe the owner who is responsible for it has been changed. And we ask them to review their notification form one more time to make sure they're using the application system as they told us they were going to use it.

4. Can you think of an instance where you had to be quick on your feet to solve a critical situation that your company might have undergone and how did your company mitigate that problem to attend to those data issues?

One of the big problems with personal data is photos. Before we start publishing photos, both internally and externally, we have to make sure that we have a consent in place. So, we are looking at a new application system, where instead of having different consent forms for every time we have a new photo publication, we'll be able to put it in a workflow in a system. That is really important for us as we don’t want our employees to feel like we are using or publishing any photos of them without their consent. Sometimes they create nice videos, without realizing they can't put them on social media unless we have consent for all of our employees. When that happens, we have to address the issue right away and ask them to remove it from social media, or get the consent for everyone who's involved in the video.

5. What advice would you give to the other leaders in this industry or any other industry regarding the different kind of data challenges and the way to mitigate them and come in compliance with GDPR?

First of all, it's really important that you've had the board of directors in your company on board. So, I give an update to my manager, who presents it to the board to get a summation. They realize that GDPR is a part of how we work and not an addition to what we do. Once that's accepted, it's really important that we communicate all the different regulations. It is also important to do different things like sensitivity labels, consent forms, and retention periods, so that your employees are informed and feel more comfortable. And I think it’s really important to have a good communication. I work in HR, but I have a very close communication with our IT department, because they have lots of application tools that can be used to help us with data privacy and eliminating personal data breaches. So, I think it's really important that you have a good working relationship with your HR, IT, compliance and legal departments, so that everyone's involved in the working of the company.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.