论文标题
GDPR Regtech的设计挑战
Design Challenges for GDPR RegTech
论文作者
论文摘要
GDPR的问责制原则要求组织可以证明遵守法规。 GDPR合规性软件解决方案的调查显示了其证明合规性的能力差距。相比之下,RegTech最近为财务合规带来了巨大的成功,从而降低了风险,节省成本和增强的财务监管合规性。结果表明,许多GDPR解决方案缺乏互操作性功能,例如标准API,元数据或报告,并且不受已发表的方法或证据支持其有效性甚至效用的证据。使用基于调节器的自我评估清单探索了概念原型的证明,以确定RegTech最佳实践是否可以改善GDPR依从性的演示。 Regtech方法的应用为可证明和验证的GDPR合规性提供了机会,尽管Regtech可以提供的风险降低和成本节省。本文表明,GDPR合规性的RegTech方法可以促进履行其问责义务的组织。
The Accountability Principle of the GDPR requires that an organisation can demonstrate compliance with the regulations. A survey of GDPR compliance software solutions shows significant gaps in their ability to demonstrate compliance. In contrast, RegTech has recently brought great success to financial compliance, resulting in reduced risk, cost saving and enhanced financial regulatory compliance. It is shown that many GDPR solutions lack interoperability features such as standard APIs, meta-data or reports and they are not supported by published methodologies or evidence to support their validity or even utility. A proof of concept prototype was explored using a regulator based self-assessment checklist to establish if RegTech best practice could improve the demonstration of GDPR compliance. The application of a RegTech approach provides opportunities for demonstrable and validated GDPR compliance, notwithstanding the risk reductions and cost savings that RegTech can deliver. This paper demonstrates a RegTech approach to GDPR compliance can facilitate an organisation meeting its accountability obligations.