DAT-250 Module 3 Project One Business Brief
docx
keyboard_arrow_up
School
Southern New Hampshire University *
*We aren’t endorsed by this school
Course
250
Subject
Information Systems
Date
Dec 6, 2023
Type
docx
Pages
6
Uploaded by SuperHumanOyster2735
Surge Consulting
Expansion Proposal
Prepared for Pixie Tech
Created by Tatiana Portsova
07/13/2023
Topic
Findings and Recommendations
Regulatory
Bodies
●
Regulatory bodies are organizations that make sure companies follow
the rules for handling data. They create guidelines and rules that
control how data is collected, stored, used, and protected. For Pixie
Tech, the regulatory bodies that affect their expansion project a lot are
the General Data Protection Regulation (GDPR) and the California
privacy laws. GDPR is a set of rules from the European Union that
protect the data and privacy of people in the EU, no matter where the
company that handles their data is located. California privacy laws, like
the California Consumer Privacy Act (CCPA) give people in California
even more rights and rules for how businesses handle their data (State
of California Department of Justice, 2023.)
These regulatory bodies control different types of data, like personal
information that identifies someone, sensitive personal information,
and data about children. They make sure companies get clear
permission to collect data, are honest about how they use data, give
people certain rights over their data, and take enough security
measures to keep data safe.
●
For Pixie Tech, the specific client data that falls under these regulatory
bodies would include personal information about people from the EU,
like their names, addresses, contact information, and what they've
bought. Since Pixie Tech sells toys for children, they also have to follow
2
Topic
Findings and Recommendations
rules about collecting and using data about kids. This includes checking
their age, getting permission from their parents, and making sure the
content is suitable for their age.
Impact of
Data Regulation
●
Changes in data regulations can have a big impact on companies like
Pixie Tech. When regulations change, new rules and requirements may
be imposed, which can increase costs and disrupt the way businesses
operate. If the regulations become more strict, Pixie Tech might have
to invest in better ways to protect data, do privacy assessments, hire a
data protection officer, and make sure they get clear consent from
customers. They might also need to update their privacy policy, terms
of service, and how they handle data.
●
On the other hand, if regulations become less strict, Pixie Tech might
have some advantages like having fewer rules to follow and more
flexibility in how they use data. But it's still important for Pixie Tech to
be careful with privacy and data protection, even if the rules are not as
strict. Building trust with customers and maintaining a good reputation
should always be a priority.
●
For example, a regulatory change that could affect Pixie Tech is if there
are stricter rules for moving data across countries under the GDPR. If
the European Data Protection Board makes new guidelines or puts
more restrictions on transferring data to countries outside the
3
Your preview ends here
Eager to read complete document? Join bartleby learn and gain access to the full version
- Access to all documents
- Unlimited textbook solutions
- 24/7 expert homework help
Topic
Findings and Recommendations
European Union, Pixie Tech might need to add extra protections like
special contracts or rules to make sure they are following the law when
transferring data.
Regulating
Data Usage
●
Regulating how data is used and handling sensitive information are
important for Pixie Tech. Non-sensitive data includes general customer
details, order history, and marketing preferences. On the other hand,
sensitive data is more confidential and includes things like financial
information, health records, and data about children (Investopedia,
2022.)
●
There are benefits to handling sensitive data. It can increase customer
trust, ensure compliance with rules, and protect against data breaches.
Pixie Tech can achieve this by putting strong security measures in
place, which will make customers feel more confident and loyal.
●
However, handling sensitive data also brings challenges. It requires
extra security measures, strict controls on who can access the data,
and regular checks to make sure everything is done properly. Pixie Tech
needs to be careful and follow security protocols, train employees
well, and have plans in place for how to deal with incidents, in order to
reduce the risks associated with sensitive data.
●
An example of sensitive data that Pixie Tech might have to deal with is
4
Topic
Findings and Recommendations
financial information like credit card numbers or bank account details,
which they would need for processing customer payments
(Investopedia, 2022.) Additionally, if Pixie Tech offers personalized toys
based on children's preferences, they may collect and protect sensitive
information about the children, such as their ages, interests.
Data
Professional Roles
●
Keeping data safe and following the rules involves different jobs in a
company. These jobs make sure the company follows the rules, sets up
ways to manage data, makes things secure, and keeps an eye on data
activities.
●
Inside the company, there are people like the Data Protection Officer
(DPO) who makes sure data is protected and private. The Chief
Information Security Officer (CISO) is in charge of keeping data secure,
and the Chief Compliance Officer (CCO) makes sure the company
follows the rules.
●
Outside the company, there are organizations like the European Data
Protection Supervisor (EDPS) and the California Attorney General's
Office that enforce the rules. They can check if the company is
following the rules, look into data problems, and give penalties if the
rules are broken.
●
At Pixie Tech, some roles responsible for keeping data safe and
5
Topic
Findings and Recommendations
following the rules might be a Data Governance Manager who sets up
rules for managing data, a Security Analyst who checks how secure the
data is, and a Privacy Officer who makes sure the company follows the
privacy rules and helps people with their data requests.
References
Office of the Attorney General (May 10, 2023)
California Consumer Privacy Act (CCPA).
State of California
Department of Justice.
https://oag.ca.gov/privacy/ccpa
J. Frankenfield (October 30, 2022)
What Is Personally Identifiable Information (PII)? Types and Examples
.
Investopedia.
https://www.investopedia.com/terms/p/personally-identifiable-information-
pii.asp#:~:text=Non%2Dsensitive%20personally%20identifiable%20information%20is%20easily
%20accessible%20from%20public,non%2Dsensitive%20personally%20identifiable%20information.
6
Your preview ends here
Eager to read complete document? Join bartleby learn and gain access to the full version
- Access to all documents
- Unlimited textbook solutions
- 24/7 expert homework help