Skip to main content

      In today’s hyperconnected world, privacy is no longer just a legal checkbox – it’s a cornerstone of business integrity, customer trust, and long-term success. As companies collect and process more personal data than ever before, the stakes have never been higher. A single data breach can damage reputation, erode consumer confidence, and lead to costly regulatory penalties.

      But how do you build a strong and practical privacy strategy? What steps should you take to reduce risks and stay ahead of potential data leaks? No worries, we’ve got you covered. Together with our privacy experts, we’ve outlined a deep dive in the different privacy projects that can help you shape your own privacy strategy.

      Relevant privacy regulations

      Before explore the different ways in which KPMG can support you in strengthening your privacy strategy, let’s take a moment to look at the broader legal landscape. Spoiler alert: GDPR isn’t the only regulation you should be thinking about.

      Although the GDPR is recognized as the gold standard for privacy regulations around the world, it is essential to acknowledge the significance of other privacy and data protection regulations as well, such as the ePrivacy Directive (also known as the Cookie Directive). A closer look also reveals various local regulations, such as the Belgian Data Protection Act, the Belgian Camera Act, and specific sectoral legislation. For example, while the GDPR requires retention periods to be defined, specific durations are often set out in national laws.

      There are also standards that incorporate privacy requirements such as ISO27701 that should be considered, as well as related legislation on topics such as data localization and retention, cybersecurity regulations, and other EU digital legislation such as the Data Act, Data Governance Act, Digital Services Act, and the AI Act.

      Navigating this broad spectrum of regulations can be complex, but that’s where we come in. At KPMG, we help you make sense of it all and build a privacy approach that’s not only compliant, but also strategic, scalable, and tailored to your business.

      Benny Bogaerts

      Partner, Technology | Advisory

      KPMG in Belgium


      Privacy makeover journey

      Either way, you’re in the right place. Whether you’ve just experienced a data breach or you're ready to rethink your entire privacy strategy or framework, we’re here to help. At KPMG, one of the services we offer is guiding you through your full privacy journey - from assessing where you stand today to implementing your new privacy approach.

      Just like any project aimed at enhancing a strategy or framework, we start with examining your present situation. What does your current privacy approach entail? Are you already adhering to all pertinent privacy regulations? Which components are present in your existing privacy framework, and where can we find room for enhancement? Based on this investigation, we design a roadmap together with you that is tailored to your organization. This tailored Privacy Roadmap outlines the key steps and priorities for the implementation of a robust privacy program.

      One of the first concrete steps in the implementation phase is often the review or the creation of a Register of Processing Activities (ROPA). Under the GDPR, it’s essential for all companies to maintain such an overview as part of their compliance with privacy regulations. This register provides a structured overview of the personal data processing activities within the organization and forms a legal foundation for demonstrating accountability under GDPR. It is also our starting point for determining further steps and priorities for implementation.

      From there, we also examine any privacy requirements that are relevant for local branches, carefully mapping the broader privacy landscape. Based on these insights, we refine the roadmap and continue with the broader implementation. This includes setting up clear policies and procedures, developing internal guidelines, and preparing training sessions. To keep things engaging for employees, we create bite-sized training modules, each tailored to specific topics relevant to your organization. To reinforce awareness and support, we also offer interactive workshops, helping employees understand and take ownership of their new responsibilities.

      Privacy tools

      Introducing OneTrust, a tool that can revolutionize your privacy landscape, with implementation support provided by KPMG to help you implement this privacy tool. OneTrust is in essence a large database that keeps track of details about your organization’s processing activities. For example: What is the goal of the activity? Which departments are involved in the activity? What is the scope of the data? Is the data used sensitive or non-sensitive? Which vendors have access to the data? In other words, OneTrust can give you a clear overview of all the data inside your organization.

      One of the main benefits? Automation. You can set up your entire Register of Processing Activities and turn it into a dynamic tool by mapping it to your data flows and linking it to the systems where the data is stored. We can even go a step further by automating your DSR workflow and linking it to the systems where the data is stored to allow for a fully automated response.

      Our Cyber Privacy team provides end-to-end support for the implementation of the OneTrust platform, including full set-up and tailored customization to meet your organization's specific needs and integrations.

      GDPR quick scan

      Want to assess your GDPR privacy status without a full transformation journey? At KPMG, we also provide assessments to determine the progress of your privacy journey. During these assessments we identify key privacy and cybersecurity risks, gaps, and areas for improvement. This can range from very broad to very specific; such as the identification of personal and sensitive data to data flow mapping, review of records of processing activities, review of access controls, as well as data minimization and purpose limitation.



      Did you know

      At KPMG, we assist clients in implementing comprehensive security privacy frameworks? All the activities highlighted in this magazine can be leveraged to support your organization on its privacy journey.


      What did we learn?

      In today's interconnected world, privacy has become more critical than ever before. The increasing reliance on digital technologies and the vast exchange of personal data emphasize the significance of robust privacy frameworks to safeguard individuals' information and maintain trust in the digital ecosystem. Organizations must prioritize privacy measures to address evolving data protection challenges and ensure compliance with regulations, reflecting the heightened importance of privacy in the contemporary landscape.

      We at KPMG can support your organization throughout your privacy journey! Our team can assist you in implementing and optimizing privacy tools like OneTrust, conducting assessments to gauge your privacy status, and navigating the complexities of data protection regulations. With our expertise and personalized approach, we ensure that your organization remains compliant, secure, and trusted in handling sensitive information. Let us guide you every step of the way in your privacy journey to safeguard your data and build stakeholder trust.



      Explore our latest insights on cybersecurity

      KPMG Technology services.

      Stay informed

      Be the first to know about top business trends that can drive success for your company.

      stay informed