Tags:
Alain Geerts, Head of Governance & Service Management · March 01, 2025
We have seen in a previous article that privacy by design and by default is a fundamental principle that needs to be integrated into all aspects of a project, particularly where personal data is processed, which is often the case. By adopting this approach, organisations can comply with current regulations such as the GDPR, FADP and cantonal data protection laws, increase stakeholder confidence and reduce data security risks.
The Information Security and Data Protection (ISDP) concept, found, for example, in the Swiss HERMES methodology, is a good approach to data protection right from the design stage. It is increasingly important in today’s digital world.
The ISDP concept is an essential element in project management. It serves as a basis for defining the technical and organisational measures to ensure adequate data protection. Here are some of its key points:
Implementing the ISDS concept in a project requires a methodical approach and must be integrated from the earliest stages of the project.
Finally, bring together those responsible for these three areas and list the risks. Classify these risks according to their likelihood and impact. Then, for each risk identified, decide on actions to mitigate, maintain or outsource.
If risks could potentially harm an individual’s privacy or if sensitive data is being collected and processed, you should carry out a more detailed and formal impact assessment.
Finally, you will discuss the implementing regulations and the specific guidelines for implementing and auditing safeguards.
The process does not stop at the design stage. Ensure that the ISDP concept is dynamic and evolves as the project progresses, e.g., by incorporating new functionality that may prove necessary or by discovering specific features in the tools used.
Of course, the project manager is responsible for ensuring that the approach is followed. However, depending on the complexity of the project, the project manager will call on one or more specialists to effectively manage these aspects throughout the project. These experts will then use their experience to ensure all data security and protection measures are integrated and adhered to.
When data is a vital business asset, it is essential to guarantee its integrity, confidentiality, and availability, as well as the rights of the individuals concerned. The ISDP concept should, therefore, be at the heart of every project, demonstrating its role in protecting against external and internal threats, ensuring regulatory compliance, and safeguarding the company’s reputation. It complements information security and data protection requirements by providing an in-depth analysis of risks and the necessary protective measures.
Tags:
| Cookie | Duration | Description |
|---|---|---|
| __hssrc | Session | This cookie is set by Hubspot whenever it changes the session cookie. The __hssrc cookie set to 1 indicates that the user has restarted the browser, and if the cookie does not exist, it is assumed to be a new session. |
| _GRECAPTCHA | 5 months 27 days | This cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks. |
| cookielawinfo-checkbox-advertisement | 1 year | Set by the GDPR Cookie Consent plugin, this cookie is used to record the user consent for the cookies in the "Advertisement" category . |
| cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| CookieLawInfoConsent | 1 year | CookieYes sets this cookie to record the default button state of the corresponding category and the status of CCPA. It works only in coordination with the primary cookie. |
| JSESSIONID | session | New Relic uses this cookie to store a session identifier so that New Relic can monitor session counts for an application. |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |
| Cookie | Duration | Description |
|---|---|---|
| __cf_bm | 30 minutes | This cookie, set by Cloudflare, is used to support Cloudflare Bot Management. |
| __hssc | 30 minutes | HubSpot sets this cookie to keep track of sessions and to determine if HubSpot should increment the session number and timestamps in the __hstc cookie. |
| Cookie | Duration | Description |
|---|---|---|
| __hstc | 1 year 24 days | This is the main cookie set by Hubspot, for tracking visitors. It contains the domain, initial timestamp (first visit), last timestamp (last visit), current timestamp (this visit), and session number (increments for each subsequent session). |
| _ga | 2 years | The _ga cookie, installed by Google Analytics, calculates visitor, session and campaign data and also keeps track of site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognize unique visitors. |
| _ga_* | 1 year 1 month 4 days | Google Analytics sets this cookie to store and count page views. |
| _ga_JYCPSB48B8 | 2 years | This cookie is installed by Google Analytics. |
| _gat_gtag_UA_* | 1 minute | Google Analytics sets this cookie to store a unique user ID. |
| _gid | 1 day | Google Analytics sets this cookie to store information on how visitors use a website while also creating an analytics report of the website's performance. Some of the collected data includes the number of visitors, their source, and the pages they visit anonymously. |
| CONSENT | 16 years 2 months 25 days 10 hours | YouTube sets this cookie via embedded youtube-videos and registers anonymous statistical data. |
| hubspotutk | 1 year 24 days | This cookie is used by HubSpot to keep track of the visitors to the website. This cookie is passed to Hubspot on form submission and used when deduplicating contacts. |
| Cookie | Duration | Description |
|---|---|---|
| IDE | 1 year 24 days | Google DoubleClick IDE cookies are used to store information about how the user uses the website to present them with relevant ads and according to the user profile. |
| test_cookie | 15 minutes | The test_cookie is set by doubleclick.net and is used to determine if the user's browser supports cookies. |
| VISITOR_INFO1_LIVE | 5 months 27 days | A cookie set by YouTube to measure bandwidth that determines whether the user gets the new or old player interface. |
| YSC | Session | YSC cookie is set by Youtube and is used to track the views of embedded videos on Youtube pages. |
| yt-remote-connected-devices | never | YouTube sets this cookie to store the user's video preferences using embedded YouTube videos. |
| yt-remote-device-id | never | YouTube sets this cookie to store the user's video preferences using embedded YouTube videos. |
| Cookie | Duration | Description |
|---|---|---|
| VISITOR_PRIVACY_METADATA | 5 months 27 days | Description is currently not available. |