A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

Roquette
Jennifer Godin, Group Data Protection Officer
Driving Privacy Strategy in Complex Global Ecosystems


where she oversees global privacy and data protection compliance. With deep expertise in GDPR and international data regulations, she ensures that Roquette's operations align with evolving legal and ethical standards. Her work supports both innovation and trust across the company's global supply chain. In an exclusive interview to CIO Applications, she shared her insights on data protection and privacy.
Can you walk us briefly through your leadership role as Group Data Protection Officer? What are your key responsibilities and areas of focus?
As Data Protection Officer for the Group, I define our Privacy & Data Protection Strategy, and I oversee our related Data Protection Management System & Data Compliance Program.
I am business process owner for the following processes:
• Respect Privacy and Enable Trust
• Manage Privacy Risks and Controls
• Ensure Data Compliance
To keep these processes in operational condition and improve our level of compliance, I monitor (new) laws in terms of data protection, cyber security, data governance, AI, etc.
How can professionals effectively balance legal requirements with practical business realities when building or auditing a data protection framework?
You must be pragmatic and attentive to business. In an often-complex environment, all the parameters, business needs, technical and organizational constraints as well as the various legal obligations must be considered. In the face of this, practical measures must be recommended and harmonized as much as possible. More than finding a balance between legal requirements and business practices, we can improve internal processes.
This involves synergies between the Data Protection teams, the business and support functions.
What is your perspective on embedding a risk-based approach into a Data Protection Management System? Where should organizations start?
A risk-based approach is essential. It allows, with often limited resources, to focus efforts on data processing and assets that are most risky for the people concerned and for the company.
This also makes it possible to put in place appropriate resources according to the situation. Finally, it must be part of a continuous improvement process to increase the maturity and compliance of the Data Protection Management System, and to strengthen the trust of customers, employees, partners and supervisory authorities.
What best practices would you recommend for building a culture of privacy awareness and accountability across decentralized teams?
Data protection compliance is evolving and concerns all categories of data in the company to have an ethical approach to data aligned with the company's values”
Several factors can contribute to establishing a culture of privacy in decentralized teams as well as in an international group.
Here are some tips:
• Include in the company's data protection policy and internal guidelines rules on data protection awareness and training of individuals as well as on document and evidence management.
• Have dedicated communication and training channels accessible to all teams in the company and/or group entities.
• Have a visual identity and an annual communication plan.
• Define and manage awareness-raising and training actions in coordination with the company's Communication and HR functions.
• Have a network of local correspondents by function and/or by site and lead it.
• Lead days on themes common to Data Protection and other company functions (e.g. Data Cleaning Week with Digital and Sustainability, Privacy & Cyber Month with Digital and Cyber Security teams, etc.).
• Carry out local actions and events (teams and/or sites) in line with the communication carried out at the global level.
If you could give just one piece of advice to digital leaders trying to make meaningful changes in complex organizations, what would it be?
In complex organizations, it is useful to plan transformation projects involving many actors who do not all have the same challenges, but whose shared expectations and evaluation about the company's processes make it possible to achieve a more rational and efficient evolution of technical and organizational practices. In addition, this involvement of the actors in the entire design approach allows for better appropriation and facilitates the change management essential to these evolutions.
Please share any additional information you wish to contribute that will help us enhance the article.
Whatever the field of activity of a company, it is subject to numerous regulations and all its internal processes generate data processing supported by increasingly innovative digital solutions.
Corporate data and personal data are processed, stored and shared in structured and unstructured environments. Acting on the protection of personal data and respecting the rights of individuals contributes to strengthening the security of information systems and the trust of the Data Subjects and stakeholders.
Data protection compliance is evolving and concerns all categories of data in the company to have an ethical approach to data aligned with the company's values.
Weekly Brief
I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info


