Governance, Risk and Compliance (GRC)
Compliance should become part of your organization’s security program. Your organization’s security strategy should include plans, a roadmap, and budgeting estimates of what projects should be considered to comply with the law requirements. Based on your organization’s business size, you should appoint an officer in charge of compliance efforts.

New processes should be created to define a privacy policy that states the rights of data subjects upon collecting, processing, and preserving their personal information. Administrative procedures should be amended to facilitate understanding and performing necessary practices for processing personal data. These processes should be followed by the organization staff, who is responsible for handling personal data in terms of the law. For instance, what should be notified to subjects? How to verify the data collected is correct and complete? How long should the data be collected, and when or how the data should be destroyed?