{"id":576974,"date":"2025-06-15T19:38:10","date_gmt":"2025-06-16T02:38:10","guid":{"rendered":"https:\/\/www.genesys.com\/blog\/post\/navigating-the-new-era-of-security-privacy-and-compliance"},"modified":"2025-06-15T19:39:01","modified_gmt":"2025-06-16T02:39:01","slug":"navigating-the-new-era-of-security-privacy-and-compliance","status":"publish","type":"blog","link":"https:\/\/www.genesys.com\/en-sg\/blog\/post\/navigating-the-new-era-of-security-privacy-and-compliance","title":{"rendered":"Navigating the New Era of Security, Privacy and Compliance"},"content":{"rendered":"<div class=\"wpb-content-wrapper\"><p>[vc_row][vc_column][vc_column_text css=&#8221;&#8221;]<span style=\"font-weight: 400;\">Data privacy regulations are evolving across jurisdictions and countries and increasing in their scope. At the same time, artificial intelligence (AI) is accelerating risk exposure. This can put organisations under pressure to not only protect their environments but also prove that they\u2019re doing so. That requires more than just putting an &#8220;X&#8221; in your compliance checkbox.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Security, privacy and compliance concerns are operational realities. Regulatory frameworks like the <a href=\"https:\/\/www.genesys.com\/blog\/post\/understanding-your-role-in-the-eu-ai-act-and-dora-compliance\" target=\"_blank\" rel=\"noopener\">EU AI Act<\/a>, <a href=\"https:\/\/www.genesys.com\/resources\/navigating-compliance-with-the-digital-operational-resilience-act\" target=\"_blank\" rel=\"noopener\">Digital Operational Reliance Act (DORA)<\/a>, <a href=\"https:\/\/www.genesys.com\/trust\/gdpr\" target=\"_blank\" rel=\"noopener\">EU GDPR<\/a>, EU Data Act, Health Insurance Portability and Accountability Act (HIPAA) and the California Consumer Privacy Act (CCPA) require demonstrable compliance \u2014 and enforcement is escalating. A data breach today doesn\u2019t only result in financial penalties; it could damage a company\u2019s reputation and trigger customer flight in an era where switching providers is easier than ever.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><a href=\"https:\/\/www.genesys.com\/en-sg\/blog\/post\/balancing-innovation-with-responsible-ai\" target=\"_blank\" rel=\"noopener\">As businesses look to scale securely and responsibly<\/a>, several capabilities will be essential to running compliant operations. These include the ability to verify how vendors implement security controls and handle sensitive data, <a href=\"https:\/\/www.genesys.com\/en-sg\/resources\/comprehensive-guide-to-genesys-cloud-ai\" target=\"_blank\" rel=\"noopener\">how AI models are trained and used<\/a>, what safeguards are in place, what documentation is available for due diligence and the vendor\u2019s approach to supporting its customers\u2019 due diligence process.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This article explains why your organisation needs user-friendly tools to help close the information gap in order to reduce risks with AI and strengthen compliance strategies.<\/span>[\/vc_column_text][vc_row_inner][vc_column_inner][vc_column_text css=&#8221;&#8221;]<\/p>\n<h3><span style=\"font-weight: 400;\">Increasing Adoption of Directives and Regulations<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Privacy is one of the two primary areas of the global regulatory environment. While the GDPR in the EU led the way in privacy regulations eight years ago, other regions and states are quickly catching up with their own privacy laws. This includes Australia, several countries in Asia and California.<br \/>\n<\/span><br \/>\n<span style=\"font-weight: 400;\">Within the EU, several cloud providers have announced plans for EU Sovereign Cloud services. The <a href=\"https:\/\/www.genesys.com\/en-sg\/genesys-cloud\" target=\"_blank\" rel=\"noopener\">Genesys Cloud<\/a><\/span><sup><span style=\"font-weight: 400;\">\u2122<\/span><\/sup><span style=\"font-weight: 400;\"> platform is already available in 14 core regions and Genesys has announced plans to deploy Genesys Cloud on EU Sovereign Cloud, providing our customers with more deployment options to meet regulatory and preferred compliance requirements.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Because of such strict regulations and directives, the public is increasingly aware of privacy as it relates to their digital footprint and their rights to have it secured. On top of the directives and regulations around privacy are the evolving challenges of AI, the second primary area of global regulations.<\/span>[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][vc_row_inner][vc_column_inner][vc_column_text css=&#8221;&#8221;]<\/p>\n<h3><span style=\"font-weight: 400;\">Handling Data in the Era of AI<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Public awareness of privacy rights extends to AI, and the knowledge that the information they input into an AI system could be used elsewhere. It\u2019s not necessarily private and there aren\u2019t necessarily \u201cring fenced\u201d systems protecting it.<br \/>\n<\/span><br \/>\n<span style=\"font-weight: 400;\">One of the purposes of the EU AI act is to categorise AI systems, how they can be used and their levels of risk. For example, scanning people\u2019s faces in a public place is categorised as an unacceptable risk and is therefore prohibited.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Systems categorised as high and medium risk still have transparency and other obligations, and some seemingly low-risk AI systems could fall into a higher risk category under certain use cases. Details like these are causing businesses to look more closely at the controls they need around AI.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The complexity and speed of change can make it difficult to manage controls \u2014 especially for those with limited resources. As the enforcement dates of new regulations draw closer, so does the potential risk of heavy fines. If a company hasn\u2019t kept on top of its training and education \u2014 or maybe isn\u2019t aware of every new law coming out \u2014 there can be pressure to get up to speed quickly.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Larger corporate entities and certain vertical industries, such as healthcare or financial services, tend to be better prepared for these directives because they\u2019re under more scrutiny by regulators for their management of sensitive data. But not all of them are fully prepared \u2014 and neither are many small and medium-sized businesses. These smaller businesses might be going through impact assessments and trying to understand if their customer data is at risk. And if so, what do they need to do about it?<\/span>[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][vc_row_inner][vc_column_inner][vc_column_text css=&#8221;&#8221;]<\/p>\n<h3><span style=\"font-weight: 400;\">Manually Managing Compliance Opens the Door to Risks<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Businesses are doing a lot of manual work to keep up with security, privacy and compliance regulations, especially with the increasing risks of non-compliance. In some cases, rather than mandating a data protection officer or a data privacy officer, which many businesses have, regulators are now pointing to C-level executives and board members as the liable parties if there\u2019s a breach.<br \/>\n<\/span><br \/>\n<span style=\"font-weight: 400;\">There\u2019s also mandatory training for executives. At a minimum, executives must understand the framework of what&#8217;s being introduced, and that information must cascade down to the rest of the business.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In addition to the financial fines that can impact profitability, there\u2019s also a massive risk to reputation. Nobody wants their data stored at a company known for a data breach.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The speed of negative news can translate into fast and massive cancellations of a company\u2019s products and services. Month-to-month subscription models are common in consumer entertainment and other industries, making it very simple for customers to move on to your competitor. Once you\u2019ve lost trust, it can be costly to regain.<\/span>[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][vc_row_inner][vc_column_inner][vc_column_text css=&#8221;&#8221;]<\/p>\n<h3><span style=\"font-weight: 400;\">Build Customer Trust with a Vendor You Can Trust <\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Any business looking for assistance with their compliance and security issues should look carefully at how vendor solutions use data and the guardrails around its use. It\u2019s not enough to merely see on a vendor\u2019s website that they have a specific certification and accept a claim as validation that the vendor is compliant.<br \/>\n<\/span><br \/>\n<span style=\"font-weight: 400;\">This was the driver behind the<\/span> <a href=\"https:\/\/spc.genesys.com\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Genesys Security, Privacy and Compliance (SPC) Portal<\/span><\/a><span style=\"font-weight: 400;\">, which provides up-to-date compliance documentation and certifications to our partners and direct customers\u2014all in one central location. The portal includes attestations of compliance, penetration testing reports, Data Protection Impact Assessment (DPIA), Transfer Impact Assessment (TIA), AI model Cards (transparency reports) and best practices documentation. It also has in-depth details, including videos on topics like the encryption used by the Genesys Cloud platform, Genesys SDLC approach.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Beyond some of the use cases listed above, the SPC Portal includes a COE AI assistant to help improve efficiency and make search a better self-service experience, as it surfaces answers from multiple applicable managed sites and resources within Genesys.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Other trial tools in the Portal, available through a signed Free Trial Agreement, demonstrate how the Genesys Cloud APIs can be used to give you a deeper look into your own organisation. For example, you might use the tools to:<\/span><\/p>\n<ul>\n<li><span style=\"font-weight: 400;\">Build reports and trends for security risks.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Audit and configure alerts for monitoring security, privacy and compliance risks related to your Genesys Cloud organisation.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Address data subject requests in an automated fashion.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Using APIs to create your own tools can help you integrate these tools within your existing compliance dashboards and portal, enabling you to simplify your regulatory compliance job.<\/span>[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][vc_row_inner][vc_column_inner][vc_column_text css=&#8221;&#8221;]<\/p>\n<h3><span style=\"font-weight: 400;\">Accessing AI Model Cards for Full Transparency<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Genesys has a long history of building security into its product development, known as security by design, versus creating products and adding security to them as an afterthought or bolt-on feature. It\u2019s how we do business. We also believe that, as a company, we shouldn\u2019t have anything to hide about how we use AI in our products, and so we provide AI model cards.<br \/>\n<\/span><br \/>\n<span style=\"font-weight: 400;\">These standardised documents explain details about how AI and data is used in our products. Genesys uses them to show how a model was built, what data it was trained on, what we do with that data, how bias is addressed within the model and what limitations or risks may apply. This helps us establish our own benchmark for transparency, and it\u2019s another way to enable customers to keep up with changing regulations.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Using Genesys Cloud, these cards let you determine how your customers\u2019 data is flowing through the platform and understand why your AI isn\u2019t putting that data into a pool of publicly available information. <a href=\"https:\/\/spc.genesys.com\/\" target=\"_blank\" rel=\"noopener\">Using the SPC Portal<\/a>, you can download these documents for all our AI products.<\/span>[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][vc_row_inner][vc_column_inner][vc_column_text css=&#8221;&#8221;]<\/p>\n<h3><span style=\"font-weight: 400;\">Get Fast, On-Demand and Transparent Answers<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Most of us consume information on-demand; we\u2019re used to researching and getting the information we want on our own. Why not expect the same capability for more technical needs? The <a href=\"https:\/\/spc.genesys.com\/\" target=\"_blank\" rel=\"noopener\">Genesys SPC Portal<\/a> enables customers and partners to self-serve real-time certifications, AI feature documentation and even get AI-driven vulnerability insights.<br \/>\n<\/span><br \/>\n<span style=\"font-weight: 400;\">It can save time so that you can progress faster in decision-making without an intermediate step with a representative, as well as help reduce the risk of human error in manually researching and sharing information. And when you need a deeper level of detail, you can still contact us.<\/span><\/p>\n<p><a href=\"https:\/\/spc.genesys.com\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Watch the video<\/span><\/a><span style=\"font-weight: 400;\"> and see how Genesys Cloud customers can get fast answers to critical questions about security, privacy and compliance \u2014 unique to each environment.<\/span><\/p>\n<p><em><span style=\"font-weight: 400;\"><strong>Please note:<\/strong> The Security, Privacy and Compliance Portal is available to Genesys direct customers and partners with an existing non-disclosure agreement, while usage of some selective tools requires an additional trial agreement.<\/span><\/em>[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][vc_row_inner][vc_column_inner][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row]<\/p>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>[vc_row][vc_column][vc_column_text css=&#8221;&#8221;]Data privacy regulations are evolving across jurisdictions and countries and increasing in their scope. At the same time, artificial intelligence (AI) is accelerating risk exposure. This can put organisations under pressure to not only protect their environments but also prove that they\u2019re doing so. That requires more than just putting an &#8220;X&#8221; in your [&hellip;]<\/p>\n","protected":false},"author":1167,"featured_media":576326,"template":"","tax_priority":[54],"tax_blogtype":[17756],"tax_blogcategory":[15928,13117],"tax_contenttheme":[14902],"tax_bundle":[],"tax_contenttheme2":[18481],"tax_capability_sitewide":[16201,16352],"tax_products_programs":[16477,17548],"tax_buying_job":[16651],"tax_buyer_persona":[16887,16919],"tax_sector":[],"tax_segment":[17079,17104,17125],"class_list":["post-576974","blog","type-blog","status-publish","has-post-thumbnail","hentry","tax_priority-54","tax_blogtype-genesys-en-sg","tax_blogcategory-ai-and-machine-learning-en-sg","tax_blogcategory-cloud-en-sg","tax_contenttheme-improve-customer-experience-en-sg","tax_contenttheme2-level-up-your-technology-en-sg","tax_capability_sitewide-ai-and-automation-en-sg","tax_capability_sitewide-security-and-availability-en-sg","tax_products_programs-genesys-ai-en-sg","tax_products_programs-genesys-cloud-cx-en-sg","tax_buying_job-job-2-solution-exploration-en-sg","tax_buyer_persona-business-en-sg","tax_buyer_persona-technical-en-sg","tax_segment-enterprise-en-sg","tax_segment-midsized-en-sg","tax_segment-smb-en-sg","tax_content_type-blog-en-sg"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.genesys.com\/en-sg\/wp-json\/wp\/v2\/blog\/576974","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.genesys.com\/en-sg\/wp-json\/wp\/v2\/blog"}],"about":[{"href":"https:\/\/www.genesys.com\/en-sg\/wp-json\/wp\/v2\/types\/blog"}],"author":[{"embeddable":true,"href":"https:\/\/www.genesys.com\/en-sg\/wp-json\/wp\/v2\/users\/1167"}],"version-history":[{"count":3,"href":"https:\/\/www.genesys.com\/en-sg\/wp-json\/wp\/v2\/blog\/576974\/revisions"}],"predecessor-version":[{"id":576977,"href":"https:\/\/www.genesys.com\/en-sg\/wp-json\/wp\/v2\/blog\/576974\/revisions\/576977"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.genesys.com\/en-sg\/wp-json\/wp\/v2\/media\/576326"}],"wp:attachment":[{"href":"https:\/\/www.genesys.com\/en-sg\/wp-json\/wp\/v2\/media?parent=576974"}],"wp:term":[{"taxonomy":"tax_priority","embeddable":true,"href":"https:\/\/www.genesys.com\/en-sg\/wp-json\/wp\/v2\/tax_priority?post=576974"},{"taxonomy":"tax_blogtype","embeddable":true,"href":"https:\/\/www.genesys.com\/en-sg\/wp-json\/wp\/v2\/tax_blogtype?post=576974"},{"taxonomy":"tax_blogcategory","embeddable":true,"href":"https:\/\/www.genesys.com\/en-sg\/wp-json\/wp\/v2\/tax_blogcategory?post=576974"},{"taxonomy":"tax_contenttheme","embeddable":true,"href":"https:\/\/www.genesys.com\/en-sg\/wp-json\/wp\/v2\/tax_contenttheme?post=576974"},{"taxonomy":"tax_bundle","embeddable":true,"href":"https:\/\/www.genesys.com\/en-sg\/wp-json\/wp\/v2\/tax_bundle?post=576974"},{"taxonomy":"tax_contenttheme2","embeddable":true,"href":"https:\/\/www.genesys.com\/en-sg\/wp-json\/wp\/v2\/tax_contenttheme2?post=576974"},{"taxonomy":"tax_capability_sitewide","embeddable":true,"href":"https:\/\/www.genesys.com\/en-sg\/wp-json\/wp\/v2\/tax_capability_sitewide?post=576974"},{"taxonomy":"tax_products_programs","embeddable":true,"href":"https:\/\/www.genesys.com\/en-sg\/wp-json\/wp\/v2\/tax_products_programs?post=576974"},{"taxonomy":"tax_buying_job","embeddable":true,"href":"https:\/\/www.genesys.com\/en-sg\/wp-json\/wp\/v2\/tax_buying_job?post=576974"},{"taxonomy":"tax_buyer_persona","embeddable":true,"href":"https:\/\/www.genesys.com\/en-sg\/wp-json\/wp\/v2\/tax_buyer_persona?post=576974"},{"taxonomy":"tax_sector","embeddable":true,"href":"https:\/\/www.genesys.com\/en-sg\/wp-json\/wp\/v2\/tax_sector?post=576974"},{"taxonomy":"tax_segment","embeddable":true,"href":"https:\/\/www.genesys.com\/en-sg\/wp-json\/wp\/v2\/tax_segment?post=576974"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}