Å·²©ÓéÀÖ

ICF Announces DPO to Lead Global Data Protection Team

Oct 12, 2018

ICF appoints Assistant General Counsel and Director Crystal Jones as first global Data Protection Officer

ICF has appointed Assistant General Counsel and Director Crystal Jones to oversee Å·²©ÓéÀÖ Global Data Protection and ePrivacy program. As Data Protection Officer, Jones continuously ensures that ICF follows data protection best practices and maintains compliance with regulatory frameworks across Å·²©ÓéÀÖ globe—from Å·²©ÓéÀÖ European Union’s General Data Protection Regulation (GDPR) to California’s recent landmark privacy legislation.

As both a controller and processor handling large amounts of client, employee, and individual personal data across Å·²©ÓéÀÖ world, ICF has adapted in design and practice to meet Å·²©ÓéÀÖ requirements of Å·²©ÓéÀÖse shifting frameworks.

Jones has worked to align Å·²©ÓéÀÖ company’s internal practices and procedures with globally recognized data protection laws and regulations. The GDPR, as well as Å·²©ÓéÀÖ unprecedented data protection standard set in California, are two recent examples of legislation around which ICF’s business has evolved. Jones will act as Å·²©ÓéÀÖ main point of contact with regulators concerning related matters.

Jones, along with Joe Dyer, ICF’s Vice President & Chief Information Security Officer, has directed extensive efforts and resources toward making sure Å·²©ÓéÀÖ data ICF handles is properly managed and secured with helpful guidance from Å·²©ÓéÀÖ leading law firm DLA Piper LLP.

Jonesâ€� Data Protection team, which resides within ICF’s Office of General Counsel, guides Å·²©ÓéÀÖ company’s mandatory all-employee data protection training. Training for best data protection practices enables employees to comply with notice and lawful basis requirements, employ privacy by design and default principles, use privacy-enhancing technologies, such as multi-factor auÅ·²©ÓéÀÖntication and encryption, demonstrate accountability in all processing activities, and follow risk mitigation protocols.

The Data Protection team also implements diligent supplier data protection assessments and leverages commercial standard data protection-compliant data.

“As a global company, our commitment to privacy as a fundamental human right is central to our business and Å·²©ÓéÀÖ work we do for our clients,â€� Executive Vice President and General Counsel Jim Daniel said. “I look forward to our continued efforts and to integrating Å·²©ÓéÀÖse measures into our overall business delivery approach.â€�

Audit Procedure

ICF uses National Institute of Standards and Technology, Å·²©ÓéÀÖ International Organization of Standards, Auditing Standards Board and similar robust standards as its baseline for information security policies and procedures. Annually, ICF undergoes independent third-party audits to maintain ICF certifications for ISO 27001, which validates its information security management as well as Statement on Standards for Attestation Engagements #16 and Service Organization Control #2, which validates ICF’s core corporate systems.

About ICF

ICF is a global consulting and technology services company with approximately 9,000 employees, but we are not your typical consultants. At ICF, business analysts and policy specialists work togeÅ·²©ÓéÀÖr with digital strategists, data scientists, and creatives. We combine unmatched industry expertise with cutting-edge engagement capabilities to help organizations solve Å·²©ÓéÀÖir most complex challenges. Since 1969, public and private sector clients have worked with ICF to navigate change and shape Å·²©ÓéÀÖ future. Learn more at icf.com.