
Close gaps to a regulation
Example: Compliance with EU General Data Protection Regulation (GDPR)
Client Problem (example)
In 2018 the European Union introduced General Data Protection Regulation (GDPR). The GDPR significantly overhauled how organizations must handle personal data, introducing strict requirements for transparency, consent, data minimization, and individual rights. This regulation impacts all businesses that handle EU citizen data.
A client is struggling with how to effectively, and efficiently, ensure compliance with the GDPR given the complex, de-centralized, nature of their global business. A consulting or audit program would be hugely costly to implement and would likely not ensure sustained learning and compliance.

Client Objective
The client seeks to:
- Ensure on-going compliance with the EU Global Data Protection Regulation (GDPR).
- Ensure the right employees (within its businesses around the globe) are engaged to understand and assess compliance.
- Minimize the administrative burden and costs associated with ensuring on-going compliance.
- Complement (not duplicate) its existing learning, risk management and compliance systems.
How Method8 is used to meet the client’s objectives
Aspire
- The client assigns an Accountable Person and Method8 assigns a Practitioner to work with them.
- The GDPR requirements are evaluated and priortized based on the content of the client’s business and risk profile.
- The risk-assessed GDPR is transformed into an engaging, and measurable, Method8 formative assessment.
- The assessment contains education materials specific to the relevant GDPR requirements.
- The assessment is designed to measure both employee understanding of, and compliance with, the requirements.
- Multiple Method8 tools / techniques are built into the assessment to improve employee engagement and insight.
- The client defines an accountable person at each of their businesses to lead the assessment and identifies the preferred mix of team members (both internal and external) assigned to undertake the assessment (most Method8 assessments are taken as a team).
- 5.The client integrates the Method8 assessment into its existing:
- Learning Management System (LMS) GDPR training module (completion of the assessment is logged as part of a course)
- The Compliance Management System is updated to include the Method8 assessment.
Assess
- The client deploys the Method8 GDPR assessment to its businesses.
- The assessment is taken as a team—building a deeper understanding of the requirements and self-assessing current compliance / alignment with the regulation. Significant team discussion and debate unfolds during this self assessment process.
- Method8 platform functionality is used to escalate questions / blockers that require clarification from client or regulatory expertise.
- Teams identify the actions required to close gaps to the regulation and identify blockers that will require internal leadership support.
Act (and AI)
- Method8’s AI agent is used to review maturity scoring, gaps, actions and other data to provide enterprise-level insights.
- The clients confirm and initiate gap closure actions across each business and, if required, at an enterprise level.
- Clients track gap closure and determine the next assessment point.
- Clients provide feedback (and data as required) to auditors and regulatory bodies to clarify requirements and verify compliance.
Outcomes
- Engaged Workforce—The client engaged its own workforce to build understanding and self-identify gaps and improvement opportunities.
- Effective Compliance—The client was able to both educate and empower its dispersed employees to ensure local compliance.
- Reduced Costs—The client was able to efficiently implement the regulation by using Method8’s approach.
- Sustained Results—The client uses Method8 as an on-going process to ensure compliance with the regulation.
- Integration—The client integrated Method8 assessment into its existing learning, risk and compliance management systems.
- Improved Audit—The client was able to refine and focus its future GDPR audits by using the Method8 assessment data available.
Create a better way to learn and improve
Discover how Method8 helps organizations transform standards and
practices into performance