LCOUNCIL法总专访 | 凯士比泵黄早早:数据合规治理与企业数字化转型的 协同发展

2024-06-04



LCOUNCIL法总专访

Exclusive Interview

法总专访栏目是LCOUNCIL在企业越发重视法务深层价值与创新赋能的背景下,开展的法总分享栏目,特别邀请知名企业法务、风控、合规总监,针对各自最擅长的领域倾囊相授,旨在为广大法务同行提供一个开放、创新的智库平台,深度接触行业顶尖专家的智慧洞察,分享您的成功实践和独到见解,推动法务领域的创新与发展。


LCOUNCIL诚挚地邀请各行业优秀法务同行加入,汇聚更多的智慧和力量,为行业搭建更加紧密的合作与学习网络,共同打造一个更加专业、创新和有影响力的法务智库。


若您希望成为LCOUNCIL法总专访栏目特邀嘉宾,欢迎扫描文末二维码与我们取得联系,让更多同行了解您的经验积淀与价值思考!


名企法务智库4.0上线

收纳资深法总专访精粹

扫码抢先预约领取






本期嘉宾

   Guest



黄早早

凯士比泵


上海凯士比有限公司

北亚法律顾问、中国区合规官、出口控制官(上海 &天津)、数据保护官(上海)


2024年3月29日,理购LCOUNCIL带队,与近50位企业法总、优秀法务同行来到上海凯士比泵有限公司,与上海凯士比泵有限公司北亚法律顾问、中国区合规官、出口控制官(上海 &天津)、数据保护官(上海)黄早早女士、上海市张江公证处主任助理应旭玢先生以及北京市金杜律师事务所上海分所合伙人虞磊珉律师,就“数据合规治理与企业数字化转型的协同发展”主题展开热切交流,在春意盎然与独具特色的凯士比园区度过了一段难忘的走访之旅。



本期法总专访,LCOUNCIL 再次邀请到黄早早总,聚焦于数据合规治理与企业数字化转型的协同发展话题,带来干货分享。






法总专访

   Exclusive Interview



Q1

上海凯士比泵在数字化转型上取得了傲人成就,可否请您介绍一下凯士比集团法律合规团队架构?团队在企业数字化转型的道路上扮演了怎样的角色?


向上滑动阅览

KSB Shanghai Pumps has made great achievements in digital transformation. Could you please introduce the legal compliance team structure of KSB Group? What role does the team play in the digital transformation of the enterprise?



从整个集团的法律合规团队架构来看,首先我们拥有一个庞大的团队,涵盖了传统的法务和合规职能,这是我们的Legal & Compliance部门。此外,我们还设立了专门的出口控制团队、商标和专利团队,并在总部设置了一名全职数据保护官,负责数据安全。这些职能共同构成了集团层面法律合规团队的整体架构。在各大区,我们会配置3~4名区域法务人员,而地方层面可能要看每个公司具体的实际需求,比如在业务体量较大的地方公司,如印度和法国的公司,还会设置全职的专门法务人员。


在数字化转型方面,其实整个集团都有截至2030年的整体数字化转型目标。在北亚区域,为了更好地推动和辅助企业的数字化转型,区别于常规的传统职能,我们特别成立了一个数字化委员会。在这个委员会中,我兼任了数据保护官的职务,以便与德国总部的数据保护官进行直接沟通,从而打通数据共享和跨境数据流通的渠道,高效推进以北亚为核心的数字化转型进程。


向上滑动阅览

Looking at the Legal Compliance team structure across the group, first of all we have a large team that covers the traditional legal and compliance functions, which is our Legal & Compliance department. In addition, we have a dedicated export control team, trademark and patent team, and a full-time data protection officer at headquarters responsible for data security. Together, these functions form the overall structure of the legal compliance team at Group level. In each region, we will deploy 3 to 4 regional legal personnel, and the local level may depend on the actual needs of each company, for example, in the larger business volume of local companies, such as India and France, will also set up full-time specialized legal personnel.

In terms of digital transformation, in fact, the entire Group has an overall digital transformation target up to 2030. In the North Asia region, in order to better drive and support the digital transformation of enterprises, separate from the conventional traditional functions, we have set up a digital committee. In this committee, I also assumed the role of Data Protection Officer in order to communicate directly with the data Protection Officer at the headquarters in Germany, so as to open up the channels of data sharing and cross-border data flow, and effectively promote the digital transformation process centered in North Asia.



Q2

作为一家跨国集团内的法律顾问,如何在不断变化的形势下履行各类常规职能?


向上滑动阅览

How does a legal adviser in a multinational organization perform routine functions in a constantly changing environment?




关于这个问题可能分两个背景来介绍。首先,我负责的区域包括中国、日本和韩国,总共覆盖10家公司,拥有1500名全职员工。除了与这些覆盖区域的公司进行沟通,我还需与德国总部各职能部门保持紧密联系。我的工作范围涵盖传统的法务、合规工作、进出口管控、知识产权管理、数据安全以及地方公司的总体治理。这要求我不仅担任独任法务,还需扮演多面手的角色。在处理这些工作时,我始终秉持积极拥抱不同文化的态度,尝试理解并尊重各个国家和地区的文化背景和语言习惯。在与德国集团同事以及下属分子公司沟通时,我会先了解对方的文化习惯,扮演倾听者的角色,然后再输出自己的理念和想法,以达到更好的沟通效果。


其次,我始终保持好奇心和热情。好奇心驱使我不仅关注法律和合规领域的知识技能,还对公司业务和不同职能部门的领域进行学习和了解。热情则是我自我驱动的动力,使我能够源源不断地提升自己,为职位产出做出贡献。我相信能够有所发展的,不论是法律专业出身还是后来走上法律工作者道路的,其实都能够看到他们保持的热情是一种自我驱动的动力,不是靠外界的一些认可。不同于一些经验总结,这些自我要求也十分重要。



向上滑动阅览

There are two possible backgrounds to this issue. First, I cover 10 companies in China, Japan and Korea, with 1,500 full-time employees. In addition to communicating with the companies in these coverage areas, I also need to maintain close contact with the functional departments in the German headquarters. My work spans traditional legal affairs, compliance work, import and export controls, intellectual property management, data security and general governance of local companies. This requires me not only to act as a sole legal counsel, but also to play the role of a generalist. In handling these tasks, I have always adopted a positive attitude of embracing different cultures, and tried to understand and respect the cultural backgrounds and language habits of different countries and regions. When communicating with colleagues in the German group and affiliated companies, I will first understand the cultural habits of the other side, play the role of listener, and then export my own ideas and ideas to achieve better communication results.

Secondly, I am always curious and enthusiastic. Curiosity drives me not only to focus on knowledge and skills in the field of law and compliance, but also to learn and understand the fields of the company's business and different functional departments. Passion is the driving force that drives me to continuously improve myself and contribute to the output of the position. I believe that those who can make progress, whether they are legal professionals or later embark on the road of legal workers, can actually see that their enthusiasm is a self-driven power, not some external recognition. Unlike some lessons learned, these self-requirements are also important.



扫码领取完整版

名企法务智库4.0


Q3

法务在企业数字化转型和数据安全中的关注要点有哪些?比如说物联网数字经济的新生态带来的更多实操考虑,销售合同条款要点数据安全与合规要求的集中体现,或者是数字化管理委员会建立完善的合规管理体系。


向上滑动阅览

What are the key concerns of legal in enterprise digital transformation and data security? For example, the new ecology of the Internet of Things digital economy brings more practical considerations, the centralized embodiment of the key data security and compliance requirements of the sales contract terms, or the establishment of a perfect compliance management system by the digital Management Committee.




关于这个问题,也很感谢您提到的三个方面和例子,在探讨这些具体工作内容之前,我想先阐述一下我们法务的工作思路。企业化数字化转型是需要驱动各个职能来提供支持。在转型过程中,法务需要主动适应并融入这一变革。我们的工作思路主要体现在两个方面:首先,要从后端走向前端,深入了解转型战略、业务涉及领域以及产品研发情况。虽然法务人员不可能像技术和商务人员那样专业,但掌握这些背景信息对于解决实际问题至关重要。其次,法务人员应尝试从单纯的法律事务角色转变为总务角色,拓宽自身的技术、商务甚至是财务,尤其是税务角度的视野和行业内的嗅觉,了解行业动态,以便在坚持法律原则的前提下,提供更为全方位的支持。遵循这样的工作思路,我们可以更好地关注数字化转型和数据安全中的关键问题。


那回到您前面问题里提到的三方面的一些实际工作,首先我们传统生产硬件的数字化转型的一个大背景是物联网。在数字经济的浪潮下,从战略角度来看,我们需要勇于尝试新的方法。在此背景下,法务在物联网和数字经济新生态中,更多地以业务合作伙伴的身份出现,从业务角度提供支持。除了了解业务状况,法务还需关注立法动态,为业务提供法律建议和解决方案。这是法务在物联网领域的主要职责。


对于销售合同条款的要点,我想分享以下经验。我们公司最初主要从事泵阀备件等硬件制造,属于传统制造业。在研究销售合同条款时,我们遇到了一些挑战。为了制定一套适用于软件销售的条款,我们几乎是从零开始。与硬件销售不同,软件销售涉及到数据安全、工业数据分类定级、数据的收集、处理、存储、共享以及保存期限等特定问题,这些都需要在合同中明确相关条款。同时,我们还考虑了个人信息保护等方面的内容。到2023年,我们成功实现了软硬件结合的销售模式。销售团队可以根据实际需求,选择适用的硬件或软件条款,或者同时选择两者,从而实现了传统硬件与软件的打包销售。我们制定了一套十分完整的、同时满足硬件和软件销售需求的合同范本。然而,从法务的角度来看,我们的工作并未结束。我们需要根据立法动态和业务的发展情况,不断对这套销售合同条款进行更新和调整,以适应法律和市场的变化。这是关于销售合同条款我想要分享的内容。


第三点是关于我们北亚特有的数字化管理委员会的建立。在该委员会中,我担任数据保护官的角色,这是一个完全独立的职能。除了数据保护之外,我还负责数字化相关的所有知识产权布局工作,包括商标注册、专利软件著作权等的维护。我直接向数字化管理委员会的主任汇报,而委员会的主任由我的直接上级,即北亚区总裁担任。数字化管理委员会是专为整个集团及区域数字化转型而建立的,旨在整合现有架构下的最优资源,以推进数字化转型工作。我接受了这个挑战,并获得了中国网络安全认证中心CCRC的认证。对于同处制造业或面临多元化数字化转型的企业,如果法务支持和数据安全工作较为集中,建议考虑构建类似的虚拟组织,以便更有效地开展与数字化相关的工作。



向上滑动阅览

With regard to this issue, thank you very much for the three aspects and examples you mentioned. Before discussing these specific work contents, I would like to explain the work thinking of our legal department. Enterprise digital transformation is needed to drive each function to provide support. In the process of transformation, legal services need to actively adapt and integrate into this change. Our work ideas are mainly reflected in two aspects: First, from the back end to the front end, in-depth understanding of the transformation strategy, business areas and product development. While legal professionals cannot be as professional as technical and business professionals, having this background information is essential to solving practical problems. Secondly, legal personnel should try to change from the role of simple legal affairs to the role of general affairs, broaden their technical, business and even financial perspective, especially tax perspective and the sense of smell in the industry, to understand the industry dynamics, in order to adhere to the premise of legal principles, to provide more comprehensive support. By following this line of work, we can better focus on key issues in digital transformation and data security.

To go back to some practical work on the three aspects mentioned in your previous question, first of all, a big background of the digital transformation of our traditional production hardware is the Internet of Things. In the wave of digital economy, from a strategic point of view, we need to be brave to try new approaches. In this context, in the new ecology of the Internet of Things and the digital economy, legal appears more as a business partner to provide support from a business perspective. In addition to understanding the state of the business, legal professionals also need to follow legislative developments to provide legal advice and solutions for the business. This is the main responsibility of legal affairs in the field of iot.

For the gist of the terms of the sales contract, I would like to share the following experience. Our company was originally mainly engaged in the hardware manufacturing of pump and valve spare parts, which belongs to the traditional manufacturing industry. We encountered some challenges when researching the terms of the sales contract. To develop a set of terms that would apply to software sales, we started almost from scratch. Unlike hardware sales, software sales involve specific issues such as data security, classification and grading of industrial data, collection, processing, storage, sharing and retention period of data, all of which need to be clearly defined in the contract. At the same time, we also consider aspects such as the protection of personal information. By 2023, we have successfully achieved a sales model that combines hardware and software. The sales team can choose the applicable hardware or software terms, or both, according to the actual needs, thus realizing the packaging of traditional hardware and software. We have developed a very complete set of contract models to meet both hardware and software sales needs. However, from a legal point of view, our work is not over. We need to update and adjust this set of sales contract terms according to legislative dynamics and business development to adapt to changes in the law and the market. This is what I want to share about the terms of the sales contract.

The third point is about the establishment of our unique digital management committee in North Asia. Within the commission, I have the role of Data Protection Officer, which is a completely separate function. In addition to data protection, I am also responsible for all intellectual property layout work related to digitalization, including trademark registration, maintenance of Copyrights for patented software, etc. I report directly to the Director of the Digital Management Committee, who is headed by my immediate superior, the President of North Asia. The Digital Management Committee has been established specifically for digital transformation across the Group and regions to bring together the best resources within the existing structure to advance digital transformation efforts. I accepted the challenge and was certified by the China Network Security Certification Center (CCRC). For companies in the same manufacturing sector or facing diversified digital transformation, if legal support and data security work is more centralized, it is recommended to consider building a similar virtual organization to carry out digital-related work more effectively.




Q4

您能分享一下上海凯士比泵在数字化转型过程中,法务团队与其他部门是如何紧密合作确保数据安全和合规性的?


向上滑动阅览

Can you share how the legal team worked closely with other departments to ensure data security and compliance during the digital transformation process of KSB Shanghai Pumps?




关于这个问题,主要分为三个层面,其实和我覆盖的区域以及汇报线也是直接匹配的。首先是地方公司层面,这是实际工作层,包括技术人员、销售团队、财务和产品管理等职能部门,他们负责具体落实数字化转型的工作,如设计报价、研发产品等时间和金钱的投入。其次是区域管理层面,作为我所在的层级,它更多作为一个战略层面,负责制定战略发展方向和业务布局,指引未来的拓展方向和重大投资。在确定战略方向后,会交由地方公司层面来推行具体举措的落实。最后是总部层面,我将其界定为汇报层面,因为总部在德国,沟通主要是定期或不定期的成果展示,同时需要兼顾德国总部的数据安全要求。与总部的汇报主要为了打通和欧洲的数据交流、跨境数据流动,同时符合中国和欧盟的法律法规。我目前会直接对接到这三个层面,根据不同层面的定位提供相应的支持。理想状态下,地方层面应有专门的法务人员提供日常支持,而区域和总部层面应有更高级别的人员统筹安排,以在符合总部期待的前提下,在中国范围内最大化地推进数字化转型工作。



向上滑动阅览

About this issue, it is mainly divided into three levels, in fact, it is directly matched with the area I cover and the reporting line. The first is the local company level, which is the actual work level, including technical staff, sales teams, finance and product management functions, who are responsible for the concrete implementation of the digital transformation work, such as design quotation, product development and other time and money investment. The second is the regional management level. As my level, it is more of a strategic level, responsible for formulating the strategic development direction and business layout, guiding the future expansion direction and major investment. After determining the strategic direction, the implementation of specific initiatives will be carried out at the local company level. Finally, at the headquarters level, I define it as the reporting level, because the headquarters is in Germany, and the communication is mainly a regular or irregular display of results, while taking into account the data security requirements of the German headquarters. Reporting to the headquarters is mainly to open up data exchange and cross-border data flow with Europe, while complying with Chinese and EU laws and regulations. At present, I will directly receive these three levels and provide corresponding support according to the positioning of different levels. Ideally, there should be dedicated legal staff at the local level to provide day-to-day support, while there should be a higher level of coordination at the regional and headquarters level to maximize digital transformation efforts across China while meeting headquarters' expectations.




Q5

在数字化转型的背景下,您如何看待数据保护法律的发展及其法务工作的影响?


向上滑动阅览

In the context of digital transformation, how do you see the development of data protection law and the impact of its legal work?




关于这个问题,我认为可以从两个方面来看。首先,对于我们法务工作者自身来说,在数字化转型的背景下,我们需要保持开放的态度,不断学习新的立法动态,并接纳和改变自己的工作思维。这既是一种挑战,也是一种机遇。如果我们能够抓住机遇并迎接挑战,就有可能在数字化转型的大背景下脱颖而出,成为与业务和战略配合更紧密的法务人才。


另一方面,从整个大环境来看,数字化转型并不仅仅与产品和研发相关。虽然传统制造业的数字化转型可能没有互联网企业或人工智能企业那么直接或快速,但我们仍然可以感知到整个世界层面的数字化转型对营商环境产生的深远影响。作为法律工作者,我们应该意识到许多立法和司法实践可能会落后于营商环境的变化。因此,在数字化转型的浪潮中,我们需要保持敏锐的嗅觉,不仅要学习新的立法,还要判断哪些立法和改变可能只是过渡性的,哪些立法有可能在未来通过其他解释或条例的方式予以修正,以便更好地指导实践。这样的大环境也有利于提升我们法律人士在日常工作中的法律思维和法律嗅觉。



向上滑动阅览

Regarding this issue, I think we can look at it from two aspects. First of all, for us legal workers themselves, in the context of digital transformation, we need to keep an open attitude, constantly learn new legislative dynamics, and accept and change our working thinking. This is both a challenge and an opportunity. If we can seize the opportunities and meet the challenges, we have the potential to stand out in the context of digital transformation and become more aligned with the business and strategy of the legal talent.

On the other hand, in the overall context, digital transformation is not just about products and research and development. While the digital transformation of traditional manufacturing may not be as direct or rapid as that of Internet companies or AI companies, we can still sense the profound impact of digital transformation on the business environment at the world level. As legal practitioners, we should be aware that many legislative and judicial practices may lag behind changes in the business environment. Therefore, in the wave of digital transformation, we need to maintain a keen sense of smell, not only to learn new legislation, but also to judge which legislation and changes are likely to be only transitional and which legislation is likely to be amended in the future by way of other interpretations or regulations to better guide practice. Such an environment is also conducive to enhancing the legal thinking and legal sense of our legal professionals in their daily work.




Q6

随着技术的不断发展,您认为未来数据安全和法务工作会面临哪些新的挑战?


向上滑动阅览

As technology continues to evolve, what new challenges do you see for data security and legal work in the future?




在数字化转型和营商环境变化的背景下,法务工作者面临着新的职业选择和发展路径。一方面,我们可以选择继续从事传统的法务工作,专注于合同、诉讼和合规等领域。另一方面,我们也可以考虑将数据安全和数据保护纳入自己的工作范围,成为一个更全面的法务人才。这一选择可能会带来新的就业机会,尤其是在外资企业和上市公司中,数据安全和数据保护官的角色将越来越重要。然而,这一转变也面临着一些挑战,因为不同的公司会根据自身的成本和架构来考虑是否培养现有的人员来承担这一额外的工作分支。作为法务工作者,我们应该慎重考虑这一职业转型的机会,如果所处的公司和行业确实有这样的转型计划,那么我们可以考虑接受这一挑战,让自己的职业发展更为全面。这不仅能够提升我们的职业素养,还能够为公司和行业的发展做出更大的贡献。



向上滑动阅览

In the context of digital transformation and changes in the business environment, legal professionals are facing new career choices and development paths. On the one hand, we can choose to continue our traditional legal practice, focusing on areas such as contracts, litigation and compliance. On the other hand, we can also consider incorporating data security and data protection into our work scope to become a more comprehensive legal talent. This option could lead to new job opportunities, especially in foreign-owned enterprises and public companies where the role of data security and data protection officers will become increasingly important. However, this transition comes with some challenges, as different companies consider whether to train existing personnel to take on this additional branch of work based on their own cost and structure. As legal professionals, we should carefully consider this opportunity for career transformation, and if the company and industry we work in does have such a transformation plan, then we can consider accepting this challenge to make our career development more comprehensive. This can not only enhance our professional quality, but also make a greater contribution to the development of the company and the industry.




黄总寄语


在我眼中,Lcouncil不仅是一个平台,更是一个契机,一个为我们企业法律工作者量身打造的学习、交流与自我提升的综合舞台。深知法律工作的本质离不开文字的精准与人际的交往,我特此借用“让法律学习更有趣”这一宣传语,以表达我的愿景。期望Lcouncil能够赋予法律学习更多的趣味性,同时也能为我们的工作注入源源不断的活力和创意。愿每一位在Lcouncil相聚的同行,都能在这里找到成长的动力,共同为企业的法律事务贡献智慧与力量。这是我对Lcouncil的深切期望与寄语。




法总专访栏目邀请



LCOUNCIL依托法总专访平台,邀请标杆企业法总、合规总等优秀法律人,聚焦于自身擅长话题,进行专业、有深度的分享,为更多法务带来法务日常工作、管理策略的思考灵感,栏目开设至今受到众多法务同行的认可。


若您希望成为LCOUNCIL法总专访栏目特邀嘉宾,欢迎扫描二维码与我们取得联系,让更多同行了解您的经验积淀与价值思考!



分享