Jasmina Hudić works at the intersection of personal data protection, GDPR, management systems, information security, cybersecurity and auditing. Through Korektiva, she helps organizations understand regulatory requirements and turn them into practical processes that work in everyday business.
Her approach goes beyond policies, procedures, and certificates. For Jasmina, effective compliance is ultimately about people, responsibility and the way an organization behaves when regulations are no longer just words on paper.
As businesses face growing privacy obligations, cybersecurity risks, and new technologies such as artificial intelligence, the relationship between compliance and organizational culture has become more important than ever. We spoke with Jasmina about her professional journey, the reality behind GDPR compliance, the connection between privacy and cybersecurity, and what organizations can do to build systems that genuinely support the way they work.
The Compliance Journey
The Women Today: Jasmina, your professional work brings together GDPR, personal data protection, ISO management systems, information security, cybersecurity and auditing. What brought you to this combination of disciplines, and what did you want to achieve when you established your approach through Korektiva?
Jasmina: “My professional journey developed gradually. I started with management systems, and that gave me a very structured way of looking at organizations. You learn to look at processes, responsibilities, risks, and documentation, but you also learn to ask whether those processes work in practice.
When I became more involved in personal data protection, I started seeing another side of the same picture. Personal data is present throughout an organization. It is part of HR, sales, marketing, customer service, finance, IT, and many other areas. Once you begin looking at how that information is collected, used, stored, and shared, you realize that privacy is connected to almost every business process.
Information security and cybersecurity add another dimension. If an organization wants to protect personal data, it also needs to understand who has access to information, how systems are protected and what happens when something goes wrong.
Although these areas have different requirements, I see a strong connection between them. They all involve understanding risks, defining responsibilities, and creating processes that people can follow.
That thinking is very much a part of Korektiva. I wanted to focus on practical solutions rather than compliance for the sake of documentation. A policy is useful when it reflects how an organization works. A management system is valuable when employees understand it and when management can use it to make better decisions
For me, the real purpose of compliance is not simply to say that an organization meets a requirement. It is to help the organization understand its responsibilities, manage its risks and work in a more structured and responsible way.”
From GDPR Documentation to Real Privacy Culture
The Women Today: GDPR has been part of the European business environment for several years, yet many organizations still associate it mainly with policies and paperwork. What is the difference between having GDPR documentation and building a culture of data protection?
Jasmina: “The difference is between knowing what you have written and knowing what you do.
An organization can have privacy policies, procedures, records of processing activities, and contracts that look very professional. But if employees do not know what to do when a customer requests access to their personal data, when information is sent to the wrong person, or when they notice a potential data breach, there is still a gap between documentation and reality.
That is why I prefer to understand the organization first. I want to know what personal data it processes, why it processes it, who has access to it, where it goes and how long it is kept. Only after understanding those processes can, we properly assess whether the existing measures are appropriate.
The same applies to the role of employees. People do not need to become privacy lawyers, but they need to understand how data protection affects their responsibilities.
An employee in HR will deal with personal data differently from someone in sales, marketing or IT. Training and guidance should therefore be relevant to the actual work they perform.
I also think organizations sometimes forget that GDPR is not a one-time project. You cannot prepare the documentation, put it in a folder and consider the matter finished. Processes change, technology changes, employees change, and the business itself changes.
Good data protection therefore requires continuous attention.
For me, the strongest privacy culture is one where employees understand why protecting personal data matters and naturally consider it when making everyday decisions. That is much more valuable than simply having a collection of documents prepared for an audit.”
Privacy, Cybersecurity and the Future of Compliance
The Women Today: With cybersecurity threats becoming more sophisticated and organizations increasingly using cloud services and artificial intelligence, how should businesses bring privacy and information security together?
Jasmina: “I think organizations first need to understand that privacy and information security are not the same thing, but they are very closely connected.
If you process personal data, you need to think about how that information is protected. Who can access it? Is that access necessary? Where is the information stored? What happens if an account is compromised? What happens if data is lost? How quickly can the organization respond to an incident?
These are security questions, but they can also have very serious privacy consequences.
My cybersecurity education has helped me understand the technical side of these risks, while my work with GDPR gives me another perspective on what those risks mean for individuals and organizations.
I believe one of the biggest challenges is that organizations sometimes treat these responsibilities as separate. IT looks at cybersecurity, legal or privacy professionals look at GDPR, and management looks at business priorities. All those perspectives are necessary, but they need to communicate with each other.
Standards such as ISO 27001 can help organizations create a structured approach to information security and risk management. Depending on the organization and its activities, businesses may also need to consider requirements arising from NIS2 and other regulatory developments.
Artificial intelligence is adding another layer of complexity. Organizations are adopting AI tools very quickly, and they need to ask practical questions about what information is being entered into these systems, whether personal or confidential information is involved, who has access to the information, and how it is being used.
The technology itself is not necessarily the problem. The challenge is making sure that organizations understand the risks and establish appropriate rules before problems occur.
I believe the future of compliance will be much more connected. Privacy, cybersecurity, technology, and business decisions will increasingly have to be considered together.”
What Auditing Has Taught Her About Organizations
The Women Today: You have worked with several ISO standards and auditing processes. What have those experiences taught you about leadership, organizational culture and the difference between how a company says it operates and how it operates?
Jasmina: “Auditing has taught me that there can sometimes be a significant difference between how an organization believes a process works and how that process actually works.
You may have a procedure that looks perfect on paper, but when you speak with employees, you discover that they have developed another way of working. Sometimes the reason is that the official process is too complicated. Sometimes responsibilities are unclear. Sometimes employees have not received enough training.
That is why I do not see an audit simply as a search for mistakes.
When you identify a nonconformity or a weakness, the more important question is why it happened.
If an employee made an error, was the employee properly trained? If a process was not followed, was the process practical? If a control failed, was the control designed correctly?
Understanding the cause is much more valuable than simply correcting the immediate problem.
The different ISO standards I have worked with also taught me that successful management systems require leadership involvement. Quality, environmental management, occupational health and safety, information security, and anti-bribery management may address different subjects, but they all require people to understand their responsibilities.
Management cannot simply delegate the entire system to one person and expect it to work.
Employees need to understand why the system exists, and management needs to provide the resources and support necessary for it to function.
I also think organizations sometimes become too focused on the certificate. Certification can be important, but the certificate should be the result of a functioning system rather than the entire objective.
The real value comes when a management system helps an organization identify risks, solve problems, and continuously improve.”
The Next Chapter
The Women Today: Looking ahead, what is your vision for the next chapter of your work, and what would you like organizations to understand differently about privacy, cybersecurity and compliance?
Jasmina: “I would like to continue bringing together the different areas I have worked with throughout my career, particularly personal data protection, information security, cybersecurity, management systems, and auditing.
I see these areas as increasingly connected, and I believe organizations benefit when they stop treating every requirement as a separate responsibility.
I would also like to encourage organizations to become more proactive.
It is always better to understand a weakness before there is a data breach, a failed audit, a regulatory problem, or a serious customer complaint.
That means organizations need to regularly look at their processes, assess their risks and, ask whether what they are doing still makes sense.
I also want to continue learning. This is a field that never stands still. Regulations change, technology develops, cybersecurity threats evolve, and organizations themselves continue to change.
Artificial intelligence will bring many new questions, particularly around data protection, confidentiality, transparency, and accountability. I think it will be important for organizations to approach these developments thoughtfully rather than simply adopting new technology because it is available.
Ultimately, I want my work through Korektiva to help organizations become more aware and more confident in managing their responsibilities.
Compliance should not create unnecessary fear or bureaucracy. It should create clarity.
When people understand what they are responsible for, when management understands the risks, and when processes are designed around the way an organization works, compliance becomes much more useful.
That is the kind of work I want to continue building – not simply helping organizations meet requirements but helping them understand why those requirements matter and how they can use them to become stronger, more responsible, and more resilient.”
Connect with Jasmina Hudić
For more information about Jasmina Hudić’s work in privacy, data protection, management systems and compliance, visit Korektiva and connect with her on LinkedIn.
Also Read:-
Dr. Henrietta Newton Martin: Law, AI, Governance & Purpose
Dolce Condé: Why Employee Health Drives Business Strategy
Sofica Bistriceanu on Ethics, Trust & Human Transactions