GDPR Data Regulations & Commercial Fines

The goals of the General Data Protection Regulation (GDPR) are simple: a law to ensure data protection and privacy for all individual citizens of the European Union and the European Economic Area. However, the maximum fine under the GDPR is up to 4% of annual global turnover or €20 million, whichever is greater, for organisations that infringe its requirements.
 
But, not all GDPR infringements lead to data protection fines. Supervisory authorities such as the UK’s ICO (Information Commissioner’s Office) can take a range of other actions, including:
 
  • Issuing warnings and reprimands;
  • Imposing a temporary or permanent ban on data processing;
  • Ordering the rectification, restriction or erasure of data; and
  • Suspending data transfers to third countries.
UK Government Fines
There have been a few large fines made by the UK Government against organisations who have misused personal data and recently some in the government has said that more fines will take place against commercial operations that operate in the UK, but break GDPR rules and these fines will be issued in the new year.  
 
One of the most important aspects of GDPR is the ability for citizens to see what data is held on them by an organisation and how it is being used. 
 
However, in the rush to comply with the data retention, security and usage requirement of GDPR, the process for enabling consumers the right to access their data is still somewhat ad-hoc for many organisations. One of the most challenging issues is how does an organisation determine that a request from an EU citizen to see retained data, is truly from the person making the request? 
 
GDPR is vague on how an organisation should verify that they are the legitimate person and different processes are starting to evolve that could cause some serious GDPR issues. For example, requesting copies of physical documents such as passports or driving licenses, which would need to be verified (and potentially held for audit), are a potential goldmine for criminals engaged in identity theft. If badly handled, this could lead to a GDPR compliance breach.
 
Digital to Paper
The public and private sector are both impacted, although government agencies have more leeway across GDPR in general due to requirements to retain and use data to deliver services to citizens. In terms of what best practice should be in dealing with a request, the advice from the UK’s Information Commissioner’s Office is that there should be a policy for recording all “subject access requests” and that based on Recital 59 of the GDPR, organisations “provide means for requests to be made electronically, especially where personal data are processed by electronic means.”
 
This process will start with an access request form but when it comes to identity, the guidance is unclear. A number of organisations are asking for a similar set of documents that most banks require to open an account which includes a “proof of identity” such as a passport, photo driving license or birth certificate along with a “proof of address” such as a utility bill, bank statement or credit card statement.
 
This requirement to verify from copies or scans of electronic documents is a major weakness in this process. With a modicum of Photoshop skill, faking a photocopy of a passport and utility bill is an easy task and as such, some organisations are instead requiring stronger validation methods. 
 
Best and Worst
The UK banks have possibly the best method of validating identity through the e-banking processes. Although banks must accept subject access requests by letter, many are prompting account holders to make the request through online banking platforms. This has many advantages as the platforms are linked to an account which was opened using validated identification and access and is further strengthened by Multi-Factor Authentication (MFA).
 
This concept of using an online identity to act as an arbitrator for GDPR compliance is gaining favor. This process, especially when it is tied to a credit or debit card which tied to a physical account holder and address, provides responders to a GDPR request with at least, a verifiable trail to assure identity.
 
The right to access issues exposed by GDPR point to a larger challenge around how people can confirm identity in the digital age. 
 
Estonia’s digital identity scheme, which although had a short outage when a vulnerability was discovered and later rectified, has become a model for best practice in the field of identity. The Estonian ID-kaart is a mandatory identity document for citizens of Estonia, and along with a photo and chip and pin, the ID-kaart has a companion smart-ID app that is compatible with standard X.509 and TLS infrastructure. 
 
The government issues a client certificate to each citizen that has made it a convenient means of identification for web-based government services, medical records, tax claims, online banking and to make secure GDPR subject access requests.
 
For public services and local government that want to ensure a citizen’s identity, the best advice is to sign up for GOV.UK Verify, which the Department for Work and Pensions (DWP) uses to check the identities of users who apply for Universal Credit.
 
Keep the Shredder Ready
Unfortunately, until GOV.UK Verify or similar services emerge that can help third parties to carry out digital identity assurance for free, or at least at low cost; the requirement to gain copies of physical documents will remain.
However, to ensure that documents submitted for access requests don’t themselves become targets for cyber-criminals; organisations must develop verifiable processes to destroy these documents after they have been examined and the request has been delivered.
 
For organisations that have developed rigorous customer on-boarding processes for Internet services that include identity validation methods, specialist data protection websites like IT Governance can provide the most effective way to verify and process access requests. However, this cannot be an exclusive option as non-electronic means must also be available to meet GDPR requirements.
 
Please contact Cyber Security Intelligence to connect with expert  GDPR Lawyers.
 
ITGovernance:             Infosecurity Magazine
 
You Might Also Read:
 
The GDPR Wake-Up Call Is Being Ignored By Business:
 
 
« Parliament Wants A New Cyber Security Director
WEBINAR: How to Leverage a CASB for Your AWS Environment »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 8,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Tines

Tines

The Tines security automation platform helps security teams automate manual tasks, making them more effective and efficient.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

CloudDNA

CloudDNA

CloudDNA deliver solutions that enable users and devices to connect over high performance, secure, efficient, scalable cloud networks.

Marsh

Marsh

Marsh is a global leader in insurance broking and risk management and has been a leader in combatting cyber threats since their emergence.

Bastille

Bastille

Bastille’s patented software and security sensors bring visibility to devices emitting radio signals (Wi-Fi, cellular, IoT) in your organization.

Wilson Sonsini Goodrich & Rosati (WSGR)

Wilson Sonsini Goodrich & Rosati (WSGR)

WSGR is the premier provider of legal services to technology, life sciences, and growth enterprises worldwide. Practice areas include cybersecurity and data protection.

Secardeo

Secardeo

Secardeo is a provider of corporate solutions using digital signatures and certificates. Our solutions enable the user transparent end-to-end encryption of e-mails between organizations.

HumanFirewall

HumanFirewall

HumanFirewall makes it possible for every individual to take part in securing their organisation. With HumanFirewall, achieving security has never been easier.

Cloud Managed Networks

Cloud Managed Networks

Cloud Managed Networks provides enterprise grade IT network solutions for cloud-based and on premise network security, Wi-Fi, data switching, collaboration, device management and more.

Sigma IT

Sigma IT

SIGMA IT is one of the largest IT services organizations in EMEA region providing a full range of solutions and services including cybersecurity, data protection and business continuity.

Quantum Generation

Quantum Generation

Quantum Cyber Security for a new age of communications. We are developing the largest decentralized orbital, and ground quantum mesh network based on blockchain technology.

Axxum Technologies

Axxum Technologies

Axxum Technologies is a premier provider of Network Communications and Information Technology Security Solutions.

AlJammaz Technologies

AlJammaz Technologies

AlJammaz Technologies is the leading Technology Value-Added Distributor, which distributes advanced technology products, solutions and services in area including networking and cybersecurity.

Vanta

Vanta

Vanta helps companies scale security practices and automate compliance for the industry’s most sought after standards - SOC 2, ISO 27001, HIPAA, GDPR, and other security and privacy frameworks.

Balance Theory

Balance Theory

Balance Theory provides the knowledge infrastructure and collaboration center for the cybersecurity community. A networked community to build better cybersecurity outcomes.

GreenPages Technology Solutions

GreenPages Technology Solutions

GreenPages provide expert strategic guidance and proven cloud-era solutions for our clients. Every day we help organizations leverage the cloud securely with less risk and cost.

OneZero Solutions

OneZero Solutions

OneZero specialize in cybersecurity operations, information assurance, computer network operations, solutions engineering, and project management.

Modat

Modat

Modat is an AI-powered, research-driven company focused on developing products and services that enable cybersecurity professionals to outpace adversaries.