Playing Catch-Up With GDPR

After two years of waiting, Europe’s General Data Protection Regulation has officially taken effect. Beyond Europe, the regulation is expected to reshape how global organisations manage, share and protect their users’ personal data. 
 
Many organisations across the world have scrambled to be ready. But based on public statements from companies and client feedback, it is clear that many companies are still not in compliance. Still, with all the high-profile data breaches and misuses we have witnessed in the last few months; i.e. Equifax and Cambridge Analytica, global businesses are taking GDPR seriously. 
 
Not knowing the extent and depth to which the EU will enforce GDPR, the potential fines of up to 4 percent of global annual revenue or 20 million euros should still inspire an immediate need to review and subsequently adjust data privacy and protection programs. 
 
As a result, companies will have to restructure how they handle data, and, if they do not have a cyber infrastructure that is sound, they will have to rebuild from the ground up including their applications. Even if the GDPR does not directly affect your organisation, the requirements and guidelines contained within can help any organisation obtain resilient data privacy and protection.
 
Who is in Compliance?
The answer differs based on several factors. Over the past few weeks there have been at least four distinct studies with very different results. On May 21, a new GDPR study carried out by the Ponemon Institute found that 40 percent of the companies surveyed would not be ready.
 
A Crowd Research Partners report drawn from the Information Security Community on LinkedIn, says that only 40 percent of the organisations surveyed would be fully compliant by today’s GDPR deadline.
 
A World Federation of Advertisers (WFA) survey stated that 95 percent of respondents planned to be fully compliant by the deadline, of which 74 percent said they believe their company would likely be fully compliant by the deadline, with 42 percent of those respondents saying they would definitely be.
 
A Netsparker GDPR survey of 300 senior executives found that only 2 percent of those surveyed said that they do not expect to be compliant by today’s deadline.
 
The various survey results indicate that there is still much confusion around GDPR. For those organisations that are playing catch-up with GDPR, the first step is to realise that they will need their customer’s permission to collect and process their data. This includes internal tools used to share or analyse the data internally, exclusive of tools that encrypt the data end to end. 
 
The steps should be prioritised by risk and execution complexity within your organisation.
 
1. Revise your procedures that define how you are going to handle an individual's request for erasing or rectifying inaccurate data. Executing this process will take the longest time so it should be prioritized.
2. Review your contracts with third parties. Their compliance is your risk exposure so you need to make sure you ensure their compliance. 
3. Review and understand how you process your customer data mapping the data processing activities across the business processes. This activity, previously put on the back burner, needs to be moved up. It is a compliance activity not a systems analysis activity. It simply isn’t an option anymore.
4. Revise your data security practices and systems to be in compliance with GDPR. The core initiative for meeting EU GDPR compliance is to protect user data. If you have not already, you need to take inventory of your data and map your data to protected EU GDPR categories. 
5. Most importantly once you have the knowledge of where your data is and how is it being used a prudent step would be to also implement a data leak prevention tool and policy to enforce GDPR systematically. 
6. It is equally important to remember why GDPR was created in the first place. The main goal of the regulation was to protect the misuse of personal data by organisations for intrusive marketing and influencing activities. 
 
Moving forward, GDPR compliance will emphasise transparency of the data. The retention and processing of our data has to be with our permission and easily auditable. 
 
Complying with GDPR will be a significant challenge to all businesses. 
However, knowing what you have to do to be in compliance is the first and most important step. This will help you quickly get to a point where you demonstrate to the regulators that you can both identify and audit your data so that you can create a practical roadmap to GDPR compliance.
 
To contact the GDPR Advisory Board please visit:  www.gdpr-board.co.uk
 
Information-Management
 
You Might Also Read: 
 
What Your Board Needs To Know About GDPR:
 
Cybersecurity Advice For SMEs:
 
 
« Demand For Indian Cybersecurity Skills Rising Fast
Cybercrime: Law Enforcement Must Get Serious »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

ZenGRC

ZenGRC

ZenGRC (formerly Reciprocity) is a leader in the GRC SaaS landscape, offering robust and intuitive products designed to make compliance straightforward and efficient.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Airbus Cybersecurity

Airbus Cybersecurity

Airbus CyberSecurity is a European specialist in cyber security. Our mission is to protect governments, military and critical national infrastructure enterprises from cyber threats.

AVG Technologies

AVG Technologies

AVG is focused on providing home and business computer users with the most comprehensive and proactive protection against computer security threats.

Cybercrypt

Cybercrypt

Cybercrypt is a world leading system provider in robust cryptography. Protecting critical assets, applications and sensitive data.

Guardsquare

Guardsquare

GuardSquare is the global reference in mobile application protection. We develop premium software for the protection of mobile applications against reverse engineering and hacking.

Pryv

Pryv

Pryv is a Swissmade software for privacy, personal data collection, usage, sharing and storage.

SynerLeap

SynerLeap

SynerLeap is ABB's innovation growth hub. Our aim is to help startups accelerate and expand across industries, ranging from industrial automation and robotics to grid technologies and smart cities.

CyberSN

CyberSN

CyberSN is your essential partner in cybersecurity workforce risk management offering solutions that empower leaders to diversify, acquire, retain, and develop their cybersecurity teams.

Samurai Digital Consulting

Samurai Digital Consulting

Samurai Digital Security are a cyber and Information security services provider, specialising in penetration testing, incident response, user awareness and information governance solutions.

Epiphany Systems

Epiphany Systems

Epiphany enhances your defensive security controls by providing you with an offensive perspective. We expose the most likely attack paths to your most critical IT assets and users.

D2 Network Associates (D2NA)

D2 Network Associates (D2NA)

D2NA help businesses deliver and achieve their goals, through innovative IT solutions, robust cyber security services and proactive IT managed services.

Analygence

Analygence

ANALYGENCE is your trusted partner for mission support, cyber solutions, and management services.

Secrutiny

Secrutiny

Scrutiny's core services include Cyber Maturity, Cyber Risk Analyser, Cyber Controls, Incident Response, SOC, Cyber Recovery and Assurance Testing.

SENTRIQS

SENTRIQS

SENTRIQS advanced encryption technology is engineered to defend against the most sophisticated cyber threats, keeping your operations efficient and secure.

ThoughtSol

ThoughtSol

Thoughtsol help brands grow through Digital Transformation enabling them to leverage the power of IT for an all-embracing impact on their businesses.

Krash Consulting

Krash Consulting

Krash Consulting is a premier provider of Cyber Security solutions, offering a range of services to safeguard businesses against cyber-attacks, minimize fraud, and protect brand reputation globally.

Strata Horizon

Strata Horizon

Strata Horizon is a leading cybersecurity solutions provider in the UAE, offering innovative and comprehensive services to safeguard your organization from evolving digital threats.

SurePath AI

SurePath AI

SurePath AI is a SaaS platform that governs any GenAI solutions you build, adopt, or buy - even Shadow AI.