GDPR is the EU’s response to the privacy debate. Its stated objective is to give control of personal data back to the person. The data you collect on customers and prospects is no longer yours. It’s theirs. And it’s your responsibility to make sure it’s properly protected.
GDPR: The specifics
Any data relating to an individual is covered
– whether public or private. And medium is irrelevant. The only exceptions are for some data relating to your own employees.
Businesses must select a ‘one-stop shop’ in the EU to act as their Supervisory Authority. Businesses are expected to give notice of retention time, and provide contact info for their data controller and Data Protection Officer.
You must obtain explicit consent from individuals if you want to use their data. For every purpose you want to use it for. And your Data Protection Officer must be able to prove that consent if asked.
In keeping with earlier EU conventions, those using data are segmented into controllers (those who gather and store the data) and processors (those who analyse and otherwise leverage it.) Under GDPR, processors must follow the same rules as controllers. That means you’ll have to be very, very careful about what apps you
use – and where they store and house their data to avoid data leaving the EU without proper oversight.
Some vendors (like Microsoft) are leading the charge in this area by establishing data centres in the EU, giving users the option to never have their data leave the Union. However, this will still be the responsibility
of individual users and enterprises. And getting it wrong will cost a lot.
Most important to you is the cost of not playing ball. Depending on the violation, you could pay anything up to 4% of your company’s annual turnover in fines.
Your company will also face the administrative burden of hiring a Data Protection Officer to oversee compliance if you regularly and systematically process data.
GDPR: THE reaction
Over 28,000 DPOs (Data Protection Officers) must be created in the EU alone – with many more also needed in overseas companies trading in or with the EU.1 Although there’s no clear guidance on which companies must appoint them, earlier drafts of the regulations specified any company processing data of 5,000 individuals in a year. The law now refers to any company that ‘systematically’ processes personal data.
Companies will have to get used to their customers running the show when it comes to data. Even deleting personal data without notifying a subject can constitute a violation.
Gartner estimates that by the time GDPR activates, over 50% of the companies affected will not be fully compliant.2
GDPR: The good news
GDPR has the potential to save businesses as much as €2.3bn a year by removing
a complex web of national laws and disconnected regulations.3
What’s more, 90% of the EU’s population (i.e. your customers) are in favour of it.4
What does GDPR mean at Board Level
Compliance will cost you – but noncompliance will cost you more.
Violating regulations on data governance, storage, and usage – and failing to answer requests - means a fine of up to €10,000,000 or 2% of your last year’s turnover.5
Violating regulations on acquiring consent, failing to observe the rights of data subjects, or illegally transferring data to centres outside of the EU means a fine of up to €20,000,000 or 4% of turnover.6
Complying means recruiting a Data Protection Officer if you regularly and systematically handle individual data.7
The DPO: Your new hottest Hire
Data Protection Officers can be internally hired or can be an outside contractor retained ‘as a service’. You’ll almost certainly need one even if you maintain so much as an emailing list.
The DPO’s job is to ensure the compliance of your data controllers and processors. But they won’t be directly involved in
the process of building your compliance capability and culture. That will be a job for
other senior team members.
Your DPO will need a platform in the business to co-operate with both IT and security leaders. Between them, they’ll be vital in training the rest of your teams to understand and follow the new rules.
BREACHES MEAN DIRECT DAMAGE TO BRAND EQUITY AND SHARE PRICE
All breaches involving personal data must be reported to your Supervising Authority within 72 hours. Anyone whose sensitive data is deemed to be at risk must also be notified.8
Right now, 32% of companies report losing data in breaches9, and the average company will experience around 100 cyber attacks in a year10. What’s more worrying is that only 25% of companies report having experienced an attack11 – which means you’ve probably experienced multiple breaches without even realising it.
That means security isn’t just important to safeguard your assets – it’s now a matter of your brand’s day-to-day survival. According to a recent IDG report, a majority of business leaders (57%) consider reputational damage almost as important as potential lost revenue (58%)12.
Your security teams will need to have dependable loss prevention policies, Secure Internet Gateways, password management plans, and other protocols in place to best safeguard the company.
NOT HAVING THE RIGHT PEOPLE AND PARTNERS IN PLACE MEANS TROUBLE
Only 5% of FTSE companies currently have cyber security expertise at board level.
Companies are increasingly conscious of the need to fill this gap – according to IDG, only 60% of UK businesses believe they currently have the people and processes they need to be compliant with GDPR. That means an already scarce talent pool is rapidly evaporating.
Start looking now – and make sure you have the right partners in place to help train and support the people you do have. Avoiding loss of face (not to mention loss of funds) will now be a matter of both compliance, selecting the right security solutions, and evolving your company’s culture.
Get used to collecting data in a way people can understand... and get ready to re-format or throw out what you currently have.
Data storage lifecycles must be declared under GDPR, so it’s highly likely that your older records will be invalid.15
What’s more, customers can ask to see what data you hold on them. And ask for it to be moved somewhere else at any time16. It needs to be stored in a common format that’s easy to read.
You’ll probably have to set up an initial project to audit your current data-gathering activities – working with your DPO (if your company already has one) to work out what is and isn’t acceptable under the new regime.
KNOW WHERE IT’S KEPT, WHAT IT IS, AND WHOSE IT IS
If you don’t, you’re already in violation. And since you’ll be expected to prove consent on demand, that might cost you.17
This means that a full assessment of your data storage will be essential before May 25th 2018. You should pay particular attention to your cloud storage and software solutions, as these could be more vulnerable to breach and may be harder to make compliant.
You’ll also have to be a lot more careful about how your people use data on apps. Unless you know where app vendors base their data centres, you risk moving data out of the EU and incurring a huge penalty.
PRACTICE ASKING AWKWARD QUESTIONS
Questions of both your customers (from whom you’ll now need explicit permission for each way you intend to use their data) and of your people (who will need to be able to accommodate this requirement in new user experience formats).
According to IDG, 62% of survey respondents think that securing compliance with GDPR is IT’s job18. That means your first awkward question should be about responsibilities.
If building architecture and on-boarding solutions isn’t explicitly assigned to someone, it’s likely you’ll take the blame later if the company’s sanctioned.
To keep yourself and the company in the clear, you’ll need to know:
-
What data do we absolutely need to be collecting?
-
Where are we keeping it?
-
What applications are we using to process it? Are they compliant? Are their servers based in the EU?
-
Are our staff aware of what they must do to maintain compliance?
-
Who has privileged/controller-level access to data? Do they really need it?
-
How are we testing our systems for vulnerability?
-
Do we have a robust system for breach response? Are my legal, security, HR, and PR teams looped in on it?
What does GDPR mean for cyber security leadership
This is your problem now.
72-hour breach reporting requirements mean a lot more pressure will be placed on you to guarantee the company’s market position. Especially since it’s currently unlikely that you even know when a breach has occurred 19.
That means you need to know who controls and who processes your data, where it is, and what protects it. You’ll have to co-operate extensively with your organisation’s IT leadership to discover the true scope of this – as shadow IT and unsanctioned 3rd party app use must be covered and controlled as well.
To address specific cloud vulnerabilities, you’ll likely need to enlist the aid of a Cloud Security Access Broker – and Gartner have suggested that by 2020, 85% of large enterprises will depend on such a service 20.
You’ll need strong Data Loss Prevention policies in place for cloud and on premise. As well as more traditional Secure Internet Gateways.
Malware and ransomware are still the primary entry points for a data breach, and according to security leaders this is unlikely to change 21.
Password management policies will also become a much more important part of your life. Because if a breach comes about thanks to a password that hasn’t been changed since 2007, you’ll be the one who must explain why.
Visit - Is your Cloud Ready for GDPR to find out more
YOU NEED TO KNOW HOW TO PROTECT PERSONAL DATA. AND WHO MIGHT TRYTO STEAL IT.
It’s impossible to keep any data 100% safe online – but now you’ll have the spotlight (and hopefully the budget) to do the job properly. Make sure you have the software, people, and partners you need in place.
We recommend a suite of traditional platforms as discussed above – alongside strong end-user behavioural analytics. Together, these will detect and prevent breaches with a much greater level of success.
DEVELOP A CLOSE RELATIONSHIP WITH YOUR DPO.
Your company’s Data Protection Officer – whether internal or external – will be your biggest ally in protecting the company. And staying on the right side of the law.
You should consult with them to craft your company’s new security architecture and culture in compliance with GDPR.
They’ll also provide an invaluable resource when it comes to training and coaching your end users to follow the correct protocols. (Though this will remain your responsibility.)
Everycloud are the cloud confidence consultants
We provide independent and impartial cloud security consultancy and implementation services.
Our aim is to make your business secure and cloud confident. To give you the security systems, software, and policies to grow and thrive.
We advise on all aspects of cloud security. Providing insight and recommendations on cloud access, identity management, and traditional web security services.
Because we’re truly independent, we’ll build your custom solution completely from scratch. And we’ll only use the software, tools, and protocols that fit your priorities, to help your business
grow and thrive.
Related Articles
External sources
Thank you to all of the external sources below in helping to put this research together
- Gartner, Focus on five high-priority changes to tackle EU GDPR ID: G00311301
- Gartner, Ibid
- For more on this, see our previous whitepaper,The New EU General Data Protection Regulation
- (GDPR)European Commission > Justice > Data protection > reform - http://ec.europa.eu/justice/data-protection/reform/index_en.htm
- GDPR Article 83, Paragraph 4
- GDPR Article 83, Paragraphs 5&6
- GDPR Articles 37-39
- GDPR Articles 33&34
- Aberdeen Group research, SaaS Data Loss: The problem you didn’t know you had.
- Accenture Security Technology Vision 2016
- Sixth annual Databarracks Data Health Check Report
- IDG Connect Mixed state of readiness for new cyber security regulations in Europe
- Accenture Security Tech Vision 2016
- IDG Connect Mixed state of readiness for new cyber security regulations in Europe
- GDPR Article 25
- GDPR Article 20
- GDPR Article 7
- IDG Connect Mixed state of readiness for new cyber security regulations in Europe
- Accenture Security Technology Vision 2016
- Gartner: How to Evaluate and Operate a Cloud Access Security Broker, 08 December 2015 | ID:G00292468, Analyst(s): Neil MacDonald, Craig Lawson
- IDG Connect Mixed state of readiness for new cyber security regulations in Europe