
July 12, 2018 • Garrett Garitano
The most significant change to privacy protection of the decade came into force in Europe this year. What does it mean for companies? Does it only matter for companies based in Europe? You’ll find the answers to those questions and more today. First, let’s clear up the most significant misconception about GDPR compliance. The Most […]
The most significant change to privacy protection of the decade came into force in Europe this year. What does it mean for companies? Does it only matter for companies based in Europe? You’ll find the answers to those questions and more today. First, let’s clear up the most significant misconception about GDPR compliance.
The Most Dangerous Misconception About GDPR Compliance
Note: We are sharing our observations based on emerging industry best practice for GDPR compliance. However, this article is not providing legal advice. If needed, consult a qualified legal professional for advice for your specific situation.
At first glance, you might think, “my business is not based in Europe, so this regulation doesn’t affect me.” That’s a mistake. In fact, GDPR compliance is already impacting companies across the world, including many in the United States. There are three reasons why you should take action on GDPR compliance even if you aren’t in Europe.
What’s GDPR?
GDPR (General Data Protection Regulation) is a European Union regulation that came into effect in May 2018. It has attracted considerable attention from companies around the world. Why? The regulation comes with significant financial penalties for violations: up to €20 million (over $26.5 million), or 4% of the worldwide annual revenue of the prior financial year, whichever is higher. Avoiding those penalties through GDPR compliance is a smart financial move.
The regulation has been in development for several years. Overall, it’s intended to protect the privacy of end users in Europe. For companies, it means some of your current sales and marketing practices and systems may need adjustment. Here are some of the most significant expectations created by the regulation.
Broad personal data definition: You might be used to defining personal information to mean name, address, and phone number. GDPR takes a much broader view. Specifically, see how article 4(1) defines the term: “any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.”
Keeping this broad definition in mind, a “data subject” has specific rights under GDPR. Such individuals can make requests to companies. These requests are informed by the following:
Fully achieving all those requirements is demanding and may be quite expensive. How exactly do you get started if you have a significant GDPR exposure? We we’ll tackle that challenge next.
Resource: For additional insights on GDPR, consult the official website from the European Commission.
Focus Your GDPR Compliance Efforts Using a Risk-based Approach
Since GDPR is new, we don’t yet know how the authorities will enforce it. The best approach is to start your compliance efforts now and focus on the most critical areas. The following principles will guide your approach.
What Are the Cybersecurity Implications of GDPR?
To fulfill GDPR expectations, your organization needs strong cybersecurity protection. Governments and the public have less tolerance for privacy mistakes and hacking incidents with each scandal. How can you tell a customer that you’ve erased all of his or her data if you’ve been hacked and lost that data? The same problem could occur if an ex-employee used access privileges to bring data to a competitor. To reduce the chance of a data breach, you need a systematic way to optimize access governance.
Use Compliance Auditor to improve your access governance across the organization. You can revoke access and delete accounts directly from the solution, an excellent way to reduce risk when employees leave the organization.