SlideShare a Scribd company logo
T: 0333 234 4288 W: www.networkiq.co.uk E: info@networkiq.co.uk
GDPR Backgrounder
The General Data Protection Regulation is a compliance mandate
with potential fines for mishandling of personal data. A great deal
of the legislation is devoted to individuals’ privacy rights and the
organisational controls required to protect those rights. GDPR isn’t
just for companies in the EU. It applies to any organisation that
collects and uses personal information to provide goods or services
to EU citizens and residents. Let’s take a closer look at the
regulation and why it’s getting so much attention.
• GDPR is a compliance mandate. It’s a law, and it’s not an option. If an organisation does
business in the EU, then it’s most probably subject to GDPR compliance. It doesn’t matter if
the company is based in EU member states or elsewhere. The deadline is 25th
May, 2018 and
fines for non-compliance can be up to 20 million Euros or up to 4% of the organisation’s
worldwide revenue, whichever is higher. The potential for large fines is in part why GDPR is
getting so much attention. It’s also possible that legal action could be taken against
organisations under this law.
• GDPR is “lengthy”. The full legislation is 261 pages long beginning with 173 “Whereas”
clauses (for context) and then followed by 99 “Articles of Law” (the rules) that begin on Page
108. The Articles are the real meat of the legislation, but it’s not easy reading: Here is an
excerpt from Article 2: “This Regulation shall be without prejudice to the application of
Directive 2000/31/EC, in particular of the liability rules of intermediary service providers in
Articles 12 to 15 of that Directive.” It’s easy to see why many organisations will ask help
from trusted Consulting and Service Partners.
• GDPR is broader than cybersecurity. The name “General Data Protection Regulation” has
“data protection” directly in the centre of the acronym, which naturally lets you think about
cybersecurity. But it’s not just about protecting data from breaches or unauthorized access:
The law has a lot to do with governance over how an organisation uses that information as
well as the rights granted to individuals whose personal information is held by that
organisation. GDPR is heavy on privacy rights. It actually provides individuals with many
rights concerning how their data is used, shared, processed, and retained.
• GDPR requires Breach Notification. GDPR requires supervisory authority notification within
72 hours of discovering a data breach. Therefore, organisations subject to GDPR compliance
must have a well-established incident response plan that includes fast and accurate
outbound notification.
T: 0333 234 4288 W: www.networkiq.co.uk E: info@networkiq.co.uk
• GDPR is very high level. GDPR is written at a high level, and large portions of it involves
people- and process-related controls. The GDPR legislation calls these “organisational
controls.” Consider Article 35, Data Protection Impact Assessment, which says that before
any new types of processing can occur on personal data, the organisation must first
complete an assessment to determine whether this processing is likely to create a high risk
to the rights and freedoms of individuals’ data. It states that a Data Protection Officer should
be engaged to conduct an impact assessment and make a final risk determination.
• Due Diligence. GDPR requires “appropriate security” to protect personal information, but it
does not explain exactly how to achieve it. Therefore, organisations subject to GDPR
compliance must apply due diligence to determine what “appropriate security” means for
them under the spirit of this law.
• GDPR is technology agnostic. It is no simple task to map GDPR requirements to specific
cybersecurity products to this regulation, particularly since it mentions no specific
technologies or technical requirements. GDPR talks about the “what” and not the “how.”
That’s why many organisations are likely to seek supporting guidance from best practices
like the ISO 27000-series publications to help them achieve and prove compliance. It’s much
easier (though still a big task) to map specific technologies and services to these more-
specific publications because they are written more prescriptively than GDPR.
• GDPR is meant to be an enabler. On the surface, GDPR just sounds like a lot -- a lot -- of
compliance work. But it’s actually meant to streamline the many different laws currently on
the books in different EU member nations. In other words, instead of having to follow
dozens of rule frameworks, a different one for each EU member, GDPR is meant to eliminate
obstacles that prevent the free flow of data throughout the EU as a whole. Comply once
with GDPR, and you’re compliant throughout the entire EU.
A Word about Security and Privacy
As we stated above, GDPR is heavy on privacy rights. Of course, “Security” and “Privacy” often go
hand in hand, but there are differences between the two.
So, what are the differences between Security and Privacy?
Let’s use an example from GDPR Article 17 to illustrate: The “right to erasure” means that you, as an
individual doing business with a company, have the right to demand that all of your information is
permanently deleted from their systems. It’s a privacy right that’s related to security, but isn’t
exactly “Security” in the traditional sense of the word. Think about all of the personal information
you hand over to governments and organisations when you do business with them. Absolutely you
expect “Security” from these organisations so that your information is safe from hackers and data
breaches. But if you decide to close your customer account, will the company permanently purge
your data from their systems at your request? Under GDPR, organisations must comply. It’s GDPR
Article 17, Right to Erasure, that provides individuals with that Privacy right.

More Related Content

Recently uploaded

GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
James Anderson
 
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Inflectra
 
The Future of Platform Engineering
The Future of Platform EngineeringThe Future of Platform Engineering
The Future of Platform Engineering
Jemma Hussein Allen
 
Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*
Frank van Harmelen
 
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
Product School
 
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdfFIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance
 
JMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and GrafanaJMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and Grafana
RTTS
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance
 
Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...
Product School
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
DanBrown980551
 
The Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and SalesThe Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and Sales
Laura Byrne
 
Accelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish CachingAccelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish Caching
Thijs Feryn
 
Essentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with ParametersEssentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with Parameters
Safe Software
 
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Thierry Lestable
 
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdfSmart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
91mobiles
 
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
Product School
 
Knowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and backKnowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and back
Elena Simperl
 
How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...
Product School
 
Elevating Tactical DDD Patterns Through Object Calisthenics
Elevating Tactical DDD Patterns Through Object CalisthenicsElevating Tactical DDD Patterns Through Object Calisthenics
Elevating Tactical DDD Patterns Through Object Calisthenics
Dorra BARTAGUIZ
 
Assuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyesAssuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyes
ThousandEyes
 

Recently uploaded (20)

GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
 
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
 
The Future of Platform Engineering
The Future of Platform EngineeringThe Future of Platform Engineering
The Future of Platform Engineering
 
Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*
 
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
 
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdfFIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdf
 
JMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and GrafanaJMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and Grafana
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
 
Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
 
The Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and SalesThe Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and Sales
 
Accelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish CachingAccelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish Caching
 
Essentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with ParametersEssentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with Parameters
 
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
 
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdfSmart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
 
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
 
Knowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and backKnowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and back
 
How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...
 
Elevating Tactical DDD Patterns Through Object Calisthenics
Elevating Tactical DDD Patterns Through Object CalisthenicsElevating Tactical DDD Patterns Through Object Calisthenics
Elevating Tactical DDD Patterns Through Object Calisthenics
 
Assuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyesAssuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyes
 

Featured

Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
Skeleton Technologies
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
Neil Kimberley
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
contently
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
Albert Qian
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
Search Engine Journal
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
SpeakerHub
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
Tessa Mero
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Lily Ray
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
Rajiv Jayarajah, MAppComm, ACC
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
Christy Abraham Joy
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
Vit Horky
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
MindGenius
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
RachelPearson36
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Applitools
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
GetSmarter
 
More than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike RoutesMore than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike Routes
Project for Public Spaces & National Center for Biking and Walking
 
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
DevGAMM Conference
 

Featured (20)

Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
 
ChatGPT webinar slides
ChatGPT webinar slidesChatGPT webinar slides
ChatGPT webinar slides
 
More than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike RoutesMore than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike Routes
 
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
 

GDPR Backgrounder

  • 1. T: 0333 234 4288 W: www.networkiq.co.uk E: info@networkiq.co.uk GDPR Backgrounder The General Data Protection Regulation is a compliance mandate with potential fines for mishandling of personal data. A great deal of the legislation is devoted to individuals’ privacy rights and the organisational controls required to protect those rights. GDPR isn’t just for companies in the EU. It applies to any organisation that collects and uses personal information to provide goods or services to EU citizens and residents. Let’s take a closer look at the regulation and why it’s getting so much attention. • GDPR is a compliance mandate. It’s a law, and it’s not an option. If an organisation does business in the EU, then it’s most probably subject to GDPR compliance. It doesn’t matter if the company is based in EU member states or elsewhere. The deadline is 25th May, 2018 and fines for non-compliance can be up to 20 million Euros or up to 4% of the organisation’s worldwide revenue, whichever is higher. The potential for large fines is in part why GDPR is getting so much attention. It’s also possible that legal action could be taken against organisations under this law. • GDPR is “lengthy”. The full legislation is 261 pages long beginning with 173 “Whereas” clauses (for context) and then followed by 99 “Articles of Law” (the rules) that begin on Page 108. The Articles are the real meat of the legislation, but it’s not easy reading: Here is an excerpt from Article 2: “This Regulation shall be without prejudice to the application of Directive 2000/31/EC, in particular of the liability rules of intermediary service providers in Articles 12 to 15 of that Directive.” It’s easy to see why many organisations will ask help from trusted Consulting and Service Partners. • GDPR is broader than cybersecurity. The name “General Data Protection Regulation” has “data protection” directly in the centre of the acronym, which naturally lets you think about cybersecurity. But it’s not just about protecting data from breaches or unauthorized access: The law has a lot to do with governance over how an organisation uses that information as well as the rights granted to individuals whose personal information is held by that organisation. GDPR is heavy on privacy rights. It actually provides individuals with many rights concerning how their data is used, shared, processed, and retained. • GDPR requires Breach Notification. GDPR requires supervisory authority notification within 72 hours of discovering a data breach. Therefore, organisations subject to GDPR compliance must have a well-established incident response plan that includes fast and accurate outbound notification.
  • 2. T: 0333 234 4288 W: www.networkiq.co.uk E: info@networkiq.co.uk • GDPR is very high level. GDPR is written at a high level, and large portions of it involves people- and process-related controls. The GDPR legislation calls these “organisational controls.” Consider Article 35, Data Protection Impact Assessment, which says that before any new types of processing can occur on personal data, the organisation must first complete an assessment to determine whether this processing is likely to create a high risk to the rights and freedoms of individuals’ data. It states that a Data Protection Officer should be engaged to conduct an impact assessment and make a final risk determination. • Due Diligence. GDPR requires “appropriate security” to protect personal information, but it does not explain exactly how to achieve it. Therefore, organisations subject to GDPR compliance must apply due diligence to determine what “appropriate security” means for them under the spirit of this law. • GDPR is technology agnostic. It is no simple task to map GDPR requirements to specific cybersecurity products to this regulation, particularly since it mentions no specific technologies or technical requirements. GDPR talks about the “what” and not the “how.” That’s why many organisations are likely to seek supporting guidance from best practices like the ISO 27000-series publications to help them achieve and prove compliance. It’s much easier (though still a big task) to map specific technologies and services to these more- specific publications because they are written more prescriptively than GDPR. • GDPR is meant to be an enabler. On the surface, GDPR just sounds like a lot -- a lot -- of compliance work. But it’s actually meant to streamline the many different laws currently on the books in different EU member nations. In other words, instead of having to follow dozens of rule frameworks, a different one for each EU member, GDPR is meant to eliminate obstacles that prevent the free flow of data throughout the EU as a whole. Comply once with GDPR, and you’re compliant throughout the entire EU. A Word about Security and Privacy As we stated above, GDPR is heavy on privacy rights. Of course, “Security” and “Privacy” often go hand in hand, but there are differences between the two. So, what are the differences between Security and Privacy? Let’s use an example from GDPR Article 17 to illustrate: The “right to erasure” means that you, as an individual doing business with a company, have the right to demand that all of your information is permanently deleted from their systems. It’s a privacy right that’s related to security, but isn’t exactly “Security” in the traditional sense of the word. Think about all of the personal information you hand over to governments and organisations when you do business with them. Absolutely you expect “Security” from these organisations so that your information is safe from hackers and data breaches. But if you decide to close your customer account, will the company permanently purge your data from their systems at your request? Under GDPR, organisations must comply. It’s GDPR Article 17, Right to Erasure, that provides individuals with that Privacy right.