The New GDPR Rules Focus On Consumer Protection

It’s very clear that the new GPPR rules put consumers in the driver sseat whilst the businesses responsible for handling customer data has to comply with the regulations.
 
Businesses that fail to follow the new rules will face tough and potentially damaging penalties of up to 4% of their company’s annual global revenue or a fine of 20 million Euros, whichever is greater.
 
Here are the key requirements for consumer rights:
 
1. The right to access: individuals have the right to request access to their personal data and to ask how their data is used by a company after it has been gathered. The company must provide a copy of the personal data, free of charge and in electronic format if requested.
2. The right to be forgotten: Consumers which are no longer customers can withdraw their consent from a company to use their personal data, and have the right to have their data deleted.
3. The right to data portability: Individuals have a right to transfer their data from one service provider to another. It must happen in a commonly used, accessible, readable format.
4. The right to be informed: Any gathering of data by companies, and individuals must inform the customer/citizen before data is gathered. Consumers have to opt in for their data to be gathered, and consent must be freely given rather than automatically presumed.
5. The right to have information corrected: This allows individuals to have their data updated if it is out of date or incomplete or incorrect.
6. The right to restrict processing: Individuals can request that their data is not used for processing. Their records can remain in place, but not be used.
7. The right to object: This allows individuals the right to stop the processing of their data for direct marketing without any exemptions. Any processing must stop as soon as the request is received. In addition, this right must be made clear to individuals at the very start of any communication.
8. The right to be notified: If a data breach has occurred which compromises an individual’s personal data, the individual has a right to be informed within 72 hours of first having become aware of the breach.
 
How could GDPR affect your business?
Whilst regulation itself is needed to ensure businesses operate fairly, some regulation can hinder business and make daily operations bigger tasks than they once were. Regardless of whether the data processing takes place within the EU or not, the new regulations apply to all businesses established within the EU and even non-EU established businesses will have to comply with the GDPR. Any business that offers goods or services to customers within the EU, will be legally required to follow the new regulations.
 
Whilst the management of data will become an IT issue, it should also be a major area of concern across the whole company, in particular the sales and marketing department.
 
Implications for Businesses
The new GDPR rules allow individuals the right to withdraw consent at any time and there is a presumption that consent will not be valid unless separate consents are obtained for different processing activities.
This means you have to be able to prove that the individual agreed to a certain action, for example to receive a newsletter. Companies cannot simply add a disclaimer, or ‘small print’, and providing an opt-out option is not enough.
 
This means that companies will have to seriously consider their methods of marketing and sales activities and how they legally obtain data.
 
Companies will need to review business processes, applications and forms to all be compliant with double opt-in rules and new email marketing rules. If a customer wishes to subscribe to a company’s communications, they will have to fill out a form or tick a box and then confirm it was their actions in a further email (known as double opt-in).
Companies must also prove that consent was given by the customer should a case arise where an individual denies receiving the communication in the first place.
 
In order to do this, any data held must have a clear audit trail that is time stamped with details of how the customer opted in and when.
 
Even if the company uses third party marketing lists where the vendor confirms the data is fit for purpose, the company is still responsible for obtaining the correct customer consent. One popular way for B2B businesses to obtain data is in person at networking events and trade shows. Many sales people currently take the names and emails of prospects and then manually add them to a mailing list. Even though the customer willingly gave their data, this will not be allowed come May 25th 2018.
How to prepare your business for GDPR?
 
Any company that works with personal data should appoint a data protection officer within their compliance team whose sole purpose will be to ensure the business operates legally when sourcing, storing and managing customer data. 
 
There are many things companies will have to focus on in order to be compliant with GDPR. Here are just a few first steps for your business to consider:
 
1. Track your company’s data
Map out where all of the personal data in your entire business comes from and document what you do with the data. Note where the data is stored and who as access to it.
2. Determine which data you need to keep and which you do not
Only keep information that is necessary and remove any data that isn’t used or expired. GDPR will encourage a more disciplined treatment of personal data and companies that hold onto heaps of data, regardless of whether it is being used or not, will be fined.
Things to consider when cleaning up your data:
• Can this data be erased instead of archived?
• What is the purpose of saving all this data?
• What is the purpose of collecting all these categories of personal information?
• Is the financial gain of deleting this information greater than encrypting it?
3. Take relevant safety measures
Should a security breach arise, have the correct infrastructure in place to deal with issues in a compliant fashion. Put security measures in place to prevent any data breaches, and take quick action to notify individuals and authorities in the event a breach does occur.
As previously mentioned, outsourcing data from third parties doesn’t exempt you from being liable. Make sure your data providers have also followed the correct security methods.
4. Regularly review your documentation
Pre-checked boxes and implied consent will not be acceptable under new GDPR and consumers need to explicitly consent to a company using their data. Business will need to regularly review all privacy statements and disclosures and adjust them where needed.
5. Create compliant procedures for handling personal data
As part of the new regulations, individuals have 8 basic rights which will need to be considered by companies when planning how to obtain data.
 
Things to consider:
 
1. How can individuals give consent in a legal manner?
2. What is the correct process if an individual requests their data to be deleted?
3. How will the business ensure that the request is met and data is deleted across all platforms?
4. How will the business transfer data should the consumer request it?
5. How will the business confirm that the data genuinely belongs to the person requesting it?
6. What is the plan in the event of a data breach?
 
Whilst new regulations can bring challenged to businesses as well as un-planned associated costs, it’s important to see the bigger picture and possibilities for companies in the future.
 
Safeguarding consumer data will help create more good quality companies and improve the relationship between the customer and company. Companies that comply and choose to be transparent with consumers can in turn nurture a longer more valuable relationship with consumers.
 
ConstructaQuote
 
You Might Also Read: 
 
 
 
 
 
 
« MI5 In The Clear Over Terror Attacks
First EU Cyber Defence Exercise »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

ON-DEMAND WEBINAR: Gen AI for Security: Adoption strategies with Amazon Bedrock

ON-DEMAND WEBINAR: Gen AI for Security: Adoption strategies with Amazon Bedrock

Watch this webinar and get a comprehensive roadmap for securely adopting generative AI using Amazon Bedrock, a fully managed service that offers a choice of high-performing foundation models (FMs).

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Jones Day

Jones Day

Jones Day is an international law firm based in the United States. Practice areas include Cybersecurity, Privacy & Data Protection.

Cristie Data

Cristie Data

Cristie have been a trusted, innovative and leading edge data storage, backup and virtualisation solutions provider across all sectors of industry for over 40 years.

Cyber Secure Forum

Cyber Secure Forum

The Cyber Secure Forum is a premier cybersecurity event dedicated to bringing together experts, and professionals to explore the latest trends, share knowledge, and discuss strategies.

Cobalt Strike

Cobalt Strike

Cobalt Strike is penetration testing software designed to execute targeted attacks.

Codified Security

Codified Security

Codified is a testing platform for mobile application software. We make it easier than ever for companies to detect and fix security vulnerabilities and ensure their applications are compliant.

Enosys Solutions

Enosys Solutions

Enosys Solutions is an IT security specialist with a skilled professional services team and 24x7 security operations centre servicing corporate and public sector organisations across Australia.

WISeKey

WISeKey

WISeKey is a leading cybersecurity company currently deploying large scale digital identity ecosystems for people and objects using Blockchain, AI and IoT.

Nordic Cyber Summit

Nordic Cyber Summit

Nordic Cyber Security Summit addresses a wide range of technological issues from the IT Security spectrum and also provides a wider perspective from all aspects of the industry.

Plexal

Plexal

Plexal is East London's innovation centre and co-working space. We offer startups flexible memberships, giving them access to office space plus all the benefits and support they need to scale.

24By7Security

24By7Security

24By7Security are Cybersecurity & Compliance Specialists with extensive hands on experience helping businesses build a defensive IT Infrastructure against all cyber security threats.

Brighterion

Brighterion

Brighterion solutions stop payment and acquirer fraud, reduce credit risk and delinquency, fight financial crime, prevent healthcare fraud, waste and abuse, and more.

usecure

usecure

usecure is a global provider of computer-based cyber security awareness training, offering the market’s most time-efficient, cost-effective and admin-lite solution for reducing insider threats.

New Net Technologies (NNT)

New Net Technologies (NNT)

NNT SecureOps provides ultimate protection against all forms of cyberattack and data breaches by automating the essential security controls.

INE

INE

INE is a premier provider of Technical Training for the IT industry.

SecureClaw

SecureClaw

SecureClaw offers specialized cybersecurity consultation, various products, and a range of services to meet your company's business domain needs.

LockMagic

LockMagic

Lockmagic is an information asset management solution to protect, track, audit and control accesses to sensitive information inside and outside your organization.