What Your Board Needs To Know About GDPR

Executives in businesses around the globe have been tracking The European Union's (EU) General Data Protection Regulation (GDPR), which goes into effect 25 May 2018. Those who operate primarily in the EU have had plenty of time to focus on this and no excuses for not paying attention. 
 
Those who operate primarily elsewhere also have no excuse to not be aware of the GDPR and should have already assessed how things should change because of these new rules. 
 
We have found, however, that many firms in the EU and the US and elsewhere are still not paying enough attention to these very serious rules. 
 
The objective of these new rules is to improve privacy and security of critical personal information. The rules are also designed to harmonise many different rules active across Europe and this should make overall compliance easier. 
But still, for most, compliance will require changes be put into place for how data is stored and also changes put in place for how people can be put in control of their own data. 
 
Remember, the GDPR is not just about firms that operate in the EU. It applies to firms that have data on EU citizens. 
The GDPR requires that to collect info on EU citizens, the citizens must give their consent and the citizen also has the right to be forgotten. The data it applies to is broad, including even IP addresses.
 
At this point, just 20 days away from the compliance deadline, we recommend all firms do three things:
 
1. Read the rules yourself. They are not that hard to read and think about
 
2. Consult outside counsel. Pick a law firm you know and trust and ensure they have knowledge of the GDPR. Ask us if you need some recommendations.
 
3. Seek an external review of your technical architectures for compliance. Our firm, Crucial Point, is a good place to start here.
We recommend that Boards (including Audit Committees for those that have them) should evaluate their company's data retention activities and policies to see if they are in need of modification to comply. 
Boards should ask CEOs and the management team to assess where exposure to GDPR non-compliance is greatest and prioritise actions to fix. 
 
Boards should ask questions to determine if line of business leaders realise they are responsible for compliance vice just assuming this is an IT function. And boards should know who the Data Protection Officer (DPO) is for the firm.
 
Here is more on the GDPR:
 
• Fines for non-compliance are up to 4% of annual revenues.
• Customers must consent for processing of their data
• Personal data must be protected. This includes anything related to a natural person or anything that can be used to indirectly identify the person. This includes names, photos, email addresses, bank details, addresses, posts on social media sites, medical info, IP addresses
• The rule describes a new position, a Data Protection Officer (DPO), which will be required for firms that do large scale monitoring or processing of sensitive data
• Consent of users is required and it must be asked for and granted in specific ways before collecting and processing data.
• Citizens are given new authorities over their data including right to have it removed (a right to be forgotten)
• Data protections are expected to be designed into systems
• If there is a breach of personal information, the citizen will be notified and impact assessments done
• Transfer of data to other countries and organizations is regulated
• Companies are expected to maintain a state of the art cybersecurity architecture and posture
 
We can accelerate your compliance with GDPR and do so in a way that helps your security posture. 
 
CTO Vision
 
To contact the GDPR Advisory Board please click HERE:  
 
You mIght Also Read: 

The Pitfalls Of GDPR & Cyber Security For Micro Organisations:
 
Cybersecurity Advice For SMEs:
 
« A Guide To Preventing Charity Cybercrime
Meet Tess: The Mental Health Chatbot »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 7,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

ABB

ABB

ABB is a pioneering technology leader in industrial digitalization. Services include cyber security for industrial control systems IoT.

DG Technology

DG Technology

DG Technology is a customer-centric technology expert and business consultant that delivers services and products to minimize your information security, compliance, and business risks.

Seltek Technology Solutions

Seltek Technology Solutions

Seltek provides Digital Forensics, eDiscovery, Cybersecurity Assessments and IT Support services.

Austrian Trust Circle

Austrian Trust Circle

Austrian Trust Circle is an initiative of CERT.at and the Austrian Federal Chancellery and consists of Security Information Exchanges in the areas of the strategic information infrastructure.

Safetica

Safetica

Safetica Technologies is a Czech software company that delivers data protection solutions for businesses of all types and sizes.

Garner Products

Garner Products

Garner design, manufacture, and sell equipment that delivers complete, permanent, and verifiable data elimination.

Charities Security Forum (CSF)

Charities Security Forum (CSF)

The Charities Security Forum is the premier membership group for information security people working for charities and not-for-profits in the UK.

Avertium

Avertium

Avertium is the managed security and consulting provider that companies turn to when they want more than check-the-box cybersecurity.

Wiser Market

Wiser Market

Wiser Market is a leading company in global online brand protection services, intellectual property protection, anti-Counterfeit & trademark infringements.

Stratejm

Stratejm

Stratejm, a Next Generation Managed Security Services Provider, brings innovation and thought leadership to the fight against cyber criminals.

Silicon Cloud International

Silicon Cloud International

Silicon Cloud is a high performance and secure cloud computing platform for engineering and scientific applications.

CyberGuard Technologies

CyberGuard Technologies

CyberGuard Technologies provides a suite of fully managed end-to-end security services from its 24/7 UK security operations centre.

Brightsolid

Brightsolid

Brightsolid are experts in Hybrid Cloud. We design, build and manage secure, scalable cloud environments that meet customers’ business ambitions.

Data Defenders

Data Defenders

Data Defenders provide information security technology solutions that empower consumers, businesses and governments with safe and secure IT and cybersecurity infrastructures.

Fingerprints

Fingerprints

Fingerprints is the world-leading biometrics company. Our solutions are found in millions of devices providing safe and convenient identification and authentication with a human touch.

AUCloud

AUCloud

AUCloud is a leading Australian cyber security and secure cloud provider, specialising in supporting businesses and Governments with the latest cloud infrastructure.