Do you know how your personal data is used and exchanged within Facebook or Google? How do you feel if you see your personal information is exposed to a digital marketer and he keeps bombarding you with promotional offers which you are not interested in? Whether you like it or not, this is how it works today. Your personal information is there to be used by anyone who can pay a small amount of money or capable of doing some kind of hacking. Do you ever think about why someone wants your full detail when registering into some kind of service?
Within first 6 months of 2017, there has been more than 6 Billion personal records were exposed through data breaches. They cost millions of dollars to the organizations today and in the future. Trust and confidence are the most important factors in today's business. 70% of customers reports that they would be less inclined to work with a business that suffered a public disclosure of a data breach.
From the above facts, it is self evident that data protection is not only important to the customers but also to the businesses. Even though business leaders understands the value of the data, that understanding has not translated into careful data stewardship. But with the impact they have seen with these data breaches on other businesses, everyone is now keen on having a better protection to their data.
General Data Protection Regulation or GDPR provides the much needed kick in the ass to many businesses that have become complacent about the data security. All the businesses dealing with data about EU citizens (in and out of EU) needs to comply with this regulation by 2018 May. It is the successor to the previous regulation data protection directive which was introduced in 1995.
Even though this is a regulation, it has many useful things which any business can use for their benefit.
Within first 6 months of 2017, there has been more than 6 Billion personal records were exposed through data breaches. They cost millions of dollars to the organizations today and in the future. Trust and confidence are the most important factors in today's business. 70% of customers reports that they would be less inclined to work with a business that suffered a public disclosure of a data breach.
From the above facts, it is self evident that data protection is not only important to the customers but also to the businesses. Even though business leaders understands the value of the data, that understanding has not translated into careful data stewardship. But with the impact they have seen with these data breaches on other businesses, everyone is now keen on having a better protection to their data.
Source: https://marketoonist.com/2017/10/gdpr.html
General Data Protection Regulation or GDPR provides the much needed kick in the ass to many businesses that have become complacent about the data security. All the businesses dealing with data about EU citizens (in and out of EU) needs to comply with this regulation by 2018 May. It is the successor to the previous regulation data protection directive which was introduced in 1995.
Even though this is a regulation, it has many useful things which any business can use for their benefit.
Forcing awareness about entire data web
- Business leaders are forced to understand their data landscape no matter if your company is a small company or a large multi national company with subsidiaries and 100s of partners. All the incoming and outgoing data must be well understood.
- If the business has subsidiaries and partners, the entire data web needs to be well understood.
Demanding knowledge of data sources and origin countries
- Every data source (Partners, Customers, Subsidiaries) feeding data into the organization must be vetted and documented.
- GDPR is the first global data protection law
- Applies to any business which process data about EU citizens
Advising data minimization
- Companies must state a planned use for all the personal data they obtain. Recommend to use data which is absolutely necessary. No additional data to be used for future.
- Not holding data for any longer than absolutely necessary
- Not changing the original purpose of the data capture
- Deleting any data at the request of the data subject (customer)
Spotlighting data sharing
- Data in transit needs to be properly secured.
- Businesses must be able to document appropriate security measures for every step in data's life cycle
Acquiring consent
- Requires clear, affirmative consent of use for personal information of EU citizens.
- Lack of response is not considered automatic consent
Breach monitoring and response
- Breach notifications needs to sent within 72 hours of breach detection
- Breach policies needs to be carefully setup with partners and well documented
Even though this looks like something annoying for a business, it really has some good things which can be gained for every company. This regulation provides the careful design of your business data and avoid keeping unnecessary data within your organization and hence reducing the operational expenditure.
In addition to the above mentioned points, following link provides a list of major changes which are coming with the GDPR.
https://www.eugdpr.org/key-changes.html
nice post you have shared thanks for sharing. Here i have found a origination where you can consults about GDPR and Web Services and they will clear you all dout about GDPR.
ReplyDeleteThanks for sharing this information with us we are GDPR Consultant in India where we are single focused towards our clients and there business strategic objectives and we can provide regular and independent audit services regarding GDPR compliance.For more details call us:- +91 9968416366
ReplyDelete