Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - 6 Months To GDPR
News & Analysis

6 Months To GDPR

ISBuzz TeamBy ISBuzz TeamNovember 27, 20175 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Following the news about GDPR, IT security experts commented below.

Jes Breslaw, Director of Strategy, EMEA at Delphix:

“In a digital age, data privacy is a basic human right. With the clock counting down to the deadline for compliance with the EU’s General Data Protection Regulation (GDPR), businesses should be putting the final processes in place to provide the best, most efficient way of protecting customers’ most valuable assets – their data and identity.

Regulators have given businesses enough time to get their house in order. They will now be itching to make an example of companies that have failed to show due diligence. And what’s worse is that the regulator now has teeth.

If we look at the CEX data breach where the details of two million customers were compromised, the company could have faced fines in excess of more than £5.5 million under the GDPR regime.

In order to move fast and survive, global businesses need rapid and secure access to data. However, it can’t be at the expense of consumer privacy. What’s needed is a new approach that brings together those data operators responsible for managing, securing and distributing the data with those data consumers that are using it to run the business.

The DataOps movement offers such an approach attempting to make data operators and consumers work together to ensure sensitive data is secured and the right data is made available to the right people. At the heart of DataOps, is the ability to intelligently mask personal data at scale. With 90% of data held as copies in test, reporting and analytics systems, dynamic data platforms will protect individuals and accelerate project delivery. It will also remove the compliance requirements for these systems as the data will no longer be personally identifiable.

With the right approach and tools in place, it will be much easier for organisations to keep track of all sensitive information, mask it where necessary, and control who has access to data and for how long. However, businesses must act fast to ensure these processes are in place within the next six months. In a data driven world, how companies handle security and privacy issues will define the winners and losers.”

Chris Olson, CEO at The Media Trust:

Chris Olson“As delineated in GDPR there is a difference between website analytics and unnecessary collection of consumer data. Among other things, the valid use of session replay scripts helps website operators understand how users navigate the websites with the aim of streamlining or improving the user experience. As with any third-party code, these analytics scripts can be compromised without the website operator’s knowledge and can cause security and data privacy problems, which happened to Hotjar in December 2015. These reasons should compel companies to continuously monitor not only their own website code, but that of third parties to ensure that best practices are adhered to and that data privacy of customers are ensured.”

Lee Munson, Security Researcher at Comparitech.com:

“The days of private car parks fleecing motorists for maximum gain, even for a very short overstay, may be of huge concern to Christmas shoppers, but there is light at the end of the tunnel.

“While the DVLA is perfectly within its rights to sell personal data to private firms at this point in time, the incoming General Data Protection Regulation (GDPR) has the potential to close that lucrative side-line overnight, if motorists are aware of their rights.

“From 25 May next year, companies will have to show compliance with the new regulation, one of the requirements of which is the need for informed and unambiguous consent to be in place before data can be shared with third parties.

“As a government agency, I would expect DVLA to be completely transparent about requesting that consent anew from all motorists. Failing that, drivers will of course have the right to withdraw any pre-supposed consent at any time. In either case, the agency will not be able to pass data on in the manner in which it is currently doing so.”

Paul Edon, Director at Tripwire:  

“The first area of concerns here is the legality of recording peoples keystrokes without first informing them of the fact. Second is whether the data is protected in line with PCI standard requirements.

There are many valid use-cases for keystroke logging; training aids, presentations, auditing, and even security. However, keylogging is also a tool associated with nefarious activities such as hacking. The non-nefarious use-cases will almost always include an onscreen notice informing the user that their keystrokes are being recorded, the nefarious will definitely not. If these websites do not alert the user to the fact that they are recording keystrokes, then I would class this under “nefarious activity” as it is being less than honest, and the information is being collected without the user’s knowledge.

Many web forms collect personal and financial data from potential customers. Critical Information such as: Name, Address, D.O.B., Credit/Debit card details, including 3 digit CVV. If this information is being collected regardless of whether the potential customer submits the form or not, then this raises another question beyond the legality of the practice; is the information stored, secured and protected in line with the requirements of the DPA, PCI DSS etc.

The collection and storage of information not submitted by a potential customer will definitely be a breach of the EU GDPR, as permission to collect, store and process the data has not been given.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}