Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - GDPR: What are we going to do with your data?
Articles

GDPR: What are we going to do with your data?

ISB Editorial StaffBy ISB Editorial StaffMay 4, 2016Updated:July 4, 20246 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
expert comments on GDPR
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

“Keep Calm and Carry On” seems a fitting theme for the finally-published General Data Protection Regulation (GDPR) – a new European wide legislation which is designed to give individuals greater control over their personal information. However, this is only the case if you’re one of the organisations already valuing customers’ data. Unfortunately, for too long, some organisations have “presumed” consent, worked with “implied” permission, experienced data losses which have taken months to detect and report (remember Sony and Target?) and, in some cases such as TalkTalk, have been unable to properly classify which personal data has been compromised. No CEO wants to look as ill-informed as poor Dido Harding, and customers have an absolute right to expect better.

DQM GRC’s new research, in association with DataIQ, shows the extent to which consumers have become both suspicious and savvy about how companies use their personal details. Awareness of data protection controls is high among consumers, with 84 per cent having seen cookies notices, 76 per cent unsubscribe links in emails and 74 per cent have noticed privacy policies. Yet only half say they notice registration forms and requests for their personal data, which suggests that they overlook the starting point of how an organisation comes into possession of their personal information and subsequently makes use of it.

A significant proportion (49 per cent) are reluctant to share details unless there is a clear justification behind why they should – except if they trust the brand. Equally, consumers expect companies to encrypt their data and use technology that is properly monitored to prevent hacking and the consequent distress that accompanies those events. This is with good reason, as half of those surveyed had experienced some kind of personal data breach (such as a website hack, account hack, or even identity theft).

The research shows that consumer expectations about how their data will be protected align with what regulators endorse, but that this may also prove taxing for organisations; 76.8 per cent expect encryption, 67.5 per cent believe that firewalls should be kept up-to-date and half think that usage will be both limited and monitored. Whilst consumers are perfectly entitled to demand organisations take these steps to ensure their data is protected, implementing these processes may be difficult for the 18.4 per cent of organisations who admitted they will require 12-24 months to make the required changes – cutting the GDPR two-year deadline quite finely.

In some respects, it’s a shame that it’s the headline-grabbing, eye-watering fines of up to 4% of global turnover or €20m plus the requirement to notify customers and the ICO of unencrypted data breaches, that are catching businesses’ attention. However, if this is what it takes to make companies wake up and realise it is not their data, it’s our data that we are entrusting to them for safe keeping, then this is definitely substantial progress. It should certainly help the business case.

So what can organisations do?

Firstly, organisations need to evaluate the personal data they have; categorising the data so they are clear where the personal and sensitive data resides and where other less important data sits in the company. Usually, drafting a data flow map will help businesses to understand the pattern of data through the company, provide clarity on who has “eyes on” the data, what skills these people have and, finally, highlight where the data ends up.

Once organisations understand just what personal data they have, they should then ensure that regular risk assessments are completed in order to understand the degree of threat imposed on the company when processing data. Indeed, the GDPR demands a “risk-based approach” with the development of appropriate controls. This should, in a single stroke, ensure that management recognise the dangers associated with the loss, misuse, theft or any other compromise of customer data.

For organisations that pass data onto third parties, there is often a tendency to presume that they must operate to high standards of data security and protection. However, the GDPR now states that controllers must only engage with processors who can provide “sufficient guarantees”. Basically, as the data owner, you must check they have effective “technical and organisational measures to ensure the security of the processing”.

Subsequently, there is now an essential need for organisations to prepare a breach notification plan in the event that something does actually go wrong. If you’re already clear on what type of personal data you manage (categorisation) and where it is (data flows), then this process will be somewhat easier. However, it’s worth being clear on who will co-ordinate the customer communication, the media response and the remedial activity – and make sure you rehearse this so you are practiced in the actual event; consider it a data breach fire drill.

The benchmark for what organisations should do when they suffer a data loss or breach is set high by consumers – 92 per cent of those surveyed said they expect to always be notified and told exactly what information has been lost or stolen. In addition to this, the research also revealed that consumers would expect a public apology from the company, as well as compensation (57 per cent each).

However, if consumers are demanding to know what personal information has been compromised in a data breach, organisations will need to classify their data assets. Worryingly, only 30.7 per cent have done this for all of their data types and one in five companies resist the idea, with 11.4 per cent saying they would not do it and 9.7 per cent that they would only do so if required by law.

One of the best forms of data protection is to ensure all aspects of the organisation involved in using personal data are equally included in the data governance processes. This ensures all functions operate to a common standard, which is particularly vital in the event of a data breach. It is also important for organisations to try and spot trends in any data problems that occur, and to not just record issues separately. Otherwise there will be a risk that each incident will be seen as unique, rather than having common root causes – which can then be rectified and solve the entire issue.

Additionally, it is vital that organisations consider an engaging staff training programme to ensure all employees are aware of the valuable asset they are dealing with and understand the need to manage data securely. Data security is an important component of building consumer trust and confidence. Finally, all organisations should respect the personal data they have in their possession and treat it like it is their very own – otherwise the new “privacy aware” consumer may decide to take it elsewhere.

[su_box title=”About Christine Andrews” style=”noise” box_color=”#336588″][short_info id=’67794′ desc=”true” all=”false”][/su_box]

ISB Editorial Staff
  • ISB Editorial Staff
    Navigating the Cyber Threat Landscape: Key Insights from Trellix ARC’s Q1 2023 Report
  • ISB Editorial Staff
    Experts’ Responses: Cyber Security Predictions 2022
  • ISB Editorial Staff
    ISB Virtual Conference: Key Cyber Security Challenges and Solutions in 2021
  • ISB Editorial Staff
    Cyber Security Predictions 2021: Experts’ Responses

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}