Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - The GDPR Will Be Better For Business Owners Even If It Is A Headache
Articles

The GDPR Will Be Better For Business Owners Even If It Is A Headache

ISBuzz TeamBy ISBuzz TeamMarch 29, 2017Updated:July 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
business man with problems and stress in the office
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

headache

“headache” (CC BY-SA 2.0) by openDemocracy

With the Data Protection Directive (95/46/EC) set to be replaced in 2018 by the European Union’s General Data Protection Regulation (GDPR), businesses will soon have to adapt. With cyber security now a hotter topic than ever before, businesses are being held increasingly accountable both for their own and their customers’ actions.

In fact, when the GDPR comes into effect in May 2018, it won’t just be businesses inside the EU that must comply with the new rules. Under the new set of regulations, individuals will get more control over their personal data. On an operational level, this means applicable organizations will have to have the following provisions in place:

Mandatory Notifications – If a company suffers a data breach, the GDPR states that said company must report it to regulators and the affected individuals immediately. In practice this means companies will be forced by law to be more open about their security and, importantly, how they store their data. They’ll also be more accountable for it.

Right to Erasure – Individuals will have the right request the deletion of their personal data when this data is no longer needed for its original purposes. In practice, this means companies will have to review the way they process client information because it may be necessary for them to delete specific parts of a data file that are no longer needed, or even the whole data file. Essentially, the company will have to keep its records in order to ensure they’re able to pick out certain pieces of information following a request to delete something.

Privacy Impact Assessment – This lengthy assessment will review all areas of a business with regards to its security provisions, data storage and marketing efforts. What’s also significant is that it will focus on the businesses activities both inside and outside of its main offices. For companies, this will mean provisions for data protection now have to be applied across the board regardless of the expense.

Data Protection Officers – To ensure continued compliance, the GDPR asserts that larger businesses will have to have a dedicated in-house data protection officer (DPO). The EU recommends that a DPO be a lawyer, which means a company will have to factor this cost into their overall budget.

This Isn’t an Issue Businesses Can Ignore

degree

“FIGURE 11.2 360-degree feedback” (CC BY 2.0) by Jurgen Appelo

Given that the operational changes required to meet the new guidelines from the GDPR could be both challenging and costly for many businesses, there could be a temptation for companies outside of the EU to ignore the directive.

Unfortunately, even businesses outside of the EU may have to follow the GDPR. When looking at the guidelines and asking whether the GDPR applies to your business, it’s worth noting that any personal data that originates from the EU is subject to the rules. To put this in context, “organizations of any size in any country that process anyone’s data—if that data originated in the EU—is subject to the GDPR”.

Okay, but what if a business simply chooses to ignore the directive and continue as normal? Again, the EU has thought about this and decided to impose stiff financial penalties on any company not in compliance. At the upper end of the scale, regulators will have the power to fine businesses as much as €20 million (approx. $22 million) or 4% of their global turnover (whichever is greater) in the event they fail to adhere to core principles of data processing, infringement of personal rights, or the transfer of personal data to other countries or international organizations that do not ensure an adequate level of data protection.

To put this in context, when hackers breached Yahoo’s network and compromised an estimated 1 billion accounts, it only became public news three years later. Had the GDPR been in place and Yahoo was compliant, we would have known about this a lot sooner thanks to the new rules. However, if the GDPR was in place and an investigation revealed it hadn’t met the guidelines, Yahoo could have been hit with a $200 million fine based on its 2016 $5.18 billion earnings.

In short, even if the new rules pose something of a headache for businesses, the potential cost in fines clearly outweighs the cost of any practical changes needed for compliance. Moreover, the end result may be a better experience for customers and potentially businesses themselves. By having more control over their data, customers might have the confidence to provide companies more of their information which could benefit companies in the long run.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}