Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - A Guide for Businesses on the EU Data Protection Reform
News & Analysis

A Guide for Businesses on the EU Data Protection Reform

ISB Editorial StaffBy ISB Editorial StaffApril 7, 20165 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In advance of the introduction of the General Data Protection Regulation (GDPR), bringing stricter EU data protection rules, now’s the perfect time to familiarise yourself with how to ensure that your business stays within the regulations.

The below is a brief outline, but you’ll find more detailed information along with examples of good – and not so good – practice in this step-by-step guide.

Step 1: Examine the data that you hold

Your first port of call should be to have a thorough investigation of the data that you hold on your customers or the people within your email database, examining why you need that information, how you use it, how long you’ve held their data and when/how they signed up. Under the new rules you should only hold data for a ‘reasonable’ length of time – which very much depends on why you need the data. For example, if it’s data gathered from a one-off sale then that’s very different from holding the details of a customer with whom you have an on-going relationship. Establishing why you need that information and how you use it for each group, will help you determine what the reasonable length of time will be.

When you identify the personal data you no longer need, it’s time to delete those records.  As well as helping you to stay on the right side of the regulations, this will also create a higher quality database populated by more recent, and hopefully more active, customers.

It may be that you want to use older customer data for analytics and this is fine – as long as you make the data anonymous. This should be a relatively simple process which will retain the information you do need and erase what you don’t, aggregating this data into one anonymous pot where the individuals can’t be recognised, but still allowing you to use it for information purposes.

Step 2: Perfect your privacy statements

When you make a privacy statement it’s essential that, among other things, you cover 3 key areas;; who you are, how you’re planning to use a customer’s data and who else you might share it with (if relevant) . It’s a complex area, or at least the last two elements are, so guidance has suggested that a good way to do this is through a layered approach. This means starting with a simple privacy statement but also having more comprehensive information for anyone who wants a more detailed explanation. Obviously, not everyone will want this but it’s important to have it available for those that do.

It’s also vital to remember that you must give people the opportunity to actively acknowledge your privacy policy. If you use pre-filled boxes or assume that a customer’s silence amounts to consent then you’ll be in contravention of the rules.

Step 3: Collect evidence of consent

Unfortunately it’s not going to be enough to simply state that you’ve received consent from customers to hold or use their data. There may be situations when you’re required to prove it too – and you need to be able to do this clearly, quickly and easily. This is potentially tricky in the case of people whose consent has been implicitly assumed in the past, for example by not un-checking pre-filled boxes. You should re-opt-in these people – one of the easiest and most cost-effective ways of doing this will be to send out emails to this group explaining why you are contacting them and giving them two options, either to give or deny consent to the use of their data.

Alternatively, if customers have registered their preferences with you in the past, the email could direct them to amending their details as required. This means that if they change their preferences regarding data use, you’re staying up to date with what you can and can’t do, and you have recent customer data to use within your marketing campaigns.

Above all, you should note that the older data is the more important it will be to be able to prove that you still have consent to hold and use it. So having a robust and effective strategy to achieve this is more important than ever before.

What’s next?

It may all seem like there are too many hoops to jump through, but there are also real benefits to ensuring you abide by these data & compliance rules set out in the GDPR. The points outlined have always been best practice, and following them will create a better, more trusting relationship with your customers – and trust is one of the most valuable commodities for any business or organisation.

We’ve written this post just to get you thinking about what you need to do in advance of the GDPR coming into effect. The final text could be approved as soon as this month, then the 2 year countdown will start. For more information around the next steps you should consider, follow Communicator’s series of 6 EU Data Regulation Guides, all available here.

[su_box title=”About Ashleigh Wood” style=”noise” box_color=”#336588″][short_info id=”66247″ desc=”true” all=”false”][/su_box]

ISB Editorial Staff
  • ISB Editorial Staff
    Navigating the Cyber Threat Landscape: Key Insights from Trellix ARC’s Q1 2023 Report
  • ISB Editorial Staff
    Experts’ Responses: Cyber Security Predictions 2022
  • ISB Editorial Staff
    ISB Virtual Conference: Key Cyber Security Challenges and Solutions in 2021
  • ISB Editorial Staff
    Cyber Security Predictions 2021: Experts’ Responses

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}