Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Your Kick-Start Plan For GDPR Compliance From Someone Going Through It Too
Articles

Your Kick-Start Plan For GDPR Compliance From Someone Going Through It Too

ISBuzz TeamBy ISBuzz TeamMarch 12, 20177 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

If you are reading this, you already know what GDPR is and why it is so important that your organisation is compliant. Like most working on compliance in their organisation, I have attended various GDPR events. Clearly, there is huge interest in this subject and it is interesting to see the various ways in which the topic of GDPR can be used to encourage attendees to events – even when there is a tenuous link at best.

At the most recent of one of these events that I attended, the audience was asked how prepared they were for GDPR – from no idea, through to validating a plan. The overwhelming response was ‘I know I need to do something, but I don’t know how’. From the perspective of someone going through GDPR compliance in a 10,000 employee global organisation, I wanted to share my experience of what has worked for me so far.

Step One: Build Awareness and Budget

Step One Build Awareness and BudgetIt is a simple step, but so important. Your GDPR compliance project is going nowhere if you do not have the senior support and budget to sponsor it. For me, the compelling message to my board was the financial impact of the new penalties under the regulation. It is a tough message to deliver without scaremongering, but 4% of global turnover is sure to capture executive attention. I have found that it is useful to play through some of the more recent data breaches, such as Three, Tesco Bank and Sage and highlight what the fine could have been with GDPR in place. It is important to temper this message and explain that the financial penalty is up to 4% of global turnover or €20 million (whichever is greater), however an organisation could also see a 2% fine or a data processing prohibition order – any of these could be crippling to a business. Executives are starting to understand that it is not possible to eliminate all cyber security risks and they need to play an active part in protecting their organisation.

With this base level of awareness in place, I then identified those members of senior management that were advocates and invited them to an independent external legal briefing on GDPR. This helped me to make sure they heard a trusted second opinion and helped to bring to life the complexity of now having to consider IP addresses, usernames and meta-data as personally identifying information.

By doing this, you will build a small, albeit powerful community of change agents. Complement them by finding those in parts of the business that already understand their data protection responsibilities. Those that work in HR, Payroll and Pensions are usually good places to look. With this slightly larger community, you can build a taskforce who will have the mandate and understanding to actually deliver compliance. This mix of shareholders in different parts of the business is important because you will need to reiterate that GDPR compliance is not an IT or Legal issue in isolation.

Finally, become or hire a GDPR expert. As discussed early, you will not find a true GDPR expert due to the contemporary nature of the regulation. Individuals with a data protection or privacy background are most likely to be skilled in this area.

Step Two – Data Mapping and Gap Analysis

Step Two - Data Mapping and Gap AnalysisBefore you can protect it, you will need to understand where the personally identifying information is within your business. Depending on how structured this data is within your business and how much budget you have, you may be able to do this using data discovery tooling. In my case, I opted to undertake data discovery workshops around the business. Even if you can use data discovery tools, I would still recommend a more traditional approach. Using a whiteboard, map out the high-level business processes and data flows, and capture any data security concerns. The objective of these workshops is to map the business processes and data flows around the business using the local knowledge of the people that operate these processes. This approach has two important benefits; firstly, the people that operate these processes are most likely to know the intricacies of the various data flows and human elements far better than any tool. Finally, those that know the process are best placed to identify and own compliance improvement activities. This is important because, like any significant change activity, you cannot do sustainable GDPR compliance to people.

In my business, I started these workshops in the parts of the business with the most sensitive data. Even with these early workshops, quick wins were identified, including cost savings with the removal of duplicate data. From here, you will have the momentum to move around the rest of the business and do the same in all areas – it is a big piece of work but it is essential. The output of these workshops will then give you high-level compliance status for the business and the detail to build a plan for improvement.

Step Three – Policy Review and New Rights

Alongside the data mapping process you will need to review the policy statements you have in place for data protection. Many of these you will already have in order to comply with the Data Protection Act, but they will need to be refreshed to cater for the new rights that data subjects will have under GDPR; such as right to be forgotten and data portability. These policy statements also act as the internal authority for employees and data owners to be aware of their responsibilities.

The new rights under GDPR are probably the most contentious part of the regulation. For subject access requests, you have 10 less days to service the request than you did under the DPA. That is just a simple example, but will require process improvement to prevent non-compliance situations. Taking the more complex new requirements, such as the right to be forgotten, a root and branch redesign of business processes involving personal data will be required.

Step Four – Review and Improve

As complex as GDPR is, it is really nothing new. We’ve had data protection legislation for nearly 20 years and now is the right time to be reviewing how this works in an increasingly connected world in which we have ‘big data’ possibilities to balance with the demands of privacy aware citizens.

In my view, the difference is that there is an expectation that data protection efforts become more effective within organisations. Whilst we have had data protection legislation for nearly two decades, the volume and impact of the now nearly countless data breaches proves that organisations aren’t really taking those responsibilities as seriously as they should. No-one wants to be the first organisation to suffer a data breach when GDPR comes into force, but it will be the true test of its asserted strength and only then will we see how the regulator wants to play their role going forward.

This means there must be a focus on sustainment when you are in a position that your organisation is compliant. There are many ways to test this, but the key has to be culture. Driving meaningful cultural change within an organisation is one of the hardest tasks to achieve but it all starts somewhere. I hope that this article helps you start that journey.

[su_box title=”About Paul Heffernan” style=”noise” box_color=”#336588″][short_info id=’101117′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}