{"id":22855,"date":"2016-05-25T09:32:29","date_gmt":"2016-05-25T09:32:29","guid":{"rendered":"http:\/\/www.businesscloudnews.com\/?p=254102"},"modified":"2016-05-25T09:32:29","modified_gmt":"2016-05-25T09:32:29","slug":"let-the-countdown-to-gdpr-begin","status":"publish","type":"post","link":"https:\/\/icloud.pe\/blog\/let-the-countdown-to-gdpr-begin\/","title":{"rendered":"Let the countdown to GDPR begin"},"content":{"rendered":"<p><a href=\"http:\/\/www.businesscloudnews.com\/files\/2016\/05\/Europe1.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-254112\" src=\"http:\/\/www.businesscloudnews.com\/files\/2016\/05\/Europe1-300x199.jpg\" alt=\"Location Germany. Red pin on the map.\" width=\"300\" height=\"199\" \/><\/a>The road to data protection has been a long and confusing one. Despite being one of the biggest concerns of consumers and corporates throughout the world, progress has hardly been moving at breakneck speed, but as of today (May 25<sup>th<\/sup>), companies now have exactly two years to ensure they are compliant with the EU\u2019s General Data Protection Regulation.<\/p>\n<p>The general objectives of the GDPR are to give citizens back the control of their personal data and to simplify the regulatory environment for international business by unifying the regulation within the EU. Data protection is a complicated business throughout the EU mainly due slight differences from country to country, and then again, with overarching EU regulations, or directives which haven\u2019t even made it to regulation.<\/p>\n<p>Conversations surrounding the new regulations have been ongoing since 2012, though companies now have until 25<sup>th<\/sup> May 2018 to ensure they are fully compliant. For this would seem an adequate amount of time, however a recent YouGov and Netskope <a href=\"https:\/\/www.netskope.com\/press-releases\/netskope-research-finds-only-1-in-5-companies-confident-of-achieving-gdpr-compliance\/\">survey<\/a> highlighted only one in five are confident they will be compliant in this time period. For Eduard Meelhuysen, VP at Netskope, decision makers need to take a step back to get a better understanding of the current state of their data, before concentrating on any company app.<\/p>\n<p>\u201cIf they are to comply, IT teams will need to make the most of the two-year grace period which means that both cloud-consuming organisations and cloud vendors will need to take active measures now,\u201d said Meelhuysen. \u201cAs a starting point, organisations should take a hard look at how their data are shared and stored, focusing in particular on any cloud apps in use across the organisation.<\/p>\n<p>\u201cThe GDPR makes specific provisions for unstructured data of the type created by many cloud apps, data which are typically harder to manage and control. That means organisations need to manage employees\u2019 interactions with the cloud carefully as a key tenet of GDPR compliance.\u201d<\/p>\n<p><a href=\"http:\/\/www.businesscloudnews.com\/files\/2016\/05\/Security-Protected2.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-254122\" src=\"http:\/\/www.businesscloudnews.com\/files\/2016\/05\/Security-Protected2-300x269.jpg\" alt=\"a safe place to work\" width=\"300\" height=\"269\" \/><\/a>\u201cAs cloud app use continues to increase within businesses, data will become harder to track and control. But with the GDPR instigating a maximum possible fine of \u20ac20 million or 4% of global turnover (whichever is higher) in certain cases, there is now more incentive than ever for companies to focus on data protection. Getting a handle on cloud app use will be a crucial part of ensuring compliance for any organisation, and IT teams will need to start work now to meet the May 2018 compliance deadline.\u201d<\/p>\n<p>One area which has been given attention within the GDPR is that of data residency. New regulations will require organizations do not store in or transfer data through countries outside the European Economic Area that do not have equivalently strong data protection standards. The list of countries that meet these standards is short, 11, with a notable absentee, the United States of America, which could pose problems for numerous organizations.<\/p>\n<p>While this may be considered one of the headline areas for the GDPR and one which will likely be heavily scrutinized, for Dave Allen, General Counsel at Dyn, concentrating too much on this area could lull companies into a false sense of security.<\/p>\n<p>\u201cAs the EU GDPR comes into effect, businesses will need to take a hard look at their current methods of sharing and storing data,\u201d said Allen. \u201cWhile some Internet companies have begun to address new challenges at the fixed locations where data is stored \u2013 this alone will not necessarily be enough to ensure compliance.<\/p>\n<p>\u201cThose companies focusing solely on data residency may well fall victim to a false sense of confidence that sufficient steps have been taken to address these myriad regulations outlined in the GDPR. As the GDPR will hold businesses accountable for their data practices, businesses must recognise that the actual paths data travels are also a key factor to consider. In many ways, the constraints which come with the cross-border routing of data across several sovereign states mean these paths pose a more complex problem to solve.<\/p>\n<p>\u201cAlthough no silver bullet exists for compliance with the emerging regulations which govern data flows, businesses which rely on the global Internet to serve their customers should be seriously considering visibility into routing paths along both the open Internet and private networks. As we enter an era of emerging geographic restrictions, businesses with access to traffic patterns in real time, in addition to geo-location information, will find themselves in a much stronger position to tackle the challenges posed by the GDPR.\u201d<\/p>\n<p><a href=\"http:\/\/www.businesscloudnews.com\/files\/2016\/05\/cybersecurity.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-252602\" src=\"http:\/\/www.businesscloudnews.com\/files\/2016\/05\/cybersecurity-300x200.jpg\" alt=\"Anonymous unrecognizable man with digital tablet computer\" width=\"300\" height=\"200\" \/><\/a>Overall, the GDPR will ensure companies take a greater level of responsibility to safeguard the personal data they hold from attacks. Recent months have seen a number of highly publicised attacks significantly impact the reputation of well-known and respected brands, making consumers nervous about which of their personal information is being held. Previously, attacks on such organizations would not have been thought possible; surely they have the budgets to ensure these breaches wouldn\u2019t happen?<\/p>\n<p>Another headline proposition from the GDPR is the consumer\u2019s right to access data which is stored on them, and also the right to have this data \u2018forgotten\u2019. For Jon Geater, CTO at Thales e-Security, this will create numerous challenges and changes to the way in which data is stored and accessed.<\/p>\n<p>\u201cThe new rules also make clear another important factor that we should already have known: that you can outsource your risk, but you can\u2019t outsource your responsibility,\u201d said Geater. \u201cIf organisations use a third party provider to store and manage data &#8211; such as a cloud provider, for example &#8211; they are still responsible its protection and must demonstrate exactly how the data is protected in the remote system. Therefore, formal privacy-by-design techniques need to make their way down the supply chain if companies are to avoid penalties or nightmarish discovery and analysis tasks.<\/p>\n<p>\u201cIn addition, organisations will now have to provide citizens with online access to any their own personal data they store. While the Data Protection Act traditionally allowed anyone to request access to this data, with GDPR in effect organisations must make this available for download \u2018where possible\u2019 and \u2018without undue delay\u2019.<\/p>\n<p>\u201cThis is a very significant change and securing this access will represent a significant challenge to many organisations \u2013 especially while still complying with the new tighter rules \u2013 and will require robust cybersecurity technology across the board.\u201d<\/p>\n<p>What is clear is there will be complications. This shouldn\u2019t be considered a massive surprise as any new regulations are fraught with complications on how to remain or become compliant, but the European Commission isn\u2019t messing around this time. With fines of \u20ac20 million or 4% of global turnover (whichever is greater), the stick is a hefty one, and the carrot is yet to be seen.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The road to data protection has been a long and confusing one. Despite being one of the biggest concerns of consumers and corporates throughout the world, progress has hardly been moving at breakneck speed, but as of today, companies now have exactly two years to ensure they are compliant with the EU&rsquo;s General Data Protection Regulation.<\/p>\n","protected":false},"author":203,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2125,4115,4224,1671,1976,2175],"tags":[],"class_list":["post-22855","post","type-post","status-publish","format-standard","hentry","category-data-protection","category-data-regulation","category-data-residency","category-european-commission","category-news-analysis","category-policy-and-regulation"],"_links":{"self":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/22855","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/users\/203"}],"replies":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/comments?post=22855"}],"version-history":[{"count":4,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/22855\/revisions"}],"predecessor-version":[{"id":22873,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/22855\/revisions\/22873"}],"wp:attachment":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/media?parent=22855"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/categories?post=22855"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/tags?post=22855"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}