Article

William Yates
William Yates 7 March 2016
Categories Technology

GDPR: What Is It And Why Should You Care?

In recent years data breaches, hacking, data theft and online fraud have emerged as massive issues at both the corporate and governmental level, exposing targets to extreme financial instability and nation states to political or defence vulnerabilities.

Anthem Insurance, Home Depot, Adobe and the UK NHS have all been hacked or even had data physically stolen and whichever way, the impact on data privacy is significant as sensitive personal data is released into the public domain.

Data Security: How Big Is The Issue?

Over the past year, the UK has suffered the greatest number of data breach incidents in the EU, with 63 by end-Q2 2015; way above Germany with 8, and the Netherlands with 6.

Interestingly, in these breaches 8.3 million records were exposed, which is only 3.4% of the global total of 246 million: the US accounted for 49% of all records compromised, with Turkey at 26%.

The first half of 2015 also shows a 10% increase in data breaches on the same period a year previously, while the number of records stolen reduced by 41%. This may be due to a smaller number of mega-breaches but very likely indicates varying regional security and data protection compliance.

eu-flag-1568439_500x585.jpg

Cohesive Trans-EU Protection

The current EU Data Protection Directive 95/46/EC is about twenty years old, and is from a very different time.

As technological evolution accelerates exponentially so security gaps, critical issues such as trans-national operation, developments in social networks and cloud computing have evolved and are not covered in a legally cohesive and meaningful way.

The new EU-wide General Data Protection Regulation (GDPR) will transcend any local data privacy laws and will be designed to provide a more comprehensive and wide-ranging legal framework, which will deliver much tougher personal data privacy legislation.

What Is GDPR?

GDPR is a Regulation with which the European Commission intends to strengthen and unify data protection within the European Union (EU), and is designed to also address the export of personal data outside the EU.

The Commission’s primary objective with GDPR is to simplify the regulatory environment for international business by unifying the regulation within the EU, and unlike a Directive, it does not require legislation to be passed by governments.

What GDPR Means To You

photo-1453060113865-968cea1ad53a_500x333.jpg

The proposed new EU GDPR data security programme expands the scope of EU data protection law to all non-EU companies processing the data of EU residents. It synchronises data protection regulations throughout the EU, making it much simpler for non-European enterprises to comply with these regulations.

While the precise wording of GDPR and financial penalties for transgression have yet to be finalised, GDPR has a very stringent data protection compliance administration with severe and rigorously imposed financial penalties of up to 4% of global gross revenue or €20,000,000 – whichever is greater – for non-compliance.

What About Your External Vendors?

While this EU-wide regulation relates to the data owner – the entity legally accountable for the data -laws relating to data management, processing and security will also impact on your enterprise if there are contraventions by third party vendors, such as your digital marketing agency.

This means that you, and your enterprise must be confident that such third party vendors have the required legal know-how and competency in current EU Data Protection Directive 95/46/EC as well as upcoming GDPR.

The most resilient verification of this is that your agency has ISO 9001 certification for data management and very importantly, ISO 27001 data security certification.

Where Do You Seek Assistance

photo-1454165804606-c3d57bc86b40_500x333.jpg

Surprisingly, help is very scarce. My agency, Novacom, has both of these critical certifications so I was surprised to learn that according to ISO’s own statistics, only 0.06% of registered UK organisations (that covers everything from government departments to banks) were ISO 27001 certified.

And it’s even less prevalent in the US, one of the EU’s top trading partners, at 0.0036% of all registered companies. Given that trade often means data transfer, transferring data to a potentially unregulated destination could prove to have very serious legal and financial impacts on you and your EU-based enterprise.

Action Points

The current EU Data Protection Directive 95/46/EC legislation is generally little understood in many areas of the EU, and in many respects quite poorly enforced. 

But with the recent growing number of data breaches, and GDPR coming soon, this situation will change very quickly.

GDPR and rapidly increasing cybercrime incidents mean companies must start taking data security seriously to mitigate security risks much more effectively.

This means not only auditing current internal security and data privacy procedures, but now ensuring your third party vendors offer the same high level of security.

Please login or register to add a comment.

Contribute Now!

Loving our articles? Do you have an insightful post that you want to shout about? Well, you've come to the right place! We are always looking for fresh Doughnuts to be a part of our community.

Popular Articles

See all
How to Review a Website — A Guide for Beginners

How to Review a Website — A Guide for Beginners

A company website is crucial for any business's digital marketing strategy. To keep up with the changing trends and customer buying behaviors, it's important to review and make necessary changes regularly...

Digital Doughnut Contributor
Digital Doughnut Contributor 25 March 2024
Read more
The Impact of New Technology on Marketing

The Impact of New Technology on Marketing

Technology has impacted every part of our lives. From household chores to business disciplines and etiquette, there's a gadget or app for it. Marketing has changed dramatically over the years, but what is the...

Alex Lysak
Alex Lysak 3 April 2024
Read more
The World Is Shrinking: 6 Degrees of Separation Is Now 2!

The World Is Shrinking: 6 Degrees of Separation Is Now 2!

Six degrees of separation is not just a party game, it's a reality. Everyone is the world is interconnected, and thanks to social media, that connectedness gets tighter and richer each day. See the research...

Scott Christley
Scott Christley 9 August 2017
Read more
10 Factors that Influence Customer Buying Behaviour Online

10 Factors that Influence Customer Buying Behaviour Online

Now is an era where customers take the center stags influencing business strategies across industries. No business can afford to overlook factors that could either break the customer experience or even pose a risk of...

Edward Roesch
Edward Roesch 4 June 2018
Read more
Cats and Dogs Boost Your Business By 300%. Here’s How.

Cats and Dogs Boost Your Business By 300%. Here’s How.

It’s the age-old question that has endured ever since the creation of the internet: are you a cat person or a dog person? Or do you love both cats and dogs? We have both dog lovers and cat lovers at Sortlist, so it...

Aline Strouvens
Aline Strouvens 27 August 2021
Read more