Governments continue to eye data privacy, forcing CIOs to adapt

3 min read

As data becomes an increasingly powerful currency, governments around the globe are taking steps to regulate how that data is collected, used and stored. That, in turn, has influenced how IT strategy is crafted.

Forrester Research analyst Paul McKay said the uptick in data privacy regulations has only encouraged CIOs to double down on baking privacy and security into their overall IT strategies. CIOs have had years to adapt to data privacy regulations likeGDPR, which was adopted in 2016 and fully enacted in 2018, but the goal posts are always moving. China recently enacted a new personal data privacy law taking effect Nov. 1 that will require CIOs operating in that market to ensure their IT strategies meet the new requirements.

In this Q&A, McKay, co-author of the recently released Forresterreport”Tech Execs: Take Four Steps to Integrate Cybersecurity and Privacy Into Your Strategy,” said having a privacy- and security-forward IT strategy will be key to an organization’s success when entering new markets and adhering to new security and data privacy regulations.

How has privacy and security changed for CIOs in the last 10 years?

Paul McKay: Everything has been pushed online and when that’s the case, no responsible CIO can take those kinds of steps without at least ensuring that any security or privacy risks associated with that — given the increased regulatory oversight that now exists in many countries — isn’t baked into that plan and dealt with in a more collaborative fashion, rather than tack it on at the end as an afterthought. I think that’s the change we’ve seen in the last 10 years or so.

How have data privacy regulations like GDPR changed privacy and security conversations in the C-suite?

McKay: With regulations coming through as a driving factor, it forces the issue onto the table because then you have regulators who might poke their noses into stuff and kick the tires on things if they’re not done properly with some of the reputational aspects in terms of fines and trust issues with customers that need to be overcome.

A lot more attention is being paid to cybersecurity because of the various breaches that have happened over the last few years. … There’s much more boardroom pressure to make sure all those angles are covered. No one wants to be the C-level executive that’s speaking to the press about what happened. Executives want to know, ‘Are we spending the right kind of money on security? Is it integrated into everything we’re doing? Are we covered?’ They are very simple questions, but they point to a number of factors that force you to integrate privacy and security into what you’re doing rather than try to tack it on as an afterthought.

China just passed a new data privacy law. At this point, how much does something like that impact a CIO’s IT strategy?

McKay: There are certain aspects that tend to come up pretty commonly regardless of the type of regulation.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at searchcio.techtarget.com →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.