GDPR compliance: Don’t cloud the issue of data protection by design

Following a period of lengthy debate, fine tuning and approvals from various political entities, the EU General Data Protection Regulation (GDPR) will soon come into effect. With just one final stage of approval yet to come, the GDPR is set to finally become law this spring, leaving organisations with two years to achieve full compliance with the regulation.
Whilst two years may seem like a sufficient amount of time, the fact is that IT teams are faced with the challenge of controlling a hugely complex web of cloud use in the workplace. As a result, GDPR compliance will be tricky: recent research conducted by Netskope and YouGov revealed that almost 80 per cent of IT professionals in medium and large organisations do not feel confident that they will be able to ensure compliance with the regulation before the expected deadline of spring 2018 falls.
Organisations striving for GDPR compliance must consider enterprise cloud app use. It is a difficult hurdle to clear: cloud apps create unstructured data which is not only more difficult to manage but also explicitly included within the regulation. The research found that while nearly a third of IT professionals admit to knowing full well that shadow IT is rife in the organisation – meaning that employees are using unauthorised cloud apps at work, placing data at risk – only seven per cent have implemented a solution to deal with this problem.
Blanket block policies when it comes to apps are not an option because cloud app use leads to such huge productivity gains. Businesses have to find a balance, enabling continued use of cloud apps while ensuring that structured and unstructured data, both at-rest and in-transit, are protected. But how can organisations securely allow employees to use cloud apps while ensuring GDPR compliance?
Under the GDPR, companies are required to take active measures to protect their data.


