What are the Business Implications of GDPR?

3 min read
Curated from techtarget.com →

For those of you that don’t know what GDPR is [and didn’t yet connect with my first blog on the subject] it stands for “General Data Protection Regulation” and is the new European Union law on data protection, replacing the existing EU data protection directive and will be implemented by every individual country in the EU. This has wide ranging implications for enterprise organizations across the EU.

TechTarget users are certainly keen to understand these implications and what they need to do to get ready for it. In fact, we are seeing 5x increase in response from our user base on any promotional emails around GDPR. The best news is that your customers and prospects in EMEA are not only paying close attention to this, they also have budget in 2017 and 2018 to comply with the necessary IT changes they need to make. Budget your marketing and sales teams need to go after.

As a result, enterprise technology organizations, especially in technology sectors most affected by GDPR, and their marketing teams must be ready to communicate their positioning around these new regulations. Following is information from a recent sit-down European editorial expert and Computer Weekly Editor-in-Chief, Bryan Glick that will help you get a better handle on what GDPR is and what the major implications are.

[AND – as a bonus – if you want to hear more from Bryan on marketing best practices for GDPR please watch this video of him presenting at the May 2017 TechTarget London ROI Summit.]

The issue around where the data is physically located is still a controversial one. Strictly speaking, the EU says that you can only move personal data of EU citizens physically out of the EU if you’re moving it to a country that has comparable levels of protection. This used to be handled by a Safe Harbor agreement; however, Safe Harbor was ruled invalid by a legal court case in Ireland in 2016 on the basis that the US Patriot Act took precedent when the data landed in the US, thus, making the data less protected for EU citizens. In late 2016, the US and the EU came up with a new agreement called Privacy Shield. Even with Privacy Shield there still remains a question about moving data out of the EU. GDPR introduces a much higher level of data protection than the current laws so there is still a question to the degree to which you’ll be able to move data out of the EU.  

Some of the more stringent requirements that GDPR introduces that are important are around data storage, particularly around backup, archiving and data management. GDPR widens the definition of “what is personal data”. It moves the definition to “personal data is any data that could be used to identify an individual”. For example, genetic data, which doesn’t have a name, can be used to identify an individual. Anonymous healthcare records are covered and, as yet, undetermined forms of data. In your data management you need to be able to flag data that could be used, even when combined with other data, to identify an individual. If data can be used to identify an individual they do have the right, under GDPR, to ask you to delete it. 

GDPR also tightens up the rules around consent.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at techtarget.com →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.