5 must know facts about GDPR compliance

2 min read
Curated from cbronline.com →

In just 94 days, the much talked about General Data Protection Rule will be implemented. The big question to every organisation is, are you GDPR ready? Since the announcement of GDPR compliance, there has been a lot of confusion as to what it means and what will happen when it is implemented in May this year.

The confusion has brought concern to businesses and questioned a hefty amount of large businesses as to whether they are GDPR ready, which a lot of FTSE 500 businesses are not. Despite the negative news around GDPR, a recent survey shone light on the matter with a positive spin.

EfficientIP carried out a study that revealed almost three quarters (74%) or businesses are ready for GDPR and know the GDPR compliance rules. For the remaining quarter, here are five must know facts about GDPR compliance and how you can prepare.

When the day finally descends on businesses, it will be mandatory that a Data Protection Officer (DPO) is appointed. GDPR does not measure the protection based on size of business, rather on the amount of data that is being processed. There will most definitely be substantial amounts of data being produced whether organisations are made up of ten or ten thousand workers. Therefore, the DPO role will be there to make sure personal data processes, systems and storage not only adhere to the laws but evidence is also available.

Other mandatory practices organisations must carry out are Privacy Impact Assessments (PIAs). These will be necessary if and when the risk of a privacy breach is high; therefore data controllers are required to carry out a PIA to outline the effect this could have. The DPO of the company will need to ensure PIAs are carried out throughout various projects.

If a data breach occurs within an organisation, it be reported to the information commissioner’s office (ICO) within 72 hours. The discovery of a data breach is not the only thing to know about data breaches within GDPR compliance. Organisations will also be expected to have the necessary processes, and technology, in place to detect breaches before they even happen.

The implementation of technology and processes to detect breaches will be required and organisations will need to invest in both system changes and staff changes. Data processors will be required to notify their customers “without undue delay” after first becoming aware of the breach.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at cbronline.com →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.