EU’s GDPR: What Will American Companies Have To Do To Comply?

4 min read
Curated from ibtimes.com →

Starting next spring, the European Union will begin operating under the General Data Protection Regulation (GDPR). Once it becomes enforceable in May 2018, the law designed to protect consumer data will have wide-reaching effects that touch companies well beyond the European border.

Organizations anywhere in the world that do business with citizens in the EU will have to comply with the new regulations. For many, especially companies in the United States that have consumers in the EU, GDPR will require making some significant changes in order to comply.

While 10 months may seem like plenty of time for an organization to cross the t’s and dot the i’s, GDPR will present some hurdles as companies attempt to reach a state of compliance—especially as fines of up to four percent of global revenue loom for those who fail to operate under GDPR’s requirements.

Get An Early Start On Compliance

Organizations shouldn’t make the mistake of waiting until the last minute to comply with GDPR. The new regulation doesn’t require just getting a new certification or adding a simple disclosure—it requires companies to fundamentally change how they collect and manage consumer data.

At its core, GDPR is designed to protect personally identifiable information by strengthening and unifying the standards for data storage inside the EU and addressing how data from citizens of the EU can be used by organizations elsewhere.

For American companies that do business in the EU, they will now have to keep those consumers’ information on servers within the EU rather than bringing that data back to servers based in the U.S.

“For every company that sells to a customer in the EU, you now have to set up a different instance or a different hub where your data can be stored that cannot be accessed or shared outside of the EU,” Monica Eaton-Cardone, the founder and chief operating officer of Chargebacks911, told International Business Times.

“This really is presenting a significant challenge for lots of CRM (customer relationship management) companies, individuals in the payment industry and retail merchants,” Eaton-Cardone said.

Get the AI & data signal, daily.

335k+ subscribers read this every morning. One email, both newsletters. Unsubscribe anytime.

It’s not just merchants and sellers who will be subject to the changes. Colleen Huber, director of cyber education strategy at MediaPro, told IBT even organizations that don’t have direct operations or sales in the EU may be subject to GDPR.

“GDPR compliance is required for organizations that provide services or goods to the —even for free,” she said. “With today’s cloud-based technology, organizations of all sizes and across all industries could potentially fall under the scope of the GDPR.”

Eaton-Cardone warned that changes required by the GDPR will likely be burdensome on organizations, as it will require establishing new operational practices for handling data within the EU. That means new protocols for collecting, maintaining and handling that information that will likely have to meet a higher standard than the one currently in place for businesses based in the U.S.

Eaton-Cardone also doesn’t expect that U.S. companies will bring home the practices required to comply with the GDPR, meaning they will have to maintain two separate standards.

“In many ways, a different set of rules acts a barrier, she said. “Now you have two independent organizations operating independently and you end up with more separation….You’re making the two areas more different, not less.”

Given the amount of change companies will have to undergo, there is no time to wait to begin working toward compliance. A recent survey found nearly one in four small businesses in the United Kingdom and 10 percent of companies with more than 500 employees have yet to begin preparing for GDPR.

The figures are likely higher for U.S. businesses that may be unaware they will be affected. It isn’t too soon to start working toward meeting the requirements—especially when waiting may lead to massive fines.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at ibtimes.com →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.