What organizations must do in the six months leading to GDPR

With the General Data Protection Regulation set to take effect in just over six months, businesses in the EU or handling European customer data need to be ready to adhere to stricter data protection guidelines than ever before.
According to a recent survey from McAfee, 25 percent of organizations have been preparing between three and four years for its implementation. That leaves 75 percent of enterprises, IT professionals, and business leaders behind the curve. These organizations need to implement an accelerated timeline to both understand how these new guidelines will impact themselves and their customers, as well as ensure standardized businesses processes, compliant with GDPR, are in place.
To get ahead of that May 25 deadline, here’s a month-by-month roadmap to ensure your team is ready.
By December 2017, a fundamental step for any organization is to identify who will champion compliance efforts. If your core business activities include the regular, systematic monitoring of individuals on a large scale, or the processing of special categories of data, GDPR requires the appointment of a data protection officer (DPO) to monitor, assess, and advise your business on compliance.
Even if your organization doesn’t fall under this category, a voluntary appointment of a data compliancy officer could greatly help your preparation efforts. It’s also important to establish an early relationship with your local data protection authorities (DPAs) responsible for policing GDPR regulations, who can provide additional insight on requirements and how the new policies will specifically impact your organization.
Per the European Commission, personal data includes a broad swath of identifiable data – public, private, or professional – including contact information, medical records, images, even IP addresses. The scope of this personal data is wide, and GDPR places the onus on businesses to centrally document and responsibly manage this information.
Transparency is at the core of this legislation and customers have a host of new rights in their pocket, including:
GDPR is going to hit home for everyone – marketing, support, finance, and legal – not just the IT departments tasked with the bulk of the data management burden.


