GDPR considerations when implementing software usage analytics

3 min read

In just a few weeks, sweeping changes intended to better protect the private information of European citizens go into effect. With the networked, global nature of our economy, the General Data Protection Act is likely to touch even the smallest businesses.

As that May 25, 2018 deadline for compliance inches closer, there isn’t a compliance officer on the planet who isn’t consumed with making sure every asset that stores, processes or leverages personal data is covered. Fines for noncompliance are steep.

Organizations can be fined up to 4 percent of their annual revenue, or 20 million euros (approximately $24 million), whichever is greater, (source). And should a breach occur, the expectations for transparency are high and broadly reaching – the regulations require notification to each of the country’s representatives within 72 hours of a breach (source).

With a usage intelligence solution, you may wonder how to ensure compliance if an external intermediary processes or stores the personal data covered under GDPR. Companies that run technology that are subject to the regulation should keep the following in mind.

While not legal counsel, these guidelines should be considered by companies that have clients of usage and intelligence software.

Under GDPR, the “data controller,” is responsible for ensuring that the principles and requirements in the regulations are met – such as collecting and managing consent. But when a third party – like a software usage and compliance analytics vendor — processes or stores the data, it can be confusing as to who is actually the data controller. Let’s clarify the roles as they are defined in the new regulations.

Under the regulations, the controller is the one who “determines the purposes and means of processing of personal data” (source). The data processer is the one who processes the data on behalf of the controller. In short, the “data controller” is your company, and the “data processor” is the third party software vendor you’re working with. The “data subject” is the end user – the individual you’re collecting information about.

This means, if you’ve implemented usage or compliance intelligence software, that vendor is the data processor. Even though the vendor stores, works with, and augments information on your behalf, you are the data controller. The vendor may only process a data subject’s personal information based on your direction. In short, as data controller, you are accountable under GDPR to assure that the principles are met.

What does that mean? Simply stated, it is the obligation of the data controller to confirm that the requirements of GDPR have been met by your usage and compliance intelligence vendor and they should have at the ready a summary of its real-time GDPR status in the event of an inquiry.

There are several approaches that can be used to lawfully process personal information under GDPR. One of them is obtaining consent from the data subject.

Currently, many organizations obtain consent by an end user accepting an End User License Agreement (EULA). But under GDPR, the bar is much higher.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at information-management.com →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.