The silver lining of GDPR preparation
The GDPR is coming, and businesses have no choice but to be compliant. While it can be a daunting task, re-evaluating information management to bring privacy issues to the forefront can have many benefits
February 01, 2018 at 09:34 AM
4 minute read
The General Data Protection Regulation (GDPR) comes into effect on 25 May 2018. The GDPR will have a significant effect on the way organisations process personal data. Its introduction is likely to see many businesses – particularly small and medium-sized enterprises – challenged to allocate sufficient time, budget and resources to satisfy the considerable compliance-focused effort required. But opportunity undoubtedly exists for businesses to alter their strategic view of the importance of data and take steps to manage their information effectively, putting privacy at the forefront of their information management activities.
Increased knowledge, reduced risk
The GDPR contains a number of requirements that will force businesses to acquire a greater appreciation of what they do with the personal data they hold. For example, it requires that organisations record what personal data they have, where it comes from, who it's shared with and what they do with it. It further requires them to conduct information audits to map data flows and maintain records of the legal bases of processing.
The days of ineffective or inoperative retention policies and the 'save everything' approach to data collection and storage are ending, to be replaced by greater corporate accountability and transparency. More than ever before, organisations will acquire insight into what they do with personal data which will, in turn, inform their future data strategy, helping them implement policy to prevent unfair, unlawful or opaque practices. Though introducing systems and processes to enable this level of organisational self-awareness may seem overwhelming at the outset, the benefits of this process in helping businesses to identify, report and manage risk are clear.
Increased consumer confidence
Consumer confidence in businesses' ability to safeguard personal data has fallen, following a series of high-profile data breaches in the last few years. The Cyber Security Breaches Survey 2017, an annual report published by the UK's Department of Culture, Media and Sport, states that almost 70% of large UK firms have suffered a cyberattack. The survey also found that businesses holding electronic personal data were much more likely to suffer cyber breaches than those that do not (51% compared to 37%).
Against this background of mistrust, the GDPR introduces a series of enhanced data security rules intended to force businesses to implement rigorous data security controls, while also giving enhanced control of personal data back to the individual. If businesses adopt data-centric, stringent approaches to data security, they are likely to benefit from reduced organisational risk and increased levels of trust – and revenue – among current and potential customers.
Increased innovation
The GDPR requires that organisations must introduce and maintain "appropriate technical and organisational measures" to protect personal data. It does not, however, define exactly what steps they must take to achieve this. In the absence of detailed guidance, the GDPR will be a catalyst for innovation, forcing organisations to inject privacy by design into existing and new processes and technologies.
There are real opportunities to gain commercial advantage by transforming the way personal data is managed. By assembling cross-functional teams including data protection officers, legal and technical data experts, many organisations will take the opportunity to define their data strategy and policies and find creative, evolving ways to implement data security measures which help them comply with GDPR amid the complex, ever-changing digital economy.
A look ahead
The GDPR will force many organisations to implement new policies and procedures to protect data by May 2018 in order to be compliant. However, this cannot be a one-time event as more and more new types of data will continue to be generated year after year. Devices that store and transmit data are growing each day, with new products constantly being released to market. The privacy implications are huge, as many do not realise that data, such as location data, is collected and stored. Companies are going to have to consistently monitor and communicate their privacy warnings so consumers understand what data is collected, where it resides and how it is going to be used. To do that, companies will need to continuously review their data protection procedures, how they use automatically collected data and address how to safeguard personal data. Becoming GDPR-compliant will be a sprint, but continuing to comply will be a marathon.
Deborah Blaxell is a senior consultant and Martin Bonney is a senior director in the consulting services team at Epiq.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllSponsored post: find out about the latest legal technology trends at ndElevate EMEA
GDPR three months on: what have we learned since the new data privacy rules took effect?
A crisis hits: strategies for GCs to manage what happens next...
Innovation driven by a different perspective leads to a whole new way of working with clients: advertising feature
Trending Stories
Who Got The Work
Michael G. Bongiorno, Andrew Scott Dulberg and Elizabeth E. Driscoll from Wilmer Cutler Pickering Hale and Dorr have stepped in to represent Symbotic Inc., an A.I.-enabled technology platform that focuses on increasing supply chain efficiency, and other defendants in a pending shareholder derivative lawsuit. The case, filed Oct. 2 in Massachusetts District Court by the Brown Law Firm on behalf of Stephen Austen, accuses certain officers and directors of misleading investors in regard to Symbotic's potential for margin growth by failing to disclose that the company was not equipped to timely deploy its systems or manage expenses through project delays. The case, assigned to U.S. District Judge Nathaniel M. Gorton, is 1:24-cv-12522, Austen v. Cohen et al.
Who Got The Work
Edmund Polubinski and Marie Killmond of Davis Polk & Wardwell have entered appearances for data platform software development company MongoDB and other defendants in a pending shareholder derivative lawsuit. The action, filed Oct. 7 in New York Southern District Court by the Brown Law Firm, accuses the company's directors and/or officers of falsely expressing confidence in the company’s restructuring of its sales incentive plan and downplaying the severity of decreases in its upfront commitments. The case is 1:24-cv-07594, Roy v. Ittycheria et al.
Who Got The Work
Amy O. Bruchs and Kurt F. Ellison of Michael Best & Friedrich have entered appearances for Epic Systems Corp. in a pending employment discrimination lawsuit. The suit was filed Sept. 7 in Wisconsin Western District Court by Levine Eisberner LLC and Siri & Glimstad on behalf of a project manager who claims that he was wrongfully terminated after applying for a religious exemption to the defendant's COVID-19 vaccine mandate. The case, assigned to U.S. Magistrate Judge Anita Marie Boor, is 3:24-cv-00630, Secker, Nathan v. Epic Systems Corporation.
Who Got The Work
David X. Sullivan, Thomas J. Finn and Gregory A. Hall from McCarter & English have entered appearances for Sunrun Installation Services in a pending civil rights lawsuit. The complaint was filed Sept. 4 in Connecticut District Court by attorney Robert M. Berke on behalf of former employee George Edward Steins, who was arrested and charged with employing an unregistered home improvement salesperson. The complaint alleges that had Sunrun informed the Connecticut Department of Consumer Protection that the plaintiff's employment had ended in 2017 and that he no longer held Sunrun's home improvement contractor license, he would not have been hit with charges, which were dismissed in May 2024. The case, assigned to U.S. District Judge Jeffrey A. Meyer, is 3:24-cv-01423, Steins v. Sunrun, Inc. et al.
Who Got The Work
Greenberg Traurig shareholder Joshua L. Raskin has entered an appearance for boohoo.com UK Ltd. in a pending patent infringement lawsuit. The suit, filed Sept. 3 in Texas Eastern District Court by Rozier Hardt McDonough on behalf of Alto Dynamics, asserts five patents related to an online shopping platform. The case, assigned to U.S. District Judge Rodney Gilstrap, is 2:24-cv-00719, Alto Dynamics, LLC v. boohoo.com UK Limited.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250