On September 7, 2017, Equifax announced a massive breach which seized control of the news the world over. By exploiting a website application vulnerability in Equifax's system, hackers were able to gain access to the personal data of approximately 143 millon consumers in the United States, UK and Canada.. This included names, Social Security numbers, birth dates, addresses, and in some instances, driver's license numbers and credit card numbers.

While this is yet another unwelcomed reminder to individual consumers that they must remain vigilant in their monitoring of unauthorized use of their personal information, for organizations, this may be their wake up call to engage in a review of their security practices and protocols. Had this event occurred under the General Data Protection Regulation (GDPR) (set to take effect May 25, 2018), the implications to the organization would be substantial.

For any organization collecting, processing, storing, or transmitting personal data of EU citizens that has not yet thought about or implemented applicable practices and protocols to comply with the GDPR and respond to security breaches under GDPR requirements, time is running out.