Lepide Blog: A Guide to IT Security, Compliance and IT Operations

GDPR Compliance: Your Questions Answered

GDPR Compliance - Your Questions Answered

GDPR requires all businesses (in and outside European Union) dealing with EU citizen’s data to protect their data and privacy for transactions that occur within EU member states. Non-compliance will result in hefty penalties. The directive will set a new norm for consumer rights but, initially, it will be challenging for companies to put the required systems and processes in place to conform. The compliance will require new expectations from security teams, as it will take a wide view of what constitutes personally identifiable information to protect citizen’s data. This article will attempt to answer some questions you may have about the GDPR.

Why has GDPR been proposed?

There are primarily two reasons why GDPR has been proposed. Firstly, the EU’s data protection legislation is old, having been implemented in 1995. The EU has evolved since then and become more complex. It ensures an individual’s fundamental right to data protection. The problem was that each Member State has their own way of implementing the law; leading to complexity, legal uncertainties and administrative costs.

Secondly, when the current legislation was introduced, many of today’s online services and the associated challenges did not exist. Social networking sites, cloud computing, mobile devices, smart cards and other technologies have led to the growth of personal data. The GDPR is an attempt to update current privacy laws to keep in line with these advances in technology.

How will GDPR change things?

The GDPR reinforces individuals’ rights, strengthens the EU internal market, ensures stronger rule enforcement, streamlines transnational transfers or personal data and sets new global data protection standards.

The new directive will give people more control over their data and make it easier to access it. It will ensure that people’s personal information is protected irrespective of where it is sent, stored or processed – even outside the EU.

What are the benefits to you?

GDPR will strengthen citizens’ rights and build trust. It has following provisions:

How will the “Right to Erasure” work?

Whilst not providing a complete “Right to be Forgotten,” this principle dictates that anyone can ask to erase his or her data if there is no convincing reason for a business to keep it.

The “Right to Erasure” states that in certain conditions, a person can submit a request to the data controller to delete their data. The “right to erasure applies” when:

Is there any protection for minors?

Yes, the directive states that minors’ data should be specifically protected as they cannot be aware of risks, penalties, precautions and the scope of their rights. The regulation expects that consent for processing a child’s data must be given or authorized by the person holding the child’s parental responsibility. The provision aims to protect children from unwillingly sharing personal data without fully realizing its consequences. When it comes to counseling services given directly to a child, parental consent should not be a necessity.

What are benefits and drawbacks of GDPR for businesses?

Benefits of GDPR for businesses:

Drawbacks of GDPR for businesses:

As far as the disadvantages are concerned, initially companies may have to update their policies and business processes, leading to increase in cost for a short period. However, in the long run, the benefits will far outweigh the initial cost.

What effect will GDPR have on Britain after Brexit?

As already mentioned in this article, the GDPR will apply to both EU-based companies and those companies that are outside EU but deal with the data of EU citizens. Even after Brexit, companies in UK will have to comply with the GDPR if they process EU data.

There are two reasons for this. Firstly, there will be an overlapping period between the GDPR coming into effect and the UK exiting the EU. The UK will have to comply with the regulation while it is still a part of the EU. Secondly, the GDPR has extraterritorial reach explained earlier. Hence, UK companies doing business with the EU or processing data of EU citizens will have to comply with the regulation even after leaving.

How can auditing help both businesses and citizens?

As per GDPR, businesses will have to ensure data security and fulfill breach response obligations. Organizations running Active Directory can meet these requirements by auditing Active Directory, File Servers, SQL Servers, SharePoint Servers, Exchange Servers and other similar server components. Proper auditing will not only fulfill organizational responsibility, it will also ensure that subject data is secure and safe from leaks and breaches.

However, the native auditing methods for doing this can be complicated and time-consuming. Collating information from servers spread over the entire network is also a complicated task. Retrieving information through scripts can be difficult, and in many cases systems hang while running scripts if there are GBs of the log.

How can Lepide Data Security Platform help?

Lepide Data Security Platform has numerous predefined audit reports which can help you to meet the IT-related regulations of GDPR. You can easily retrieve the required information by generating one record for every change. You can do advance filtration, sorting, searching, and other functions on the reports. You can schedule these reports to be delivered at predefined intervals via email.