Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

GDPR: What are we going to do with your data?

by The Gurus
May 5, 2016
in This Week's Gurus
Share on FacebookShare on Twitter

GDPR: What are we going to do with your data?
Christine Andrews, managing director, DQM GRC 
“Keep Calm and Carry On” seems a fitting theme for the finally-published General Data Protection Regulation (GDPR) – a new European wide legislation which is designed to give individuals greater control over their personal information. However, this is only the case if you’re one of the organisations already valuing customers’ data. Unfortunately, for too long, some organisations have “presumed” consent, worked with “implied” permission, experienced data losses which have taken months to detect and report (remember Sony and Target?) and, in some cases such as TalkTalk, have been unable to properly classify which personal data has been compromised. No CEO wants to look as ill-informed as poor Dido Harding, and customers have an absolute right to expect better.
DQM GRC’s new research, in association with DataIQ, shows the extent to which consumers have become both suspicious and savvy about how companies use their personal details. Awareness of data protection controls is high among consumers, with 84 per cent having seen cookies notices, 76 per cent unsubscribe links in emails and 74 per cent have noticed privacy policies. Yet only half say they notice registration forms and requests for their personal data, which suggests that they overlook the starting point of how an organisation comes into possession of their personal information and subsequently makes use of it.
A significant proportion (49 per cent) are reluctant to share details unless there is a clear justification behind why they should – except if they trust the brand. Equally, consumers expect companies to encrypt their data and use technology that is properly monitored to prevent hacking and the consequent distress that accompanies those events. This is with good reason, as half of those surveyed had experienced some kind of personal data breach (such as a website hack, account hack, or even identity theft).
The research shows that consumer expectations about how their data will be protected align with what regulators endorse, but that this may also prove taxing for organisations; 76.8 per cent expect encryption, 67.5 per cent believe that firewalls should be kept up-to-date and half think that usage will be both limited and monitored. Whilst consumers are perfectly entitled to demand organisations take these steps to ensure their data is protected, implementing these processes may be difficult for the 18.4 per cent of organisations who admitted they will require 12-24 months to make the required changes – cutting the GDPR two-year deadline quite finely.
In some respects, it’s a shame that it’s the headline-grabbing, eye-watering fines of up to 4% of global turnover or €20m plus the requirement to notify customers and the ICO of unencrypted data breaches, that are catching businesses’ attention. However, if this is what it takes to make companies wake up and realise it is not their data, it’s our data that we are entrusting to them for safe keeping, then this is definitely substantial progress. It should certainly help the business case.
So what can organisations do?
Firstly, organisations need to evaluate the personal data they have; categorising the data so they are clear where the personal and sensitive data resides and where other less important data sits in the company. Usually, drafting a data flow map will help businesses to understand the pattern of data through the company, provide clarity on who has “eyes on” the data, what skills these people have and, finally, highlight where the data ends up.
Once organisations understand just what personal data they have, they should then ensure that regular risk assessments are completed in order to understand the degree of threat imposed on the company when processing data. Indeed, the GDPR demands a “risk-based approach” with the development of appropriate controls. This should, in a single stroke, ensure that management recognise the dangers associated with the loss, misuse, theft or any other compromise of customer data.
For organisations that pass data onto third parties, there is often a tendency to presume that they must operate to high standards of data security and protection. However, the GDPR now states that controllers must only engage with processors who can provide “sufficient guarantees”. Basically, as the data owner, you must check they have effective “technical and organisational measures to ensure the security of the processing”.
Subsequently, there is now an essential need for organisations to prepare a breach notification plan in the event that something does actually go wrong. If you’re already clear on what type of personal data you manage (categorisation) and where it is (data flows), then this process will be somewhat easier. However, it’s worth being clear on who will co-ordinate the customer communication, the media response and the remedial activity – and make sure you rehearse this so you are practiced in the actual event; consider it a data breach fire drill.
The benchmark for what organisations should do when they suffer a data loss or breach is set high by consumers – 92 per cent of those surveyed said they expect to always be notified and told exactly what information has been lost or stolen. In addition to this, the research also revealed that consumers would expect a public apology from the company, as well as compensation (57 per cent each).
However, if consumers are demanding to know what personal information has been compromised in a data breach, organisations will need to classify their data assets. Worryingly, only 30.7 per cent have done this for all of their data types and one in five companies resist the idea, with 11.4 per cent saying they would not do it and 9.7 per cent that they would only do so if required by law.
One of the best forms of data protection is to ensure all aspects of the organisation involved in using personal data are equally included in the data governance processes. This ensures all functions operate to a common standard, which is particularly vital in the event of a data breach. It is also important for organisations to try and spot trends in any data problems that occur, and to not just record issues separately. Otherwise there will be a risk that each incident will be seen as unique, rather than having common root causes – which can then be rectified and solve the entire issue.
Additionally, it is vital that organisations consider an engaging staff training programme to ensure all employees are aware of the valuable asset they are dealing with and understand the need to manage data securely. Data security is an important component of building consumer trust and confidence. Finally, all organisations should respect the personal data they have in their possession and treat it like it is their very own – otherwise the new “privacy aware” consumer may decide to take it elsewhere…

ShareTweet
Previous Post

Breaking the Internet of Things

Next Post

Microsoft: Windows Malware Up, Stuxnet Shell Attack Most Popular

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol