Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Staying one step ahead of GDPR

by The Gurus
August 30, 2016
in This Week's Gurus
Share on FacebookShare on Twitter

The next two years are set to bring about remarkable change. The UK’s future within European borders, the introduction of the universal flu vaccine as well as the substantial increase of data flow into organisations. These are undoubtedly key milestones which are set to affect not only the UK but also the rest of the world.
In 2018 we will see the deadline hit for meeting new regulations around the treatment of personally identifiable information (PII). Along with expected volumes in data growth, this could potentially have significant implications for any business which processes personal data.
The European Parliament passed the final vote on its new General Data Protection Regulation (GDPR) in July this year, aiming to protect personal information in an ever increasing digital world. Although the new laws won’t be enforced for another two years, this is a relatively short time frame considering that businesses will need to assess the new requirements, evaluate existing measures and plan a path in order to reach full compliance.
To help businesses understand the impact of the GDPR on their information management processes and where it fits within the wider regulatory landscape, here are six key steps to ensuring records are GDPR-ready.
Defining GDPR
Aiming to protect digital personal information, the GDPR is by far the largest shake-up of data protection rules so far this century. It includes more than 50 Articles that have far-reaching implications for organisations and their use and storage of personal data. In essence, the legislation protects the right of a European citizen to determine whether, when, how and to whom his or her personal information is revealed and how it can be used.
The Information Commissioners Office advises businesses to start planning their approach to GDPR compliance as early as they can. However, many businesses across Europe remain unaware of how the changes will affect them and the impact they will have.
There are a number of important steps you can take now to help your organisation identify where your PII is stored and understand your obligations towards managing it. Considering the prospect of multi-million Euro fines for non-compliance, can you afford to wait?
Step 1 – Do I have personal data?
In order to decide which parts of the new legislation will apply to your organisation, you must understand what is meant by personal data. The definition of ‘personal data’ in the context of the new regulation is data relating to a ‘data subject’ (a person) who can be directly or indirectly identified on the basis of that data. Such data also includes device identifiers, cookies or IP addresses. This means that, under the GDPR, data controllers within organisations need to be aware of all personal data under their control and able to demonstrate that they understand the potential risks to information, as well as how to mitigate those risks.
Step 2 – Does GDPR affect me?
Next, it is vital to have an understanding of the key terminology included in the GDPR in order to know whether it is relevant to your organisation. Key terms to understand include ‘personal data’, ‘territorial scope’, ‘data subject access requests’, ‘data protection impact assessment (DPIA)’, ‘the right to erasure’, ‘data portability’ and ‘consent’. For further information on these, go to our knowledge centre, or find the glossary of terms on eugdpr.org.
Step 3 – Where is data stored within my organisation?
In order to meet your statutory obligations, you first need to know where personal data is kept. To gain a full picture of your storage, it is advisable to analyse the data stored on corporate systems, employees’ personal devices, offsite archives and filing cabinets, as well as information stored by suppliers, subcontractors and business partners (people who process personal data on your behalf).
Step 4 – Develop a data map and categorise every piece of information
Following this analysis, we recommend creating a data map which provides a 360 degree view of all physical and digital information, including personal data, stored across an organisation. The data map is an important tool to ensure that you can easily locate, assess and monitor all information on a continual basis.
Step 5 – Review and update existing policies
Once you know the location of your information, you need to know what you can do with it and how long you are permitted to keep it. This requires you to ensure that your retention policies are up to date, in accordance with legal, regulatory or contractual obligations so that you are only keeping what you should and that you’re destroying personal data (and all other records) when required in a secure way. 
Step 6 – Remain attentive and responsive
Finally, it is key that the business as a whole is aware of its obligations. Information passes through the hands of employees, contractors and suppliers, therefore all parties must understand and comply with the same retention policies. Just like regulations changing and imposing new obligations on organisations over time, your retention policies should remain dynamic and responsive, adaptable to evolving business and regulatory landscapes.
Organisations across Europe have long been familiar with the need to store personal data according to the latest regulatory requirements. The introduction of the GDPR, however, and associated penalties for non-compliance means that it has now become critical to perform data retention correctly. Failure to do so could result in fines of up to four percent of annual world group turnover or EUR 20 million.
Following these six steps is a helpful starting point in keeping regulators at bay. Failure to act now could cost your organisation dearly in the long run, so it’s critical to avoid rushing to catch up.

ShareTweet
Previous Post

New covert malware uses USB drives to jump airgaps and works on almost every storage device

Next Post

Balancing security and convenience in online commerce

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol