Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

What do you need to know about GDPR

by The Gurus
April 4, 2017
in This Week's Gurus
Share on FacebookShare on Twitter

Over the last few months there has been a proliferation of articles concerning the General data Protection Regulation (GDPR). Most have echoed similar points however despite this it was interesting to see in a report published by Symantec that 96% of companies still do not understand the GDPR, and it would seem that the deluge of content is not causing any changes on that ground.
So here at RiverSafe we have put together our thoughts on what businesses really need to know about GDPR.
What is the GDPR?
For those who dont know, since the mid-1990’s, legislation that protects the information privacy of individuals in the European Union (EU) has been primarily based on the EU Data Protection Directive, which sets out the minimum standards on data protection in Europe. Each country within the EU has taken this directive and transposed it into their own, local data protection laws, and here in the UK we have the Data Protection Act 1998
The directive was deemed outdated and has not changed since 1995. Four years in the making, GDPR is the new EU legislation that will come into effect from May 2018. The UK, despite of Brexit, will be adopting the law.
Below is a brief summary of the changes we feel will have most impact.
Data portability
The GDPR strengthens the rights that individuals have to control their own data, in particular the right to data portability. This means an individual has the right to transport his/her personal data from one organisation to the next. The personal data must be provided to the individual in a structured, commonly used and machine-readable format. The impact of this rule could be signifcant. For example, what does it mean commercially when your client can ask for a copy of all their personal data and takes this to your competitor? But also technically it may be a challenge.
Data breach notification
Every organisation that processes personal data needs to make sure that this data is properly safeguarded against loss, theft, unauthorised access, etc. Security of the personal data is so important that the GDPR includes a personal data breach notification rule. This says that when a breach of security occurs, this breach should be reported within 72 hours and if it is likely to result in a high privacy risk for individuals, than these individuals must be informed.
Inventory
The obligation to notify local authorities of personal data being processed has gone. However, in its place organisations must now maintain a record of processing activities under its responsibility so they must keep an inventory of all personal data processed.
Data protection by design and by default
Data protection by design and by default are both included in the GDPR. This means two things. First, it will be mandatory when designing a new system, process, service, etc. that processes personal data, to make sure that data protection considerations are taken into account. Moreover, organisations need to be able to prove that they have done so. Second, the new system, process, service, etc must include choices for the individual on how much personal data they wish to share.
Expanded territorial scope
Organisations that target EU residents via the internet with services, goods or for monitoring, have to be compliant with EU rules on privacy of those residents’ data.
Processors
If you process personal data on behalf of another organisation, the GDPR has a significant change for you. Where so far all the burden of compliance with privacy legislation was on your client, now you have some obligations directly yourself.
Right to be forgotten
The right to erasure of personal data already exists in the current Directive but is now elevated in the GDPR. Under the new regulation all organisations that process personal data must remove all of that data if one condition (out of a list of six) is met.
PIAs
The GDPR introduces Data Protection Impact Assessments (DPIA) as a means to identify high risks to the privacy rights of individuals when processing their personal data. When these are identified, the GDPR expects that an organisation formulates measures to address these risks.
Security
The need to take proper information security measures to ensure the confidentiality, integrity, availability and resilience of processing systems and services has always been a part of privacy legislation. New is that the GDPR champions pseudonymisation and encryption of personal data: Furthermore it is stressed that security should be based on a risk assessment, however not of the risks the organisation faces, but the risks impacting individuals.
Accountability and data governance
Data protection legislation in the EU has always been based on a number of principles that need to be adhered to. Lawfulness, fairness, purpose limitation and transparency are good examples. The GDPR introduces a new principle: accountability. Organisations will not only be responsible for adhering to all the principles, they also must be able to demonstrate compliance with them.
Sanction
One of the most discussed aspect of the GDPR must be its explicit mentioning of fines. For example, for less serious violations, the maximum is € 10 million or 2% of total annual worldwide turnover of the preceding year (whichever is higher); for more serious violations this goes up to
€20 million or 4%.
One stop shop
For organisations that operate across the EU, a sort of ‘one stop shop’ system for supervisory authorities in Europe will be introduced. The Lead Supervisory Authority will be the primary authority organisations need to deal with, but under circumstances local authorities can step in as well.
Approved certification mechanism
The legislators have acknowledged that for many organisations being able to proof that they adhere to the GDPR will be an advantage. For that purpose data protection certification mechanisms and data protection seals and marks are being introduced.
Local deviations
Local governments have been given the ability to add or adapt provisions to fit their local data protection needs. Views on how much individuals’ personal data should be protected and from whom are deeply rooted in local culture and it is expected that that many governments will make provisions for this.
Next steps for any organisations now that the final text of the GDPR is known is to identify how this new legislation may impact them. This will of course vary per organisation, but in general terms, privacy consists of making sure you address not only the legal aspects but all the other aspects highlighted above.
By Kumar Sumeet, Principal Security Consultant, RiverSafe

Tags: CybersecurityTechnology
ShareTweet
Previous Post

Brits spend 120 hours a year on smartphones whilst at work

Next Post

World Back-up Day – How businesses must adopt greater strategic back-up flexibility

Recent News

Frontline Workers Twice as Likely to Use Unapproved AI

Frontline Workers Twice as Likely to Use Unapproved AI

June 4, 2026
Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol