Winter GDPR is Coming

Winter (GDPR) is Coming

You might have heard – winter is coming. And just like winter in Game of Thrones, GDPR is coming.

You might have heard – winter is coming. And just like winter in Game of Thrones, GDPR is coming.  Just as in fiction, people across the world are now realizing that the looming event is coming and they need to prepare.

For those who haven’t yet heard, effective May 2018, the European Union General Data Protection Regulation (GDPR) will enforce enhanced protection of European personal data. This regulation could have significant impact for any organization around the globe that acquires or stores personal data regarding European citizens. GDPR will affect how organizations manage data pertaining to individuals, including customer contacts, consumers, partner contacts, staff and other ‘data subjects.’

But how do you tackle it? The good news is, unlike winter in Game of Thrones, we know when GDPR is coming (May 2018) and for the most part, we know how to tackle it. Of course, it helps to bring in some reinforcements against the White Walkers…I mean penalties for violations, which, for GDPR, can be up to four percent of global revenue.

Game of Thrones has the Starks, Lannisters (well…some of them) and Targaryens to save the day. For GDPR, there are tools to help drive your compliance efforts. Simply put, you need to prepare for what the future holds to stay competitive.

Below are five steps to guide you on your GDPR compliance journey (each step starts off with the same advice I’d give Jon Snow for his journey, too):

  1. Take a holistic approach

It’s important to take a holistic approach across the land. Who are your stakeholders? What is your currency? How do you define and implement the right policies? It’s time to govern your land.

Of course, for GDPR, your land is your entire enterprise and data is the currency. Define your policies, identify your stakeholders, govern your data – specifically in-scope data for GDPR compliance efforts. Assess where you are today, implement policies and measure results. This last part is crucial because documentation is not enough. Implementing and tracking progress are key to helping you succeed.

Effective data governance is the democratization of data for all data users, enabling business and IT functions to work together. So, no matter who you are in the organization – whether you consider yourself a Stark, Lannister, Targaryen or other data user – you need immediate access to this data.  Data is truly a strategic asset across the enterprise. It not only benefits your users, but it also gives you a competitive advantage.

  1. Identify what needs protecting

Identify and assess what needs protecting. Where is it located? What is the risk?

For GDPR, discover and assess your in-scope data across the organization. Personal data discovery and risk analysis are needed across a wide range of technology solutions. You need immediate access to this information to detect your potential risk. This involves monitoring of data movement or use access that might violate GDPR. To sum it up, you should be able to quickly spot, monitor and protect personal data across all data types, including structured and unstructured data, for GDPR compliance efforts.

  1. Prevent unauthorized access

How are you going to prevent those White Walkers from coming over? Have you built the wall? Is that enough?

Personal information is often exposed to many different individuals across an organization and its ecosystem. For GDPR, data masking is one way to address the security challenges raised by this issue to help ensure that data is protected and access is controlled based on your policies. Data masking can help prevent unauthorized access of personal data for production environments (based on role, location, time) and can also be used to pseudonymize data for reporting, analytics and testing. Also, with data archiving, you can purge data in connection with a data subject access request or when otherwise required by law. Bottom line is that you’ll need to build your walls as quickly as needed.

  1. Manage information

What if you want a central view across the land? What if you need a three-eyed raven (aka Bran) to see it all?

Siloed, legacy systems make you feel like you are in a Game of Thrones episode with the raven delivering the data. For GDPR compliance efforts, organizations need to quickly identify all the data they hold about a data subject, regardless of location or system.

Master data management (MDM) is designed to give you a full 360-degree view of personal data so you have immediate access to all business-critical information on a data subject. With this capability and with proper access controls in place, you can then consolidate and manage the various consents and restrictions that apply to a particular data subject’s personal data. 

Also, when a data subject wants to exercise their rights (Subject Access Request, cancellation, etc.), you don’t have to send your dragons across the seven realms to find them. All the data is centrally managed from a single location linked with your applications, so rights can be applied in a consistent, efficient and unsullied way. Data is relevant, timely and trustworthy (don’t depend on data delivered by anyone with the name Littlefinger, please).

  1. Get started today

Time is short. We know it’s coming. We’ve heard about GDPR for several seasons--I mean months.

 

The good news? Actions that help with GDPR compliance efforts also result in good data management. Choose the tools and partners to help in your GDPR compliance journey carefully, with an eye toward the future and scalability. In the end, using your assets wisely and boldly transforming your land (think like Jon Snow) will determine the winners and losers in this game.

Featured

  • Maximizing Your Security Budget This Year

    7 Ways You Can Secure a High-Traffic Commercial Security Gate  

    Your commercial security gate is one of your most powerful tools to keep thieves off your property. Without a security gate, your commercial perimeter security plan is all for nothing. Read Now

  • Mobile Access Adoption

    Smartphones and other mobile devices have had a profound impact on how the world securely accesses the workplace and its services. The growing adoption of mobile wallets and the new generation of users is compounding this effect. Read Now

  • Changing Mindsets

    We have come a long way from the early days of fuzzy analog CCTV systems. During that time, we have had to migrate from analog to digital signals. When IP-based network cameras arrived, they opened a new world of quality and connectivity but also introduced plenty of challenges. Thankfully, network devices today have become smart enough to discover themselves and even self-configure to some degree. While some IT expertise is certainly required, things are much smoother these days. The biggest change is in how fast security cameras and supporting infrastructure are evolving. Read Now

  • Elevating Security

    Willis Tower, an iconic symbol in Chicago for more than 50 years, has undergone significant transformations to become a modern workplace and community hub that delivers the best experiences for its tenants, area residents and visitors. Originally known as Sears Tower, it was renamed Willis Tower after a change in ownership in 2009. Read Now

Featured Cybersecurity

Webinars

New Products

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area. 3

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation. 3

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation. 3