Winter GDPR is Coming

Winter (GDPR) is Coming

You might have heard – winter is coming. And just like winter in Game of Thrones, GDPR is coming.

You might have heard – winter is coming. And just like winter in Game of Thrones, GDPR is coming.  Just as in fiction, people across the world are now realizing that the looming event is coming and they need to prepare.

For those who haven’t yet heard, effective May 2018, the European Union General Data Protection Regulation (GDPR) will enforce enhanced protection of European personal data. This regulation could have significant impact for any organization around the globe that acquires or stores personal data regarding European citizens. GDPR will affect how organizations manage data pertaining to individuals, including customer contacts, consumers, partner contacts, staff and other ‘data subjects.’

But how do you tackle it? The good news is, unlike winter in Game of Thrones, we know when GDPR is coming (May 2018) and for the most part, we know how to tackle it. Of course, it helps to bring in some reinforcements against the White Walkers…I mean penalties for violations, which, for GDPR, can be up to four percent of global revenue.

Game of Thrones has the Starks, Lannisters (well…some of them) and Targaryens to save the day. For GDPR, there are tools to help drive your compliance efforts. Simply put, you need to prepare for what the future holds to stay competitive.

Below are five steps to guide you on your GDPR compliance journey (each step starts off with the same advice I’d give Jon Snow for his journey, too):

  1. Take a holistic approach

It’s important to take a holistic approach across the land. Who are your stakeholders? What is your currency? How do you define and implement the right policies? It’s time to govern your land.

Of course, for GDPR, your land is your entire enterprise and data is the currency. Define your policies, identify your stakeholders, govern your data – specifically in-scope data for GDPR compliance efforts. Assess where you are today, implement policies and measure results. This last part is crucial because documentation is not enough. Implementing and tracking progress are key to helping you succeed.

Effective data governance is the democratization of data for all data users, enabling business and IT functions to work together. So, no matter who you are in the organization – whether you consider yourself a Stark, Lannister, Targaryen or other data user – you need immediate access to this data.  Data is truly a strategic asset across the enterprise. It not only benefits your users, but it also gives you a competitive advantage.

  1. Identify what needs protecting

Identify and assess what needs protecting. Where is it located? What is the risk?

For GDPR, discover and assess your in-scope data across the organization. Personal data discovery and risk analysis are needed across a wide range of technology solutions. You need immediate access to this information to detect your potential risk. This involves monitoring of data movement or use access that might violate GDPR. To sum it up, you should be able to quickly spot, monitor and protect personal data across all data types, including structured and unstructured data, for GDPR compliance efforts.

  1. Prevent unauthorized access

How are you going to prevent those White Walkers from coming over? Have you built the wall? Is that enough?

Personal information is often exposed to many different individuals across an organization and its ecosystem. For GDPR, data masking is one way to address the security challenges raised by this issue to help ensure that data is protected and access is controlled based on your policies. Data masking can help prevent unauthorized access of personal data for production environments (based on role, location, time) and can also be used to pseudonymize data for reporting, analytics and testing. Also, with data archiving, you can purge data in connection with a data subject access request or when otherwise required by law. Bottom line is that you’ll need to build your walls as quickly as needed.

  1. Manage information

What if you want a central view across the land? What if you need a three-eyed raven (aka Bran) to see it all?

Siloed, legacy systems make you feel like you are in a Game of Thrones episode with the raven delivering the data. For GDPR compliance efforts, organizations need to quickly identify all the data they hold about a data subject, regardless of location or system.

Master data management (MDM) is designed to give you a full 360-degree view of personal data so you have immediate access to all business-critical information on a data subject. With this capability and with proper access controls in place, you can then consolidate and manage the various consents and restrictions that apply to a particular data subject’s personal data. 

Also, when a data subject wants to exercise their rights (Subject Access Request, cancellation, etc.), you don’t have to send your dragons across the seven realms to find them. All the data is centrally managed from a single location linked with your applications, so rights can be applied in a consistent, efficient and unsullied way. Data is relevant, timely and trustworthy (don’t depend on data delivered by anyone with the name Littlefinger, please).

  1. Get started today

Time is short. We know it’s coming. We’ve heard about GDPR for several seasons--I mean months.

 

The good news? Actions that help with GDPR compliance efforts also result in good data management. Choose the tools and partners to help in your GDPR compliance journey carefully, with an eye toward the future and scalability. In the end, using your assets wisely and boldly transforming your land (think like Jon Snow) will determine the winners and losers in this game.

Featured

  • 5 Tips to Improve Your Password Security

    Change Your Password Day is right around the corner. Observed every year on February 1, the day aims to raise awareness about cybersecurity and underscores the importance of keeping passwords strong and up to date. Read Now

  • Enhancing Port Security

    DP World Yarimca, one of the largest container terminals of the Gulf of İzmit and Turkey, is a strong proponent of using industry-leading technology to deliver unrivaled value to its customers and partners. As the port is growing, DP World Yarimca needs to continue to provide uninterrupted operations and a high level of security.To address these challenges, DP World Yarimca has embraced innovative technological products, including FLIR's comprehensive portfolio of security monitoring solutions. Read Now

  • Hot AI Chatbot DeepSeek Comes Loaded With Privacy, Data Security Concerns

    In the artificial intelligence race powered by American companies like OpenAI and Google, a new Chinese rival is upending the market—even with the possible privacy and data security issues. Read Now

  • Survey: CISOs Increasing Budgets for Crisis Simulations in 2025

    Today, Cyber Performance Center, Hack The Box, released new data showcasing the perspectives of Chief Information Security Officers (CISOs) towards cyber preparedness in 2025. In the aftermath of 2024’s high-profile cybersecurity incidents, including NHS, CrowdStrike, TfL, 23andMe, and Cencora, CISOs are reassessing their organization’s readiness to manage a potential “chaos” of a full-scale cyber crisis. Read Now

New Products

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge.

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.