Winter GDPR is Coming

Winter (GDPR) is Coming

You might have heard – winter is coming. And just like winter in Game of Thrones, GDPR is coming.

You might have heard – winter is coming. And just like winter in Game of Thrones, GDPR is coming.  Just as in fiction, people across the world are now realizing that the looming event is coming and they need to prepare.

For those who haven’t yet heard, effective May 2018, the European Union General Data Protection Regulation (GDPR) will enforce enhanced protection of European personal data. This regulation could have significant impact for any organization around the globe that acquires or stores personal data regarding European citizens. GDPR will affect how organizations manage data pertaining to individuals, including customer contacts, consumers, partner contacts, staff and other ‘data subjects.’

But how do you tackle it? The good news is, unlike winter in Game of Thrones, we know when GDPR is coming (May 2018) and for the most part, we know how to tackle it. Of course, it helps to bring in some reinforcements against the White Walkers…I mean penalties for violations, which, for GDPR, can be up to four percent of global revenue.

Game of Thrones has the Starks, Lannisters (well…some of them) and Targaryens to save the day. For GDPR, there are tools to help drive your compliance efforts. Simply put, you need to prepare for what the future holds to stay competitive.

Below are five steps to guide you on your GDPR compliance journey (each step starts off with the same advice I’d give Jon Snow for his journey, too):

  1. Take a holistic approach

It’s important to take a holistic approach across the land. Who are your stakeholders? What is your currency? How do you define and implement the right policies? It’s time to govern your land.

Of course, for GDPR, your land is your entire enterprise and data is the currency. Define your policies, identify your stakeholders, govern your data – specifically in-scope data for GDPR compliance efforts. Assess where you are today, implement policies and measure results. This last part is crucial because documentation is not enough. Implementing and tracking progress are key to helping you succeed.

Effective data governance is the democratization of data for all data users, enabling business and IT functions to work together. So, no matter who you are in the organization – whether you consider yourself a Stark, Lannister, Targaryen or other data user – you need immediate access to this data.  Data is truly a strategic asset across the enterprise. It not only benefits your users, but it also gives you a competitive advantage.

  1. Identify what needs protecting

Identify and assess what needs protecting. Where is it located? What is the risk?

For GDPR, discover and assess your in-scope data across the organization. Personal data discovery and risk analysis are needed across a wide range of technology solutions. You need immediate access to this information to detect your potential risk. This involves monitoring of data movement or use access that might violate GDPR. To sum it up, you should be able to quickly spot, monitor and protect personal data across all data types, including structured and unstructured data, for GDPR compliance efforts.

  1. Prevent unauthorized access

How are you going to prevent those White Walkers from coming over? Have you built the wall? Is that enough?

Personal information is often exposed to many different individuals across an organization and its ecosystem. For GDPR, data masking is one way to address the security challenges raised by this issue to help ensure that data is protected and access is controlled based on your policies. Data masking can help prevent unauthorized access of personal data for production environments (based on role, location, time) and can also be used to pseudonymize data for reporting, analytics and testing. Also, with data archiving, you can purge data in connection with a data subject access request or when otherwise required by law. Bottom line is that you’ll need to build your walls as quickly as needed.

  1. Manage information

What if you want a central view across the land? What if you need a three-eyed raven (aka Bran) to see it all?

Siloed, legacy systems make you feel like you are in a Game of Thrones episode with the raven delivering the data. For GDPR compliance efforts, organizations need to quickly identify all the data they hold about a data subject, regardless of location or system.

Master data management (MDM) is designed to give you a full 360-degree view of personal data so you have immediate access to all business-critical information on a data subject. With this capability and with proper access controls in place, you can then consolidate and manage the various consents and restrictions that apply to a particular data subject’s personal data. 

Also, when a data subject wants to exercise their rights (Subject Access Request, cancellation, etc.), you don’t have to send your dragons across the seven realms to find them. All the data is centrally managed from a single location linked with your applications, so rights can be applied in a consistent, efficient and unsullied way. Data is relevant, timely and trustworthy (don’t depend on data delivered by anyone with the name Littlefinger, please).

  1. Get started today

Time is short. We know it’s coming. We’ve heard about GDPR for several seasons--I mean months.

 

The good news? Actions that help with GDPR compliance efforts also result in good data management. Choose the tools and partners to help in your GDPR compliance journey carefully, with an eye toward the future and scalability. In the end, using your assets wisely and boldly transforming your land (think like Jon Snow) will determine the winners and losers in this game.

Featured

  • New Report Reveals Top Trends Transforming Access Controller Technology

    Mercury Security, a provider in access control hardware and open platform solutions, has published its Trends in Access Controllers Report, based on a survey of over 450 security professionals across North America and Europe. The findings highlight the controller’s vital role in a physical access control system (PACS), where the device not only enforces access policies but also connects with readers to verify user credentials—ranging from ID badges to biometrics and mobile identities. With 72% of respondents identifying the controller as a critical or important factor in PACS design, the report underscores how the choice of controller platform has become a strategic decision for today’s security leaders. Read Now

  • Overwhelming Majority of CISOs Anticipate Surge in Cyber Attacks Over the Next Three Years

    An overwhelming 98% of chief information security officers (CISOs) expect a surge in cyber attacks over the next three years as organizations face an increasingly complex and artificial intelligence (AI)-driven digital threat landscape. This is according to new research conducted among 300 CISOs, chief information officers (CIOs), and senior IT professionals by CSC1, the leading provider of enterprise-class domain and domain name system (DNS) security. Read Now

  • ASIS International Introduces New ANSI-Approved Investigations Standard

    • Guard Services
  • Cloud Security Alliance Brings AI-Assisted Auditing to Cloud Computing

    The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment, today introduced an innovative addition to its suite of Security, Trust, Assurance and Risk (STAR) Registry assessments with the launch of Valid-AI-ted, an AI-powered, automated validation system. The new tool provides an automated quality check of assurance information of STAR Level 1 self-assessments using state-of-the-art LLM technology. Read Now

  • Report: Nearly 1 in 5 Healthcare Leaders Say Cyberattacks Have Impacted Patient Care

    Omega Systems, a provider of managed IT and security services, today released new research that reveals the growing impact of cybersecurity challenges on leading healthcare organizations and patient safety. According to the 2025 Healthcare IT Landscape Report, 19% of healthcare leaders say a cyberattack has already disrupted patient care, and more than half (52%) believe a fatal cyber-related incident is inevitable within the next five years. Read Now

New Products

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge.

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.