No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Data Privacy

Countdown to the GDPR

by Kevin Gibson
February 14, 2018
in Data Privacy, Featured
green sand passing through an hourglass

What Compliance Should Be Doing Now

CCI has covered the General Data Protection Regulation (GDPR) extensively, and by now most readers may know that the deadline for GDPR compliance is barreling toward us. Kevin Gibson walks us through what businesses must do to prepare.

May 25, 2018, the day on which the General Data Protection Regulation (GDPR) takes effect, is fast approaching. Some firms have been proactively working toward GDPR compliance, which is wise given that failure to do so exposes organizations to fines of up to €20 million (US $23.5 million) or 4 percent of global revenue — whichever is higher. However, it appears that a majority of firms whose business requires them to comply with GDPR have yet to do so and are instead waiting to take action until just before the deadline or worse, after it passes. Such procrastination is ill advised. The GDPR compliance countdown, as outlined here, should start now.

4… Get motivated by understanding the consequences of waiting to address GDPR preparations.

The GDPR is designed to safeguard the privacy and security of personally identifiable information (PII) belonging to citizens of the European Union (EU). If previous efforts to enforce regulations are any indication, European authorities will immediately impose penalties on any company that is found to be in violation of the new rule. Pandemonium will ensue when this occurs, with a long queue of other EU citizens initiating their own attempts to recover damages for noncompliance.

The longer this queue becomes, the greater the number of organizations that will simultaneously scramble for resources to assist them in navigating the road to GDPR compliance and overcoming any obstacles they encounter. As more companies reach out for these resources, organizations’ difficulty in engaging the right services will increase. Additionally, as the shortage of competent GDPR-compliance resources increases in scope, so too will the price of their services.

3… Develop a GDPR compliance plan.

The GDPR clearly specifies how organizations that maintain and/or process PII must handle that data. This includes everything from requirements for storing and safeguarding the security of customer and employee PII to responding to requests that PII be deleted from companies’ records. It also encompasses documenting and furnishing proof that companies have followed through on requests for PII deletion and that the data no longer resides on a particular system or system. And that is just the beginning.

Companies must formulate a plan stipulating their intended method of satisfying all requirements set down under the GDPR. For instance, what measures will they take to ensure that customers’ PII is never exposed on their website? How will they respond to employee requests for PII erasure? How will they know where particular data resides? Who will be accountable for ensuring that PII that should not be exposed is not exposed? Who will be responsible for GDPR compliance as a whole? Without such a plan, organizations will find themselves frantically improvising as they go along — and quite possibly, making decisions or taking actions that could have financial or other repercussions.

2… Locate and engage appropriate resources.

Small organizations (i.e., those with just a few individuals on their payroll and a limited number of EU citizens on their customer roster) will likely not require as much assistance in attaining GDPR compliance as their larger counterparts.  However, as stated above, all companies will need some help with GDPR preparations, whether in implementing the proper tools and utilities for identifying, controlling, analyzing and acting on web, social and collaborative content or in deploying technology that performs audit trails around GDPR compliance.

No matter their size, companies should, when choosing from among resources, limit their selection to those whose capabilities support all aspects of GDPR compliance. Organizations with multiple data repositories and operations in various geographic locations should be certain to engage only those resources that can provide a solution for finding the same data in more than one system, so that if it must be erased, it is erased from all systems rather than just one. All companies should also ensure that their resources offer tools that make the whereabouts of all data in the PII category — structured data, unstructured data and web data — easily evident, whether it resides in an ERP or corporate system, on a web platform or even in employee-owned software.

1… Assess compliance levels.

By early May, at the very latest, companies should be at a stage where they are performing dummy tests to assess their degree of GDPR compliance and making any necessary adjustments before the rush. Such assessments should look at the process of responding to different GDPR-related requests — for example, an employee’s request to be furnished with information about what the organization does with his PII or for that data to be expunged from the company’s records. Also worth including are spot checks of various data repositories to make certain that PII is not exposed and accessible when it should have been placed behind a firewall.

Blastoff.

Admittedly, not all companies will be entirely positioned for GDPR by the coming deadline in May. However, the closer to the countdown they can come, the smoother the sailing for all parties concerned.


Tags: GDPRPersonally Identifiable Information (PII)
Previous Post

IHS Markit Adds Corruption, Money Laundering and Sanctions Screening to Vendor Due Diligence Service

Next Post

Effectiveness Beyond the Compliance Program

Kevin Gibson

Kevin Gibson

Kevin Gibson is CEO & Chairman of Hanzo. Hanzo provides legally defensible collection, preservation and analysis of web and social media content for Global 2000 companies in the cloud, on premise or on demand.

Related Posts

origami tiger

Paper Tigers Won’t Protect You: The Reality of Effective NIS2 Compliance

by Hans Kayaert
March 24, 2025

Why Belgium's early adoption model could prevent another round of ‘compliance theater’ across Europe

examining data on laptop screen

Privacy Rights Surge Forces Rethink of Data Management

by Gal Ringel
March 14, 2025

As global privacy regulations multiply, organizations face mounting pressure to efficiently respond to data subject requests amid complex data environments

gdpr website screenshot

In the World of JavaScript, GDPR Consent Forms Merely Scratching the Surface

by Rui Ribeiro
December 16, 2024

Consent forms alone don’t mean much when consumers are so tired of checking boxes they don’t even read the policies

us map black and white

Minnesota Latest State to OK Consumer Data Privacy Law

by Amanda Novak
August 26, 2024

Measure set to go into effect for most covered entities next summer

Next Post
behavior recognition technology on three women

Effectiveness Beyond the Compliance Program

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights