• Contact Us
  • Login
Upgrade
Tech News Hero
Advertisement
  • Home
  • News
  • Gadgets
  • Social
  • Gaming
  • Mobile
  • PC
  • Internet
  • Security
  • Apps
No Result
View All Result
  • Home
  • News
  • Gadgets
  • Social
  • Gaming
  • Mobile
  • PC
  • Internet
  • Security
  • Apps
No Result
View All Result
Tech News Hero
No Result
View All Result
Home Security

Guess what? GDPR enforcement is on fire!

by technewshero
February 3, 2020
in Security
0
Share on FacebookShare on Twitter



admin


February 3, 2020
Security


28 Views

Why only one in three organizations are GDPR compliant — and the risks they’re facing as a result
ZDNet’s Danny Palmer tells Karen Roby that over a year after coming into force, these three things are still causing trouble for organizations. Read more: https://zd.net/2nxbLDO

You read that right: GDPR enforcement is on fire! While fines are not always particularly high, our analysis shows that, in terms of volume, data protection authorities (DPAs) are rapidly increasing their GDPR enforcement activities. Some interesting trends are also emerging:

  • DPAs have levied 190 fines and penalties to date. With 43 enforcement decisions made so far, Spain leads the pack as Europe’s most active regulator, followed by Romania (21) and Germany (18). The UK has imposed the highest total amount of fines — more than €315 million — if both British Airways’ and Marriott’s fines are upheld after appeal. Following are France’s Commission Nationale de l’Informatique et des Libertés, with just over €51 million in fines, and Germany’s DPA, at nearly €25 million.
  • Failures of data governance — not security — trigger the most fines and penalties. DPAs have primarily acted against the infringement of Article 5 (principles of processing of personal data) and Article 6 (lawfulness of processing). These rules contain key data governance principles, such as data accuracy and quality, and fairness of processing, when firms collect and process the minimum amount of data necessary for a specific, clearly defined purpose. Firms struggle greatly to meet the requirements around consent and other available legal bases.
  • Breaches get the enforcement ball rolling but are just a starting point. Many security and risk (S&R) and privacy pros expected security infringements and missed breach notifications to be the main triggers of GDPR enforcement. DPAs have undertaken about 50 actions for infringement of article 32 (security requirements) and a few more related to failure to report breaches. These cases show that an actual security incident is just the starting point for determining fines. Investigations that followed some of the biggest breaches of the post-GDPR era focused not only on the specific conditions of the breach but also highlighted “poor security arrangements.” Adequate authentication procedures — or the lack thereof — have been DPAs’ focus since the first enforcement action in 2018.
  • Compromised data from a single customer can be expensive. DPAs evaluate the impact of a breach, not just its volume. For example, Spain’s data protection regulator fined two telco providers, each of which had an issue with a single customer. One telco erroneously disclosed credentials of a third party to a customer, allowing the customer to gain access to sensitive third-party data. This single event cost the provider €60,000. The DPA fined another telco provider almost €40,000 for processing the data of a single customer without their consent. A hospital in Germany was also fined €105,000 for GDPR violations associated with the misuse of data of a single patient.
  • Failure to respect individuals’ rights will lead to the next wave of fines and penalties. Forrester expects the next enforcement wave to come from failing to address individuals’ privacy rights. Most current enforcement actions refer to data access requests and data deletion. For example, a German property company that — among other issues — archived customer data in a way that didn’t allow for data deletion was fined €14.5 million. Enforcement to date has primarily come from customer requests, but enforcement actions from employee requests are also increasing. Bulgaria’s Commission for Personal Data Protection fined an employer for a delayed and incomplete response to an employee’s access request.
  • Third-party risk management is the next big thing in the privacy arena. Third-party risk management is nothing new to S&R and privacy pros, but they’re only now starting to see how third parties affect their privacy program. Third parties that don’t follow the same privacy policies you do can destroy not only your privacy program but also your brand, your customers’ trust, and your partner ecosystem. From vendors to subcontractors to data suppliers to the partners you share data with, it’s evident that third-party risk has far-reaching implications for privacy. Current due diligence practices are not going to cut it. Don’t be caught off guard. Instead, look for ways to blend technology, cross-functional knowledge and data, and external insights with your S&R peers to automate third-party management for privacy.

This post was written by Senior Analyst Enza Iannopollo, and it originally appeared here. 

Source link


2020-02-03


Check Also



Most of us are so used to the apps we rely on, it’s easy to …

Previous Post

The 5 best ever Super Bowl halftime shows

Next Post

PhonePe Introduces Chat Feature on Android, iOS

technewshero

technewshero

Related Posts

2020 Shows the Danger of a Decapitated Cyber Regime
Security

2020 Shows the Danger of a Decapitated Cyber Regime

by technewshero
January 13, 2021
A ‘Bulletproof’ Criminal VPN Was Taken Down in a Global Sting
Security

A ‘Bulletproof’ Criminal VPN Was Taken Down in a Global Sting

by technewshero
January 14, 2021
The Worst Hacks of 2020, a Surreal Pandemic Year
Security

The Worst Hacks of 2020, a Surreal Pandemic Year

by technewshero
January 15, 2021
Security

How Your Digital Trails Wind Up in the Police’s Hands

by technewshero
December 31, 2020
How to Understand the Russia Hack Fallout
Security

How to Understand the Russia Hack Fallout

by technewshero
December 22, 2020
Next Post

PhonePe Introduces Chat Feature on Android, iOS

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Most Popular

Facebook Loses Facial Recognition Appeal, Must Face Privacy Class Action

August 11, 2019

This Flame Level Adjusting Candlestick Always Keeps the Flame in Sight

August 16, 2019
Best MacBook Air alternatives for 2021

Best MacBook Air alternatives for 2021

January 12, 2021

Browse by Category

  • Apps
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • News
  • PC & Laptops
  • Security
  • Social
Tech News Hero

© 2020 Tech News Hero.

No Result
View All Result
  • Home
  • Landing Page
  • Buy JNews
  • Support Forum
  • Contact Us

© 2020 Tech News Hero.

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?