{"id":22018,"date":"2018-06-11T10:08:02","date_gmt":"2018-06-11T09:08:02","guid":{"rendered":"http:\/\/www.intelligentcio.com\/eu\/2018\/06\/11\/five-steps-on-the-journey-to-gdpr-compliance\/"},"modified":"2018-06-14T08:57:34","modified_gmt":"2018-06-14T07:57:34","slug":"five-steps-on-the-journey-to-gdpr-compliance","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2018\/06\/11\/five-steps-on-the-journey-to-gdpr-compliance\/","title":{"rendered":"Veeam expert: Five steps to complying with the EU&#8217;s GDPR"},"content":{"rendered":"<p><em>Now that GDPR has been introduced the journey towards compliance has started and companies are updating their relationship with data protection. Claude Schuck, Regional Manager for Middle East and Central Africa at Veeam Software, looks at ways that enterprises can make their approach fit for the future.<\/em><\/p>\n<p>There are still a vast number of organisations that have not taken the necessary steps to ensure GDPR (General Data Protection Regulation) compliance? The problem surrounding GDPR compliance is that it\u2019s thought of as being just an \u2018IT issue\u2019.<\/p>\n<p>Lots of businesses seem to either have an inflated sense of confidence around how they already handle data, or they\u2019re shrugging it off as someone else\u2019s problem which is to miss the point entirely.<\/p>\n<p>Compliance with GDPR, in terms of both preparation and maintenance, should be a company-wide effort. Not least because companies who are found to be non-compliant could face hefty fines that would affect everyone.<\/p>\n<p>And if the stipulations of the GDPR seem significant, it\u2019s because they are. We\u2019ve not had any updates to data protection laws since 1995 and things have changed a lot since then. The way businesses collected and stored personal data back then is no doubt very different to the way they do it in 2018.<\/p>\n<p>When you put it like that, the GDPR seems pretty overdue. Today\u2019s organisations should be welcoming it as an opportunity to update their whole relationship with data protection and make it fit for the future: To implement a methodology that\u2019s built into the fabric of the organisation, not an afterthought or just something for IT to deal with.<\/p>\n<p>The way we see it, there\u2019s a very simple way to frame your approach to GDPR compliance. The five steps detailed below is the process we at Veeam went through to prepare. Now, we\u2019re sharing it with you, in the hope that you\u2019ll be able to complete your journey to compliance.<\/p>\n<p><strong>Knowing your data<\/strong><\/p>\n<p>If you\u2019re a business that has or holds data on EU citizens, formerly known as Personally Identifiable Information (PII), then the GDPR applies to you. That means you\u2019re liable to penalty fines if you\u2019re found to be non-compliant after the deadline of May 25 which has now passed.<\/p>\n<p>The best starting point, then, is simply knowing whether you hold this kind of data or not, and if you do, where it\u2019s kept. Creating a visual map of all the data you hold will help you to build a comprehensive picture and get better oversight of this.<\/p>\n<p>A lack of knowledge around the kind of data they hold may be another reason why so many businesses don\u2019t seem to be taking much notice of the GDPR, or just don\u2019t think it applies to them.<\/p>\n<p>It could be that they don\u2019t believe they hold any relevant data (hint: if you employ EU citizens, you do), or don\u2019t realise the breadth and scope of the data they do hold (hint: personal data is more than just names and addresses). This is precisely why just <em>knowing<\/em> your data is the first step on your journey to compliance.<\/p>\n<p><strong>Managing your data<\/strong><\/p>\n<p>Once you\u2019ve built up a picture of all the relevant data you collect and hold, it\u2019s time to look at who has access to it and how it\u2019s being used. Different teams and departments in your business will be accessing the same data in different ways and will be using it for varying purposes.<\/p>\n<p>Whether it\u2019s a marketing team inputting data on prospective customers and sharing it with the sales team, or a HR team handling data on its own employees, it\u2019s essential that you implement standardised procedures and workflows around the handling of personal data, and that employees only have access when it\u2019s necessary to their business function.<\/p>\n<p>Managing your data is about having visibility of the way data lives and breathes in your organisation even if that\u2019s not in-house. Your GDPR compliance also depends on the compliance of any third-party vendors or providers you work with, so the onus is on you to make sure they\u2019re abiding by the rules. No turning a blind eye to data management once it\u2019s out of your own business\u2019 hands.<\/p>\n<p><strong>Protecting your data<\/strong><\/p>\n<p>Having gained better oversight of your data and implemented standardised processes to manage it, it\u2019s time to make sure the right security controls are in place to protect the data, \u00a0but that doesn\u2019t just mean encryption. To be compliant you can\u2019t simply turn security \u2018on\u2019 and put your feet up; the GDPR requires constant monitoring and diligence, and also much quicker action in the event of a data breach.<\/p>\n<p>It\u2019s true that technology will play an important part in that journey, but technology alone will not bring about compliance. Rolling out a new company-wide approach to data protection requires a combination of security techniques, standardised workflows, internal education, access control, backup solutions and much more besides.<\/p>\n<p>Keeping on top of who has access, where and when, with constant auditing and monitoring will enable much swifter responses to the data breaches that, despite everyone\u2019s best efforts, are probably still inevitable.<\/p>\n<p><strong>Documenting and complying<\/strong><\/p>\n<p>One of the GDPR\u2019s hottest topics is the introduction of data requests, which means an individual will have the right to request the correction or deletion of the data held about them. Businesses will be expected to comply with these requests and show that they\u2019ve done so, which is why visibility over what data you hold and where is so crucial.<\/p>\n<p>Ongoing compliance with the GDPR also requires the documenting and auditing of what data you\u2019re collecting, what it\u2019s being used for and how long you\u2019ll be storing it for. When we went through this step, we asked ourselves questions like: Is the data we collected months ago still relevant today? Do we still have visibility of data when it\u2019s moved from one place to another? Are our third-party providers still compliant?<\/p>\n<p><strong>Continually improving<\/strong><\/p>\n<p>One of the benefits of constantly monitoring and auditing your data protection processes is the opportunity to constantly review and improve them. It\u2019s true that the GDPR is something of a line in the sand, but as the digital world we live in constantly evolves and expands, it\u2019s safe to assume that responsibilities around data privacy and protection will also continue to increase so businesses will need to continually improve to keep compliant.<\/p>\n<p>The GDPR should be seen by businesses as an opportunity to rethink their entire approach to data protection, now and moving forward. It\u2019s a chance to make their organisations fit for the future and they should grab it with both hands.<\/p>\n<p>We learnt a lot about our business and our data in becoming GDPR compliant. We hope our story now helps you.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Now that GDPR has been introduced the journey towards compliance has started and companies are updating their relationship with data protection. Claude Schuck, Regional Manager for Middle East and Central Africa at Veeam Software, looks at ways that enterprises can make their approach fit for the future. There are still a vast number of organisations [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":22135,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[6587,7359,14],"tags":[7360,7361,7362,69,1750,2125,1931,7363,3766,2431,5594],"class_list":["post-22018","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-analysis","category-industry-expert","category-more-news","tag-africa","tag-claude-schuck","tag-compliance","tag-data","tag-data-protection","tag-gdpr","tag-general-data-protection-regulation","tag-middle-east","tag-personally-identifiable-information","tag-pii","tag-veeam-software"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/22018","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=22018"}],"version-history":[{"count":2,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/22018\/revisions"}],"predecessor-version":[{"id":22021,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/22018\/revisions\/22021"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/22135"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=22018"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=22018"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=22018"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}