Social Media

profilestudent118
GDPRcompaniesatriskoverunstructureddata.pdf

1/22/2020 UC MegaSearch

eds.a.ebscohost.com/eds/delivery?sid=72f23a8f-959a-4425-91fe-c21d536b7b5d%40sdc-v-sessmgr03&vid=10&ReturnUrl=http%3a%2f%2feds.a.ebscohost.com%2feds%2fdetail%2fdetail%3fvid%3d9… 1/4

Title: Authors: Source:

Document Type: Subject Terms:

Abstract:

Full Text Word Count: ISSN:

Accession Number: Database:

Record: 1

GDPR: companies at risk over unstructured data.

Jackson, Olly

International Financial Law Review. 7/30/2018, pN.PAG-N.PAG. 1p. 1 Chart.

Article

*DATA protection laws *ACCESS to information *RIGHT of privacy *GOVERNMENT policy RECORDS retention laws LEGAL status of consumers

Companies are facing potentially huge fines over their lack of retention policies [ABSTRACT FROM AUTHOR]

Copyright of International Financial Law Review is the property of Euromoney Institutional Investor PLC and its content may not be copied or emailed to multiple sites or posted to a listserv without the copyright holder's express written permission. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)

968

0262-6969

131087814

Business Source Premier

GDPR: companies at risk over unstructured data

Companies are facing potentially huge fines over their lack of retention policies

Many companies are already at risk of infringing the GeneralData Protection Regulation (GDPR) less than two months after it came into force.Smaller businesses, in particular, are struggling to consolidate unstructureddata and don’t have clear or defined retention policies in place.

GDPR consultant Neil Aremband said that a lot of companiesare struggling with unstructured data and this becomes a particular problembecause it becomes difficult to consolidate all of it.

1/22/2020 UC MegaSearch

eds.a.ebscohost.com/eds/delivery?sid=72f23a8f-959a-4425-91fe-c21d536b7b5d%40sdc-v-sessmgr03&vid=10&ReturnUrl=http%3a%2f%2feds.a.ebscohost.com%2feds%2fdetail%2fdetail%3fvid%3d9… 2/4

"For many companies, retention policies are not defined orclear and have not been communicated effectively,” he said. “Data is also stillbeing held longer than necessary.”

Companies either don’t understand or are surprised by theamount of unnecessary data they hold, which provides a big risk and increasesthe chances of a data breach. On the day GDPR came into force, Facebook,Google, Instagram and WhatsApp were subject to complaints filed to theInformation Commissioner’s Office (ICO) from European consumer rights organisationNoyb.

“Facebook has even blocked accounts of users who have notgiven consent,” said Noyb chair Max Schrems. “In the end users only had thechoice to delete the account or hit the agree button – that’s not a freechoice, it’s reminiscent of a North Korean election process.”

"Retention policies are not defined or clear and have not been communicated effectively" Fundamental tenets under GDPR are that users or customersmust be able to opt out just as easily as they can opt in - if users do decideto opt out then the service provided must not be affected. Yet social mediacompanies are said to be discriminating against users that do not agree to datasharing and excluding them if they do not agree completely.

Facebook was fined £500,000 ($659,000 approximately) thisweek after user data was collected for political purposes by CambridgeAnalytica in 2016. If a similar offence was committed today under the GDPRregime, it is believed the fine could be 2,800 times that figure at £1.4billion – with offending companies fined up to four percent of their annualturnover. Facebook is reported to make £500,000 in just 18 minutes.

KEY TAKEAWAYS

Almosttwo months after GDPR came into force, many companies are struggling toconsolidate unstructured data and do not have clear retention policies inplace;

SMEs alsodo not have a corporate list register to mitigate risks;

Ticketmasterreported a breach late last month and the case is considered a test case forhow the rules are to be enforced.

Facebook is almost inevitably going to be one of the firstcompanies to be audited and any transgression would be made public quickly. A publicitypush exposing Facebook’s newfound passion for data protection is ongoing andAremband said that they have tried to be as compliant as possible but have notcommunicated privacy policies enough so they could increase awareness.

Yet these problems are not reserved solely for largeconglomerates.

“SMEs don’t tend to have a corporate lead register, which isan effective way of mitigating risk,” he said. “The fear is that if they wereaudited, regulators could find risks present.”

1/22/2020 UC MegaSearch

eds.a.ebscohost.com/eds/delivery?sid=72f23a8f-959a-4425-91fe-c21d536b7b5d%40sdc-v-sessmgr03&vid=10&ReturnUrl=http%3a%2f%2feds.a.ebscohost.com%2feds%2fdetail%2fdetail%3fvid%3d9… 3/4

Organisations need to continuously update a corporate listregister to mitigate any risks and someone within the company needs to takelead of this. Without this, the chances of a company getting into troubleincrease if they do not have strong internal processes. Therefore they needsomeone to constantly check and update the register.

As part of its guidance, the ICO said that companies shouldcarry out data protection impact assessments for uses of personal data that arelikely to result in high risk to individuals’ interests. It is also recommendedthat companies sign up to certification regimes.

Charles Owen, director of alternative assets platformCoInvestor, said that some companies are nervous about sharing reporting data,but these nerves are not justified. Ina previous IFLR article he said alternative assets companies would have thebiggest problem complying with GDPR because transactions are held on paper, buteven though some companies are not comfortable with sharing this information,he has seen a change.

“Therehas been an increased understanding of data privacy and product providers,” hesaid. “These companies have a much higher appreciation of data and contracts,and are motivated to think more about their processes. We definitely have seena change in data privacy and it has become very much part of their thinking.”

Muchof the confusion would be alleviated by understanding data sharing policies andinterpreting contracts with all of their counterparties. Companies must ensurethat all contracts with each data handler is updated and complies with GDPRrules, often seen as the most challenging aspect of the regulations.

Lastmonth, Ticketmaster reported a data breach affecting up to 40,000 people, aftera malware attack on a third-party vendor enabled hackers to access names,addresses, email addresses, telephone number and card details. The responsefrom the regulator will be a big indication into how these rules will beenforced.

“Thisis very much a settling down process,” he said. “Until you see the regulationsbite, it is hard to judge whether companies are ahead or behind them.”

Ticketmasterargues that it did comply with GDPR, and every data breach does not necessarilyamount to a fine. GDPR builds new compliance infrastructure around existingdata protection rules and companies can avoid a fine for a data breachproviding that they have reported the data breach within 72 hours and they havecompleted sufficient preparation to minimise the chance of a data breach.

“Itis not so much about altering the core rules, like being transparent withpeople about what you are doing, but reinforcing the current rules by requiringbusinesses to be able to demonstrate how they comply,” said Richard Cumbley, Linklaterspartner.

TheTicketmaster case will provide plenty of clues for companies. The first stepmany companies need to take however is implementing clear retention policiesand a corporate lead register before anything else.

See also

1/22/2020 UC MegaSearch

eds.a.ebscohost.com/eds/delivery?sid=72f23a8f-959a-4425-91fe-c21d536b7b5d%40sdc-v-sessmgr03&vid=10&ReturnUrl=http%3a%2f%2feds.a.ebscohost.com%2feds%2fdetail%2fdetail%3fvid%3d9… 4/4

New ePrivacyRegulations will force Google and Facebook to change tact

GDPR: howbest to store data

GDPR willimpact US M&A

~~~~~~~~ By Olly Jackson

©Euromoney Institutional Investor PLC. This material must be used for the customer's internal business use only and a maximum of ten (10) hard copy print-outs may be made. No further copying or transmission of this material is allowed without the express permission of Euromoney Institutional Investor PLC. Source: International Financial Law Review and http://www.iflr.com.