From May 2018, the EU GDPR broadens and strengthens requirements for managing personal data, affecting most organizations that hold personal data on EU residents, including those outside the EU. The core IT challenge is operationalizing privacy obligations across sprawling, fragmented environments where Personally Identifiable Information (PII) exists in structured systems and unstructured locations like spreadsheets, documents, and email. Compliance begins with discovering where PII is stored and how it flows through complex architectures, because appropriate controls cannot be implemented or tested until the data is located and mapped.
GDPR compliance demands that access to PII aligns with the consent granted by the data subject, with controls that both enable legitimate use and prevent unauthorized exposure, including limits on aggregation. Organizations must be able to support data subject rights to access and correct data, and ensure request processes do not become a pathway for attackers. Consent itself must be freely given, informed, unambiguous, purpose-specific, withdrawable at any time, and provable by the controller/processor, requiring end-to-end consent lifecycle tracking potentially down to the field level and direct linkage to access control enforcement.
Cloud use does not reduce obligations; instead, it adds requirements for visibility and control over data movement and access, plus assurance that providers and services are suitable for PII (e.g., ISO/IEC 27018). GDPR also drives preparedness for breach notification within 72 hours and prompt notification to affected individuals, necessitating tested response plans integrated with business continuity, forensics, and communications. Finally, privacy engineering (e.g., NISTIR-8062) is emphasized to build compliant processing into new systems, since retrofitting privacy into legacy designs is difficult.
See All Locations
See All Locations