GDPR takes effect on May 25, 2018 and applies worldwide to any organization that holds or processes personal data relating to EU residents. Its definitions are intentionally expansive: “personal data” includes any information that can identify a person directly or indirectly (including identifiers like location data and online identifiers), and “processing” covers virtually any operation across the full lifecycle of that data, from collection through deletion. Processing is only lawful if it meets strict criteria (such as explicit consent, contract necessity, legal obligation, vital interests, public interest, or legitimate interests), and data subjects gain extended rights to access, correct, erase their data, and withdraw consent. Enforcement is severe, with penalties up to the greater of 4% of annual worldwide turnover or 20 million euros for serious breaches, while the Data Controller bears the burden of implementing and demonstrating compliance.
A central risk highlighted is non-production use of personal data (development, testing, outsourcing, cloud uploads). Because GDPR’s definition of processing includes these activities, personal data can proliferate beyond direct organizational control while responsibility and liability remain with the Data Controller. This creates complex obligations: extending data subject rights (disclosure, rectification, erasure) to all copies, ensuring Article 28(3) contractual controls for third parties, expanding breach detection and notification processes, and performing impact assessments where appropriate.
The text proposes minimizing exposure by removing personal data where it is not required, using anonymization or GDPR-endorsed pseudonymisation as “data protection by design and default,” while acknowledging residual risk when reversibility exists. Delphix Dynamic Data Platform is presented as a way to discover sensitive data across sources, govern non-production distribution, and apply irreversible masking to anonymize data (removing it from GDPR scope) while preserving relational usefulness for development and testing; tokenization is available when reversibility is needed but remains within GDPR scope.
See All Locations
See All Locations