Site navigation

GDPR: Dumb Ways to Fail (Part 4)

Toby Stevens

,

GDPR Dumb Ways Fail (Part 4)

In the fourth part of our series looking at the wonderful ways in which companies can (and will) fail to meet the new General Data Protection Regulation, Toby Stevens takes us back to the turn of the millennium and compares it to the last crisis which faced the technology sector..

4. Treat it as a one-off project

“GDPR is like Y2K – a load of running around fixing stuff, and the vendors and consultants get rich, but nothing really changes.”

Someone said that to me yet again this week, and it’s a really dumb way to fail.

Nothing could be further from the truth. Y2K was a technology remediation project to overcome a technology problem, with a hard-stop deadline. Some organisations just did the bare minimum to fix it, some used it as an opportunity to understand and overhaul their IT delivery, some stuck their heads in the sand and hoped for the best, and most got away with it in the end.

GDPR, however, is not a one-off project: it is a significant evolutionary step in data protection, and the impact it will have on your organisation depends upon the maturity of your current data protection management.

For organisations with robust and mature data protection management systems, GDPR will still require effort to ensure that risks are understood and controls and capabilities are in place.

For those with less developed data protection functions, this will require both significant remediation effort, and the creation of permanent data protection and information rights management capabilities. DPOs and data champions and information rights teams will have to be appointed to permanent roles. These organisations will find themselves paying off the data protection debt they’ve accumulated over the past 20 years as they failed to invest in their information governance but somehow got away with it.

At the end of this process, the data protection world will have changed. We’ll have more savvy data subjects with greater understanding of their new rights; we’ll be working with customers and suppliers who expect us to live up to our obligations for information governance, and enforce that through legal and technical controls; and ultimately more empowered supervisory authorities who will be able to ensure that we meet our legal obligations. This isn’t a one-off fix, it’s the transition to a new data protection model.

And that’s why viewing it as a one-off project would be a really dumb way to fail at GDPR.

Please suggest your own GDPR Dumb Ways to Fail in the comments below, and we’ll add them to the list to be tackled in the coming days.

You can find the rest of the GDPR: Dumb Ways to Fail series using the links below:

GDPR: Dumb Ways to Fail (Part 1)

GDPR: Dumb Ways to Fail (Part 2)

GDPR: Dumb Ways to Fail (Part 3)

GDPR: Dumb Ways to Fail (Part 5)

GDPR: Dumb Ways to Fail (Part 6)

Toby Stevens, Direct Enterprise Privacy Group

Toby Stevens

Director, Enterprise Privacy Group

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data