One of the most vexing problems for organizations is mitigating GDPR compliance risks when dealing with third parties, particularly the nature and extent of obligations between data controllers and processors. By virtue of the GDPR accountability principle, organizations are required to adhere to the six fundamental principles of safeguarding privacy rights that impact the collection, processing and disposition of personally identifiable information. These obligations extend beyond the walls of an organization to third parties that process personally identifiable information. Also, GDPR provides for a broad definition of processing and imposes stringent requirements on organizations that engage third parties to process personally identifiable information.
A potentially problematic challenge for industry and legislators is the apparent tension between privacy rights and the rapid adoption of blockchain-based applications which are expected to reach $10.6 billion in revenue by 2023.
More rigorous privacy regulations such as the EU GDPR and a number of US privacy initiatives such as the recently ratified California Consumer Privacy Act impose higher standards on data controllers and processors to safeguard privacy rights – including data subject consent management, accommodating data subject requests, data portability and more onerous data controller and processor accountability standards.
This is the 12th post in a series on privacy by Andrew Pery. You might also be interested in:
It's hard to believe it has been just about three months since the General Data Protection Regulation (GDPR) went into effect on May 25th, 2018. This new regulation was designed to strengthen and unify data protection for individuals within the European Union (EU) and came with a strict set of compliance protocols. And, because GDPR also applies to the export of personal data outside the EU, it's applicable to any entity that uses or exchanges this data - so, there are a lot of us all around the world feeling the pressure of GDPR. There's no shortage of valuable GDPR resources available all over the internet to help organizations prepare, but what about advice from the users working in the trenches? What advice do they have? That's exactly what we aimed to find out with this episode of AIIM on Air. Join your host Kevin Craine as he sits down with Elisabeth Belisle, Digital Transformation Consultant at Restore PLC, and Ed Steenhoek, Solution Principal and Product Manager at Informed Consulting to chat about the biggest difficulties being experienced right now by organizations working to be compliant with the GDPR and steps organizations should take to assess their state of compliance.
The GDPR’s May 25, 2018 deadline resulted in a mad compliance and security scramble not only for European companies but also for any company doing business in Europe or with European customers.