Share

Lessons on data breaches from the EU

Six months ago, May 25, 2018 to be exact the General Data Protection Regulation (GDPR) came into effect in the European Union – but its implementation happened with a "whimper" rather than a "bang", says an industry expert.

The regulation falls under EU law and deals with data protection and privacy of individuals within the EU and the European Economic Area. Among the biggest prescriptions of the policy is that companies notify authorities when data breaches occur – in a time frame of 72 hours.

Patrick Grillo, senior director of solutions marketing for cybersecurity firm Fortinet, shared with journalists at a conference in Sophia Antipolis, France this week, the impact of the policy.

One of the first changes most users would have been exposed to is companies sending out notices of their updated privacy policy. The likes of Google had to notify users of what information is being captured and how it is being tracked or used.

Even some companies not based in the EU, but which do business impacting EU members, elected to adopt the regulatory protocol.

But what happened since May 25?

'Catastrophic' data breach

British Airways experienced a "catastrophic" data breach. There had been data breaches in other companies too – but not as significant as that of the airline.

Facebook had another data breach, hot off the heels of the Cambridge Analytica saga which exposed violations of data protection rules by the social media network.

Grillo said that also in the past six months, there had been fines issued to companies as a result of non-compliance with GDPR. But there is not a silver bullet of how regulators will react – especially in light of the high-profile breaches like that of British Airways or Facebook.

"It depends on how negligent the companies were, how prepared or unprepared they were," he said.

Certainly in  the past six months the very issues have sprung up for which the GDPR was designed in the first place, he explained.

Grillow said that it was not possible for all companies to already be compliant with the regulation when it came into effect – but companies need to have had a plan in place to indicate that certain actions will be taken in the event of the breach.

Complexity

Grillo pointed out a shortcoming in the regulation, namely that it is not guiding companies on how to be compliant.

"Here is a regulation telling you to do something, but not telling you how to do it," he said. Essentially organisations are left figure a way from point A to point Z, without a roadmap, he explained.

There's a range of things that had to be changed, from the technology to the legal contracts which had to be updated.

Grillo also pointed out that there was a lack of cyber security technology mentioned in the policy. Similarly, organisations' actions echoed this. In an effort to be compliant, companies have placed more priory on data privacy than data protection – when in fact these two things should be prioritised equally, he said.

So for example, they have been proactive in avoiding fines by reporting breaches within the required time frame, but risk management or preventing the actually data breaches from happening has been secondary.

"Data privacy and data protection must be equal aspects of any organisation's GDPR preparations, but data privacy took all focus because it is most visible," he said. Grillo argued that focusing on data protection, would help companies avoid a fine, even if they had a data breach.

He elaborated that when a cyber attacker enters a network there is still the aspect of retrieving the information or misusing it. When a hacker gets into a network there is window of opportunity in which they get what they want, or try search for something of interest. The aim of data protection is to minimise that window so that no damage is done through the breach.

 Breaches will continue

In his closing remarks, Grillo said that leading up into 2019, data breaches would likely continue to happen. "Data protection and data privacy is here to stay," he said. "It is part of the landscape that a company needs to take into account, as part of risk management of how to do business."

Other countries round the world, such as the US, are also considering introducing regulation similar to GDPR, he said.

*Fin24 is a guest of Fortinet's international media conference in Sophia Antipolis, France.

* Sign up to Fin24's top news in your inbox: SUBSCRIBE TO FIN24 NEWSLETTER

We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
19.21
-0.3%
Rand - Pound
23.92
-0.4%
Rand - Euro
20.47
-0.4%
Rand - Aus dollar
12.34
-0.3%
Rand - Yen
0.12
-0.4%
Platinum
948.60
-0.2%
Palladium
1,020.50
-0.9%
Gold
2,381.38
+0.1%
Silver
28.30
+0.3%
Brent-ruolie
87.11
-0.2%
Top 40
66,831
-0.5%
All Share
72,881
-0.5%
Resource 10
63,032
-0.4%
Industrial 25
97,705
-0.7%
Financial 15
15,436
-0.3%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders