GDPR’s impact: The first six months
GDPR is now six months old – it’s time to take an assessment of the regulation’s impact so far. At first blush it would appear very little has changed. There are no well-publicized actions being taken against offenders. No large fines levied. So does this mean its yet another regulation that will be ignored? Actually nothing could be farther from the truth.
The day GDPR came into law complaints were filed by data subjects against Facebook and Google. Complaints – that does not sound like action by regulators, in fact its not – its action taken by lawyers. GDPR is a much-evolved form of European regulation allowing data subjects to file suits against data collectors whom they believe are violating their rights. This battle is going to be fought in 28 EU countries courts much sooner than in their Data Protection commissioners ministries who enforce the law and handout fines for violations.
Activist legal teams like Austrian noyb and its founder Max Schrems who had a strong hand in drafting GDPR are taking up these complaints. Meanwhile activist Privacy International is going after the likes of Oracle – filing complaints in the UK along similar lines as to the claims against Google and Facebook in that there is ongoing disregard to establishing legitimate-use of data collected and a disregard of individual’s rights because in fact those individuals do not know their data is being collected, so there is no expectation they can ask that their data be removed.
Regulator action will take time – six months is too early to get a proper read. Yet, we can still get a feel for what is going on by looking at what’s happening in a given country. The UK is interesting; their Information Commissioner predates GDPR as UKs privacy regulations go back to 1998. The UK commissioner is currently publishing findings and leveling fines after investigations for activities dating back to 2016. That gives us a feel for how long investigations may take under GDPR.
Perhaps we will not know the full impact for another two years to the magnitude of fines levied. Facebook’s challenges with Cambridge Analytica were lucky in that they fell under the prior law resulting in a smaller 500K GDP fine than the billions allowed by GDPR. Breaches at British Airways and others, which took place since GDPR became active, are being carefully monitored to see if in fact they were properly reported to the UK commission within the 72-hour limit of being discovered.
The hotbed for US companies is Dublin as Ireland is where many US companies have their European headquarters. Helen Dixon, the current Republic of Ireland Commissioner, and her office is one of the busiest in Europe working with these companies as they scrabble to be complaint under the law.
GDPR has had influence internationally – 10 countries including Canada, whose law just went active this month, now have very similar laws. California also has a much-watered down version that went into affect as well. None of these laws carry the same fines, but most allow for litigation. California is just one of 26 states that have such laws on the books. These laws vary widely in their rules. Because of this the Internet Association, an influential lobby group for Internet based companies, has come out indicating it would be for a single US law to provide uniform privacy assurance.
The difference being in how they want the law to be written. Here is an example: Google’s Android OS terms and conditions states that the user, by activating their service, consents to Google’s collection of their personal data across All Google products for any use. Today once you activate you can’t go back and ask them to remove you. The Internet Association’s President Michael Beckerman, states that individuals should have a right to ask what has been collected and then have this information removed – If they discontinue using the product/service. The difference is GDPR does not force you to disconnect your $1000 phone.
Given all that, perhaps its not surprising that Apple CEO, Tim Cook, has come out strongly in favor of having a similar strength version of GDPR here in the USA. Apparently they don’t collect the same data that Google, Facebook and Amazon do. Score one for capitalism?
All-in-all GDPR has had a subtle but extremely influential impact in the Internet world already. With all the lawyers involved, it’s not likely going by the wayside anytime soon.
source helpnetsecurity
Industry: Cyber Security News
Latest Jobs
-
- Data Privacy Lead. Client Facing London. Permanent.
- London
- N/A
-
Data Privacy Lead. Client Facing London. Permanent. London based client facing. Must be eligible to undergo UK Security Clearance (SC) Key Responsibilities: Lead and support client facing data privacy projects. Assess compliance, define and deliver strategic projects / implement privacy solutions. Manage project teams and develop business opportunities. Required Experience: Experience in data protection and privacy standards. Background in consulting. Skills and Qualifications: Business consulting experience IAPPPrivacy Manager / Privacy Technologist Location Greater London UK based role. Not able to provide VISA sponsorship.
-
- VOIP / SIP App Developer. Contract. SIP | VOIP experience needed. SC Cleared Outside IR35 Contract. London
- London
- OUTSIDE IR35
-
SIP | VOIP Developer. SC Cleared Contract. London Looking for a SC Cleared SIP / VOIP Developer to develop an application that interacts with a set of voice and video signalling API’s You will also work on developing in-house applications, browser plugins and automated tooling to support secure communication systems. Responsibilities Develop an application that will manage number mapping and associated identities using commercial SBC API’s. Develop new user-facing features using React.js or other modern JavaScript frameworks. Build reusable components and front-end libraries for future use. Collaborate with the design team to translate UI/UX design wireframes into code. Work closely with backend developers to integrate front-end code with server-side logic. Conduct code reviews and provide constructive feedback to team members. Stay up-to-date on emerging technologies and industry trends to continuously improve our front-end development practices. Troubleshoot and debug issues that arise during development and in production environments. Maintain high coding standards and practices and ensure code is well-documented. Requirement Experience of developing specialist applications using REST API’s. Good knowledge of Go, Java and Python (open to alternative combinations of languages). Proficiency in front-end languages and frameworks such as HTML, CSS, JavaScript, React.js, etc. Strong understanding of web standards, responsive design, and cross-browser compatibility. Experience with version control systems such as Git. Knowledge of RESTful APIs and asynchronous request handling. Familiarity with UI/UX design principles and tools.
-
- Senior Data Privacy Consultant. Client Facing | London
- London
- N/A
-
Senior Data Privacy Consultant. Client Facing | London Senior Data Privacy Consultant needed for a key client facing opportunity. Must be willing to undergo SC Security Clearance. Hybrid role- onsite with customer / office 2-3 days a week. London Key Responsibilities: Lead and support client facing data privacy projects. Assess compliance, define and deliver strategic projects / implement privacy solutions. Manage project teams and develop business opportunities. Required Experience: Experience in data protection and privacy standards. Background in consulting. Skills and Qualifications: Business consulting experience IAPP Privacy Manager / Privacy Technologist Location Greater London UK based role. Not able to provide VISA sponsorship.
-
- Security Analyst - Internal role. London commutable. Permanent
- London
- N/A
-
Security Analyst - Internal role. London commutable opportunity. Operational Security - Investigate, escalate and proactively work to ensure household name remains protected. Project Security - Coordinate, log change requests with project delivery teams to meet security requirements Policy / compliance - work with team to aid in uplifting these as and where needed This role is role to investigate, escalate and proactively work to protect a globally recognised brand. You must have current hands on operational analytical security experience with Microsoft technology stack Someone with a SOC Analyst / security engineering background would be well suited. This position will join a small team and would suit someone that has broad experience across the security threat landscape. Experience / knowledge across industry GRC standards such NIST, ISO27001 etc very advantageous and a priority. You will work across multiple teams proactively working to secure the business. Must be able to commute to Central London 3 days a week. Visa sponsorship not available Apply today to find out more.