GDPR’s impact: The first six months
GDPR is now six months old – it’s time to take an assessment of the regulation’s impact so far. At first blush it would appear very little has changed. There are no well-publicized actions being taken against offenders. No large fines levied. So does this mean its yet another regulation that will be ignored? Actually nothing could be farther from the truth.
The day GDPR came into law complaints were filed by data subjects against Facebook and Google. Complaints – that does not sound like action by regulators, in fact its not – its action taken by lawyers. GDPR is a much-evolved form of European regulation allowing data subjects to file suits against data collectors whom they believe are violating their rights. This battle is going to be fought in 28 EU countries courts much sooner than in their Data Protection commissioners ministries who enforce the law and handout fines for violations.
Activist legal teams like Austrian noyb and its founder Max Schrems who had a strong hand in drafting GDPR are taking up these complaints. Meanwhile activist Privacy International is going after the likes of Oracle – filing complaints in the UK along similar lines as to the claims against Google and Facebook in that there is ongoing disregard to establishing legitimate-use of data collected and a disregard of individual’s rights because in fact those individuals do not know their data is being collected, so there is no expectation they can ask that their data be removed.
Regulator action will take time – six months is too early to get a proper read. Yet, we can still get a feel for what is going on by looking at what’s happening in a given country. The UK is interesting; their Information Commissioner predates GDPR as UKs privacy regulations go back to 1998. The UK commissioner is currently publishing findings and leveling fines after investigations for activities dating back to 2016. That gives us a feel for how long investigations may take under GDPR.
Perhaps we will not know the full impact for another two years to the magnitude of fines levied. Facebook’s challenges with Cambridge Analytica were lucky in that they fell under the prior law resulting in a smaller 500K GDP fine than the billions allowed by GDPR. Breaches at British Airways and others, which took place since GDPR became active, are being carefully monitored to see if in fact they were properly reported to the UK commission within the 72-hour limit of being discovered.
The hotbed for US companies is Dublin as Ireland is where many US companies have their European headquarters. Helen Dixon, the current Republic of Ireland Commissioner, and her office is one of the busiest in Europe working with these companies as they scrabble to be complaint under the law.
GDPR has had influence internationally – 10 countries including Canada, whose law just went active this month, now have very similar laws. California also has a much-watered down version that went into affect as well. None of these laws carry the same fines, but most allow for litigation. California is just one of 26 states that have such laws on the books. These laws vary widely in their rules. Because of this the Internet Association, an influential lobby group for Internet based companies, has come out indicating it would be for a single US law to provide uniform privacy assurance.
The difference being in how they want the law to be written. Here is an example: Google’s Android OS terms and conditions states that the user, by activating their service, consents to Google’s collection of their personal data across All Google products for any use. Today once you activate you can’t go back and ask them to remove you. The Internet Association’s President Michael Beckerman, states that individuals should have a right to ask what has been collected and then have this information removed – If they discontinue using the product/service. The difference is GDPR does not force you to disconnect your $1000 phone.
Given all that, perhaps its not surprising that Apple CEO, Tim Cook, has come out strongly in favor of having a similar strength version of GDPR here in the USA. Apparently they don’t collect the same data that Google, Facebook and Amazon do. Score one for capitalism?
All-in-all GDPR has had a subtle but extremely influential impact in the Internet world already. With all the lawyers involved, it’s not likely going by the wayside anytime soon.
Industry: Cyber Security News
- Information Security Risk Consultant, London. ISO 27005
REFCH7901 Information Security Risk Consultant, London. ISO 27005 Information Security Risk consultant needed for a London based client. The ability to achieve SC security clearance will be required. ISO 27005 Risk Assessment experience is essential. The role will cover, Risk identification, Assessment and Advisory consulting. This is a client facing role, single client- not multiple. Experience working with multiple teams and internal stakeholders is essential. The information Security Risk Consultant should ideally have a breath of information Security and IT technology based security experience. Prior experience within the public sector is desirable, but not essential. Broad knowledge across Security IT transformation, Cloud is also key. Broad experience across GRC, iso27001, NIST is key. Ongoing support and training provided. Apply today for more information, all details kept in confidence.
- Google Cloud platform Security Engineer, Contract, inside IR35
- United Kingdom
REF CH7897 Google Cloud platform Security Engineer, Contract, Inside IR35 Looking for a Google Cloud platform Security Engineer will define, document, design, implement, harden and generally improve the security capability of a Google Cloud Platform. The ability to configure, and deploy the following Google Cloud Platform security solutioons is essential; Command Security Centre, Cluster Security, APIGEE, GCP Cloud Armor Hands on technical expertise security experience with Terraform, Kubernetes Security, Container (Docker) security, Secret Manager is essential as is experience securing Google Kubernetes Engine Workloads. It is essential that you have a proven track record of securing a GCP environment and expertise in automating that with Terraform. Scripting experience with the above where appropriate is a key ability. You will be highly technical and have the ability to engage with stakeholders to ultimately deliver a secure and hardened Google Cloud Platform.
- Security Analyst, London. Financial Services. End user.
CH7885. Security Analyst, London. Financial Services. End user. Immediate role. £55,000 Security Analyst needed to monitor and manage a security suite of tools within Financial Servicecs end user . The Security Analyst will be responsible monitoring, configuring, fine tuning, incident management and generally improving the security tool capability. Specific experience with CyberArk, Tripwire Log Center and Tripwire Enterprise is highly desirable). Current experience with Vulnerability management and penetration testing is highly desirable. Specifically the ability to effectively manage 3rd party pen tests. You will be working within a specialist security team reporting to the CISO. Experience working within a regulated end user environment within financial services is highly desirable. This role will run a hyrbid working schedule, partly remote, partly office based in London (once permitted) This is an exclusive role to DCL Search & Selection. https://calendly.com/chris-holt/call-with-chris-holt-dcl-search
- IAM Consultant- Identity Governance
- United Kingdom
- Upto £80,000 plus benefits
Identity and Access Management Consutlant is required for this established business who put their employees first. the role entails • Develop and maintain IAM services. • Further develop IAM tool integration with Service Now to provide automated JML processes and application access requests and fulfilment. • Provide guidance over Role Based Access in terms of Location based Roles, Application Roles and Business Roles and act as SME over any future RBAC project. • Work closely with our other Technology teams on integrating IAM services with Technology and business systems to increase efficiency through automation around areas such as JML processes, application access request fulfilment and attestation. • Work with the Governance Risk & Compliance (GRC) team to provide application access attestations and toxic combination alerting and reporting. • Involvement with Identity Management initiatives such as Single Sign On (SSO) and Privileged Access Management (PAM), to ensure security and business processes are in line with industry best practice. • Assist in ensuring that all IAM capabilities are mapped to internal processes, policies, and standards. Develop metrics to measure and improve the alignment. • Complete monthly review and report on sensitive group access, i.e., service accounts, admin accounts, etc. validating I&O processes are effective. • Provide information to both internal and external Auditors in response to findings. • Collate audit evidence for AAF audit and control reviews, taking responsibility for identifying service and process improvements to ensure compliance with our controls and standards. We are looking for someone with Hands on technical experience with the IAM tools, you need to have been involved in the integration of the IAM solution into 3rd party software like Servicenow, You will have worked with an IAM tools that are focused into Identity Goveranance, like RSA, CA Identity Suite, Fischer Identity, Hid Global, IBM IGL, Net IQ Identity Goverance, Omada, Ping or Oracle Post covid, this role will invovle a mix of home and office work, the business have a number of office spread across the UK so locaton is flexible for this position