Privacy Policy Updated

We’ve updated our Privacy Policy effective July 15, 2020. You can view our updated policy here.

X
Posted 5.23.18
by wpadmin
Blog

Are you ready for GDPR?

EU logo with GDPRYou’ve probably seen the “privacy change notices” flooding your email lately as a result of GDPR, and your team is probably getting your own organization’s emails ready to go out if they haven’t already. The General Data Protection Regulation (GDPR) takes effect this Friday, May 25, but according to a survey by ISACA, a group focused on IT governance, only 29 percent of companies will be fully compliant by then. Are you one of them? If not, here’s what you need to know.

  1. Don’t forget to build a process around data deletion. Most companies are already worried about how they’re going to store data GDPR considers “private,” but they also have to take into consideration the fact that the consumer (in Europe) has the power to request that their data be deleted. Consider how you will honor the consumer’s “right to be forgotten” with other legal requirements, such as HIPAA.
  2. If you’re found to be out of compliance, you could face a steep penalty: 20 million Euros or 4 percent annual turnover (similar to revenue), whichever is higher. Fines levied will vary based on the nature and duration of the violation, as well as where it occurred. This is because enforcement likely will not be standardized across the EU. Businesses across the globe will be watching to see who the data protection authorities will target first for being out of compliance, and how their punishment will be levied.
  3. Education is key. Your employees may be unsure or unaware of their role in GDPR compliance. Keeping them informed and trained about what their responsibilities are in the wake of these new regulations is critical to ensuring they actually follow them. Most people don’t like something if they don’t understand it!
  4. Be transparent. If you’ve read any of the “privacy change notices” mentioned at the beginning of the article, you’ll notice they’re making an effort to be clear in how they’re using your data. They aren’t trying to be nice–it’s part of the GDPR requirement that organizations must be able to clearly explain how user data is being stored and processed. This means a more thorough understanding by the IT risk and governance teams of how the user’s data is being handled so they can in turn explain it to their users. This may mean a revision of client contracts–anything from a fully signed formal agreement to “I accept the terms and conditions” click-through agreement on your website.

Learn the six keys to meeting GDPR compliance

Compliance is always a process–just because you’re compliant now doesn’t mean you can stop thinking about it. As your business changes, you must always think about how you’re collecting, processing, storing and deleting your data. It can benefit you not just from a compliance perspective but a data security and better business value of your data, too.

For more information, visit the GDPR website or check out their FAQ section.

About Otava

Otava provides the secure, compliant hybrid cloud solutions demanded by service providers, channel partners and enterprise clients in compliance-sensitive industries. By actively aggregating best-of-breed cloud companies and investing in people, tools, and processes, Otava’s global footprint continues to expand. The company provides its customers in highly regulated disciplines with a clear path to transformation through its effective solutions and broad portfolio of hybrid cloud, data protection, disaster recovery, security and colocation services, all championed by an exceptional support team. Learn more at www.otava.com.

Get started with Otava now!

  • This field is for validation purposes and should be left unchanged.