GDPR

Subscribe to our YouTube GDPR Playlist.  Purchase our accredited GDPR - Certified Data Protection Officer (DPO) training in the Arrakis store.

Contact us about our new Data Protection Officer-as-a-Service.  Through a valuable partner we have in the EU, we can now offer localized DPO services.  Contact us at sales(@)arrakisconsulting.com.

If you comply with regulations and haven't heard of GDPR by now... You are way behind the power curve.

First, a little history. GDPR was enacted on 25 May 2016 and was fully enforced on 25 May 2018. The two years in between were designed to help companies worldwide become compliant and plan for the impact GDPR will have. Consider GDPR a massive improvement on PII (Personally Identifiable Information) protection, as well as the definition of what is considered PII under GDPR guidelines. The first thing you need to know is that the "G" in GDPR stands for "General"; however, the way the regulation is written, the "G" impacts globally. This means that if you are dealing with any GDPR information for an EU or UK citizen, regardless of where you are in the world, you fall under GDPR and may face penalties. Additionally, if you are located in the EU and process data from non-EU persons, then it still applies to you. GDPR Penalties are nothing to laugh at, either, given that the fines are up to $26MM or 4% of your organization's global gross revenue... whichever is greater, and based on how badly your company screwed up.


Contact us by filling out this form - Contact Us



Have a compliance question?  Ask our Compliance AI Chatbot


gdpr scale

Interested in Cybersecurity Awareness Training? Start your free Risk Assessment.


Need to validate the security of your suppliers?  Our Prosikon platform can help reduce your risk.

So, to make it easier to understand, if you deal with EU data, then GDPR would apply to you. If you are in the EU and process data from outside the EU, then GDPR applies to you.

If you deal with regulations, then you know very well how much fun it is to read hundreds of pages of boring content. To make it easier, I refer people to gdpr-info.eu for a better way to read and understand the GDPR. This website takes the regulation and breaks it down for easier searching and referencing.

Having said that, GDPR can be complex! Data Controllers have quite a bit of responsibilities and an obligation to ensure processors are following the rules as well. Take a look at the image below that shows just some of the complexities of a controller.

In a nutshell, though, what is GDPR? Well, GDPR builds on current PII definitions. The short story is that if you have any personal information that can be linked to a name and used to identify that person, you have a GDPR situation. So, say I have the name "Tom Jones" (not the famous singer), and I happen to have the email address "[email protected]", then I would be under GDPR if I attached the name to the email address. This would mean that I would have to be able to prove a few things: 1. how I got the information, 2. why I have the information, 3. what I am going to do with the information, 4. how I protected the information, 5. If I gave the information to anyone or not, 6. how I destroyed the information, 7. all aspects of how I processed the information. To put it very subtly, this is HUGE!!!

The above scenario would also apply in a variety of ways, such as having, or having knowledge of, a person's:

- age
- birthday
- sex
- address
- phone number
- IP address
- sexual orientation
- political orientation or political opinions
- union or trade memberships
- religious or philosophical beliefs
- racial or ethnic origin
- genetic or biometric data
- health-related data
- Anything to do with child data under the age of 16.
- in addition to anything not listed above but currently covered under PII, PCI, PHI, FTI, etc...


You will also need to understand the three main classifications of entities. The first is the data subject, i.e., the human to whom the information is attached. The second is the controller. A controller is the entity that receives sensitive information from the data subject for processing, and the processing should be in line with the consent form the data subject has filled out. The last is the processor's role. A processor is an entity that performs task(s) on behalf of a controller(s) and is under contract with the controller (s) to perform those tasks and protect the data to the same, or better, standards. It should be understood that some controllers can also be processors. So, for example, ADP (the payroll company) probably doesn't outsource payroll to another company so that ADP would be both a controller and a processor. Conversely, any company that outsourced payroll to ADP would mean that the company was the controller and ADP was the processor.

So, what do you or your company have to do to become compliant or get closer to compliance? Quite a few requirements have become mandatory, depending on the language and penalties.

- Assign a Data Protection Officer (DPO) - A DPO must be assigned if processing large amounts of GDPR data. This person must be available and involved in any involvement where there is a possibility of a loss of GDPR data. The DPO will be the point person for any GDPR issues with the affected persons and the Supervisory Authority (SA).  GDPR specifically allows outsourcing the DPO role, and Arrakis can help you with that if you require it.  Do you need DPO training? Contact Arrakis for accredited training that leads to certification.
- Lawfulness of processing - Does your company have a lawful right to receive the data, store the data, or process the data? If you are unsure, you are advised to resolve this immediately, as unlawful possession of GDPR data would constitute a serious violation.
- Data protection by design - You can no longer buy or build software and then run security assessments or vulnerability analysis after that software tool is in production. Now, you must assess data protection in DevOps and ensure it for 3rd-party software before deploying to production.
- Old equipment - You can't keep your legacy windows boxes around anymore because you didn't plan on upgrading, or don't have the budget to upgrade, and the same thing applies to software that you simply just didn't want to go through the hassle of upgrading. With GDPR, you must "implement appropriate technical and organizational measures". This means that old equipment or software isn't appropriate and will come to bite you in the end.
- Encryption - to put it simply, if your GDPR data (or any sensitive data) isn't encrypted, then you are in serious trouble. This means it is completely encrypted at rest and in transit. One question is about a site-to-site VPN tunnel. In this particular case, there is not enough encryption because the tunnel is encrypted, but the traffic is not computer-to-computer. Other areas of appropriate security are recommended besides just encryption, but failing to encrypt will be a huge red flag for a GDPR investigator if it comes up.
- Data Protection Assessments - As a part of doing business, you will now be expected to assess your levels of data protection and acknowledge or remediate what is needed to become GDPR compliant.
- Privacy Impact Assessments - Similar to a data protection assessment, you are now expected to do a privacy impact assessment to increase visibility into what level of impact will happen for the data subjects, as well as your company, if there is a privacy issue.
- Logging - As a part of transparent communication, the data subjects (the person to whom the data actually refers) have the right to request a complete understanding of how their data was used. This means that you will have to be able to effectively report on who opened GDPR data, what they did with GDPR data, who they sent GDPR data to, how GDPR data was destroyed, etc Essentially, complete awareness as it relates to all aspects of how the GDPR data was used...this means intense logging.
- Consent - Data subjects must have a clear and concise method of consenting to having their GDPR data collected from them, as well as completely, with no misunderstanding, of how their data will be used and stored. So, remember all those websites that indicate they use cookies? You will see a lot more of that! There can be no confusion on the consent message at all. The data subject must also be able to revoke consent as easily as invoking it.
- Data Mapping - You must be able to demonstrate accurately how GDPR data flows through, is processed, and is stored in your network.
- Policies - Now, you must have the appropriate administrative controls in place that allow for the protection of GDPR data. This means you can no longer run a business without solid policies that can stand up to ISO, NIST, GDPR, etc. Your policies would have to cover data classification, data retention, data destruction, encryption, etc. Read our one-pager on Policies here.
- Data Subject Rights - The owner of the actual GDPR data has numerous rights, and if you are a company that processes or stores GDPR data, then you are obligated to comply with their requests. Specific rights are:

- Transparent Communication - similar to the logging bullet point, the data subject has the right to complete and fully transparent communication of how their data is stored or used. This communication must be conducted in a secure manner that doesn't put the data subject at risk. Additionally, the first request from a data subject is free; any follow-up requests may be charged.
- Right of Access by data subject - Again, as mentioned in the logging bullet point, the data subject has a right to see their own information. There can be no restrictions on access, intentional deletion, or denial of data.
- Right to rectification - The data subject has the right to correct, or change, their information if they feel it is incorrect.
- Right to be forgotten - the data subject has the right to insist on the total and complete erasure of their data. There are exceptions to this, but they mostly concern the health industry and the criminal justice system.
- Right to restriction of processing - the data subject has the right to restrict processing or prevent specific entities from accessing GDPR data.
- Notification - the data subject has every right to be notified as soon as possible for any issues or loss of their data, and the company does have a limited amount of time to ensure this happens.
- Data Portability and Storage - You may only keep GDPR data for as long as you legitimately need it. Retaining data longer puts your company at risk and violates GDPR.
- Right to object - The data subject has the right to object to the reason for processing or storage.
- Right to object to automated Processing - The data subject has the right to object to programs or artificial intelligence making decisions affecting the data subject.

At the time of this writing (2016), 70-80% of USA-based businesses and over 50% EU/UK businesses are not ready.

At the time of this update (2025), a large majority of companies are not compliant and are simply hoping they never get on the GDPR radar.  Those who are the most ready have been preparing for over 2 years.

This means there is a potential for fines and penalties (including confinement). You will see companies going on a massive spending spree on more security-related appliances and services. The GDPR regulatory bodies are designed to be self-funding, meaning they will survive on fines, which means there will be an active search for GDPR violators.

You should also understand that GDPR is an overlay regulation. This means you could be fined under GDPR and then face additional country-specific fines.

So, should you be concerned that funding is based on fines, yes...ABSOLUTELY! The cost of compliance is far lower than the costs associated with sanctions. For example, we have already discussed how GDPR could impose a fine of up to $26MM or 4% of global gross revenue (whichever is higher). To add to that, there may be country/state/province laws that are more stringent and include criminal charges. For example, GDPR requires breach notification within 72 hours; however, Belgium requires it within 24 hours. GDPR indicates 30 days to respond to a data subject request; however, Ireland indicates 21 days. Belgium imposes an additional 800,000 Euro fine for failing to register as a controller (Germany imposes a 50,000 Euro fine, and Ireland imposes a 100,000 Euro fine). GDPR doesn't necessarily indicate a statute of limitations; however, Ireland does. GDPR indicates tough cookie or spam requirements, and they can only get tougher with an extra 800,000 Euro fine from Belgium if you are located there. The UK requires a warrant to enter premises for investigating a data protection incident. Yet, the GDPR doesn't require one, and Germany and Ireland specifically DON'T require a warrant, provided it is during business hours.

What happens if you get caught? Naturally, you should immediately show an "attitude of compliance" and offer your complete support in their investigation. Even if this results in temporary downtime or a loss of productivity, you should show that you are "very concerned" and are willing to offer any support needed to expedite the closure of the investigation. Remember that the Supervisory Authority must also adhere to timelines. If you slow down the investigators, they will have to deal with that, which is likely to increase the level of discomfort in the investigation greatly. The short story provides the absolute best example of compliance and cooperation possible. Hold nothing back and keep no secrets from the investigators. Let's not forget that you should also immediately alert your legal team.

You should also honestly ask yourself if you deserved to get caught. Did you prepare for GDPR? Did you even attempt to conform with GDPR promptly, or did you start to care 3-4 months before 25 May 2018? Do you honestly know you have areas that need improvement, but you just "haven't gotten around to it"? Can you effectively demonstrate that you truly care about protecting data and the lawful processing of that data? If you didn't make any attempts and simply hoped that the regulators would never find you, then you truly deserved to get caught. The protection of data should never be taken lightly; it should be treated with the utmost seriousness. The cost of compliance will always be less than the cost of sanctions. Think of it this way: if you leave your house unlocked and get robbed, the police or your insurance company will probably not look favorably on your lack of concern for protecting your valuables.

What happens if you receive sanctions? Well, first, the sanctions can be "up to" $26MM or 4% of global gross revenue (whichever is greater); however, that doesn't mean they will immediately jump to $26MM. For smaller companies, $26MM simply isn't possible and could put the company out of business. This means jobs will be lost, and families may be at risk. Aside from a situation where it is safer for the public for the company to be put out of business, it seems counterproductive for a government organization to make the unemployment numbers worse. This doesn't mean sanctions won't occur, just that the sanctions may be of a nature that effectively delivers the message of why they occurred without destroying the entire company. Your company should also consider negotiations and the use of any appeal process that may be available to help reduce the sanctions, or propose the possibility of paying any fines or penalties over time rather than all at once. Assuming none of that works, then you should figure out how you are going to pay those fines. The result is that if you don't pay the fine and are in the EU, then you will be prohibited from running your business. If you are outside the EU, you may be prohibited from processing any EU data at all, which could have a greater impact on your company than just paying the fine. Additionally, you will have to deal with reputational and political risks related to customer trust. You will likely want to connect with a professional PR firm that specializes in mitigating potential damage. What you absolutely should not do is portray anything less than the truth to your customers. GDPR and various country laws will require disclosure to affected individuals; however, you should be upfront and proactive about the situation and handle the issue in a positive, proactive, and honest manner. The result is that if you are not willing to sacrifice all business opportunities with numerous first-world, industrialized, and wealthy countries, you should figure out how you are going to pay that fine. You should also understand any local country laws you may violate that could lead to criminal extradition proceedings, or simply know which countries you should avoid during vacation. Having said that, the EU is cooperative, so deciding not to go to Belgium, for example, due to criminal data protection laws being violated...may also put you in a position where you simply don't want to visit the EU at all for fear of being arrested in Spain and then sent to Belgium.

This article doesn't cover all aspects of GDPR; it focuses on the highlights. If you even suspect that you may have GDPR data, please get in touch with us. Arrakis has experience helping companies move toward GDPR compliance and can help you resolve your GDPR issues before they become serious. Arrakis has provided GDPR consultation to numerous Fortune 500 companies to help achieve this goal. Contact us today so we can help you help yourself!

Hear the GDPR interview with priceofbusiness.com here.

How Arrakis can help!

A rapid assessment that gives you high visibility of your environment to give you a rough understanding of your posture and potential risk. Generally lasts 3-5 weeks. The activities would involve 5-10 hour-long interviews and the review of current policies/standards/procedures, with everything wrapped up in an informative report.

A detailed assessment of your posture and potential risk. Deliverables will include a detailed report and an SOW for Arrakis support in remediation. The activities would involve 10-20 hour-long, detailed interviews; a review of current policies/standards/procedures; and a review of network topology maps, data flow diagrams, etc. Generally lasts 7-9 weeks.

Arrakis will provide detailed, informative support in remediation. Arrakis personnel will be of high quality with numerous years of experience and remediation projects under their belt, and generally of the "C" suite type.

We are masters at these frameworks and many more.

Our membership in professional organizations

Contact Us