Sie sind auf Seite 1von 6

How to prepare for the GDPR

and turn it from foe to friend


The EUs new General Data Protection Regulation (GDPR) aims
to align the privacy regulatory environments in Europe. Many
organizations are uncertain about how to cope with the requirements,
and see the new regulation and its penalties as a threat. This guide
shows how to turn GDPR from foe to friend.

nexusgroup.com
contact@nexusgroup.com
Guide
How to prepare for the GDPR

How to prepare for the GDPR


and turn it from foe to friend
The EUs new General Data Protection Regulation (GDPR) aims to align the privacy
regulatory environments in Europe. Many organizations are uncertain about how
to cope with the requirements, and see the new regulation and its penalties as a
threat. This guide shows how to turn GDPR from foe to friend.

GDPR enters into application May 25, impact assessment, which states what
2018. The regulation is complex and personally identifiable information (PII)
intertwined with other regulations and is collected and how that information is
laws, but the 6 pillars of the GDPR are: maintained, protected and shared.

The right to be forgotten. Consent.


Organizations have to erase personal If personal data is to be collected,
data at the subjects request, without organizations have to get valid and
undue delay. explicit consent from the individuals.
The organizations must also be able to
Privacy by design. prove that they have gotten consent.
Systems and technology across the
organizations need to be designed Individuals may withdraw their concent.
to limit data collection, retention and
accessibility. Parental consent is required if personal
data is to be collected about children
Breach notifications. under the age of 16.
Organizations have to notify the
supervisory authority about data Data portability.
breaches involving personal data no later Upon request, organizations have to
than 72 hours after becoming aware of provide individuals with their personal
the breach. data in a structured and commonly used
format.
Users have the right to be informed
about data breaches involving their Organizations that fail to have the
personal data. routines and documentation in place that
GDPR requires can get fines of up to 2%
Risk and impact assessments of their global revenue. Serious breaches
Organizations have to perform a privacy against the regulation can lead to fines of

nexusgroup.com
contact@nexusgroup.com 2
up to 4% of a companys global revenue. 3. Understand the security organization
This has created great attention all and systems you have today. If you do
the way to the top management in not follow basic security practices like
organizations handling personal data patching of software or having firewalls
about EU citizens, which almost all in place, this has to be fixed as soon as
European organizations and many possible. It is advisable to follow a well-
organizations outside of the EU do. known scheme like ISO 27001, since it
makes the process smoother and also
GDPR is a good thing for the privacy of makes it easier to obtain a certification
the individual. It shifts the power to the at a later stage.
users: the service providers no longer
own the data about the individuals and 4. To protect sensitive data from
cannot do whatever they want with the peering eyes, username and password
data. is not enough. You need to use strong
authentication. Bear in mind that you also
But contrary to what many believe need to ensure strong authentication
GDPR can also be beneficial for most when you delete a customer and their
organizations. If an organization does data imagine what happens if you
not know where its data is or have wrongly erase data belonging to another
insufficient security and access controls person. Organizations in the Nordic
in place, it is running a risky business. countries may choose to let their users
Organizations fulfilling the requirements authenticate with their nation-wide
given in the GDPR will have better electronic identities (eIDs), such as
control, better security and run less BankID, NemID and Tupas. The benefit
operational risk. You can also choose with using these eIDs is that you serve
to take the opportunity to make the your users with their familiar login and
interactions with your external users document signing mechanisms, which
more frictionless, as well as making your can remove much of the user friction and
internal users work easier. support issues expected to follow the
new regulation.
GDPR does not need to be a foe for
organizations. By following the to-do list 5. Understand and document the
below, you will turn GDPR into a friend. necessary changes you need to do on
both the technical and the business side.
1. Appoint a person, who knows your Examples on the technical side can be
business and your technology landscape, what you have to do to be able to delete
to be your organizations own GDPR information upon request, improve
expert. access control to data and servers, and
encrypt sensitive data. On the business
2. Make sure you understand your side you need to look into how you
current regulatory environment. In cases handle communication, how you are to
where GDPR and your current regulatory get informed consent from users, and
environment contradicts, you need to how you are going to present, move and
follow the existing laws and regulations. delete personal data in a secure manner.

nexusgroup.com
contact@nexusgroup.com 3
6. The GDPR requires you to make risk - Have implemented routines and
and vulnerability analysis for sensitive supporting technologies that restrict
data. This also means that you have to access to personal data.
classify the data.
- Can prove that you follow the GDPR.
7. Document how you are going to
follow the regulation. Start early a - Know what you can expect from your
data protection agency (uncomfortably) partners and what responsibilities you
near you may very well ask for the cannot outsource.
documentation sooner than you think.
- Have upgraded the overall security of
8. Go through all vendor agreements your organization.
and make sure the vendors are
contractually bound to comply with the Living up to the GDPR is not an easy task,
GDPR requirements. To make sure that and it involves a lot of different disciplines
the vendor (and the vendors vendors) and people. An important part of solving
operates in Europe is very likely a good the compliance puzzle is to choose the
idea. Choosing a cloud-based service right supporting technologies.
outside Europe may even be illegal in
some cases, so local cloud providers may Identity and security company Nexus
very well win over global giants in the Group can contribute to your GDPR
next few years. compliance by providing the following
technologies:
9. Restricting access to sensitive data is
not just about managing digital access - Everything you need to issue and
managing physical access to buildings manage identities across your entire user
and server rooms is also important. A base. This includes internal users needing
hot tip is therefore to get an identity access to your buildings, rooms, computer
and access management (IAM) system systems, and cloud applications, as
in place. For the sake of security, well as all of your external users, such
consistency and manageability, you may as customers, citizens and partners.
want to choose a system that manages Handling this in one single system is a
both the physical and digital world in one tremendously efficient way of enforcing
system. Look for a system that integrates and documenting the policies you need to
with all your physical access control have in place in May 2018.
systems (PACS) and manages all digital
identities for people, software and things - Tools to enforce your policies for
(internet of things, IoT). digital and physical access across your
organization. We can help you replace
cumbersome password policies with easy-
Following the to-do list above means to-use strong authentication on multiple
that you: platforms. We enable fine-grained, role
- Know what data you have and where based authorization and single sign-on,
your data is. and we also offer products for physical
access control, such as access cards and
- Have identified your risks and card readers.
vulnerabilities.

nexusgroup.com
contact@nexusgroup.com 4
- The ability to log everything that GDPR you are not only making GDPR
happens in the systems and to see who your friend you are making yourself a
has access to what, which is important better friend of your users too.
for auditing purposes.
GDPR might not be your most easy-
- Digital signing, which makes the going friend, and with all the work and
process of delivering and deleting cost this friend brings to the table you
personal information upon request might have enjoyed another friends
smoother and more automated. company more. But since this friend has
invited themselves, you better make
Nexus believes in making life as easy the most of the situation and turn it
as possible for your users, both internal into something positive for both your
and external. By choosing the right organization and your users.
supporting technology to live up to the

nexusgroup.com
contact@nexusgroup.com 5
About Nexus Group
Swedish-owned Nexus is an innovative and rapidly growing product
company that develops identity and security solutions.
Our technology makes it cost-efficient and user friendly to protect
e-commerce or internet banking, protect electronic services in the public
sector, manage physical and digital access, secure entry, and protect
communication between devices.

The very basis of all security, both physical and digital, is the creation,
management, and control of identities. We have made identities that
are reliable for people, software, and devices since 1984, and our
technology today is relied upon by a large number of organizations
and 100 million end users around the world. We are 300 employees at
15 offices in Europe, India, and the US, and we have a global network
of partners.

Contact us Social media


Tel: +46 8 685 45 60
E-mail: contact@nexusgroup.com

Das könnte Ihnen auch gefallen