# Protecting GDPR Footprints Withinthe Financial Sector
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2017-10-11
Category: FINANCE
Category URL: https://financedigest.com/category/finance
Meta Title: Understanding GDPR Impact on Financial Organisations
Meta Description: Learn how the EU General Data Protection Regulation affects financial institutions and how to identify and protect personal data footprints within your
URL: https://financedigest.com/protecting-gdpr-footprints-withinthe-financial-sectorhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/fd111017-17-1736843403623-compressed.jpg)

**Author:** **Steve Durbin, Managing Director**, Information Security Forum (ISF)

[www.securityforum.org](http://www.securityforum.org)

It is no secret that the impending EU General Data Protection Regulation (GDPR) will impact every entity that holds or uses European personal data, both inside and outside of Europe. It starts from a position that says ‘citizens’ rights are paramount.’ But what does this mean for financial organisations?

Everyone from [business people to consumers](https://www.financedigest.com/trusting-in-trust-marks-enhancing-consumer-trust-in-your-ecommerce-business.html "Trusting in trust marks: enhancing consumer trust in your ecommerce business ") will have a GDPR footprint. Knowing what these footprints look like is the first step to [becoming aware of what the regulation means and the data](https://www.financedigest.com/becoming-data-ready-for-mtd-for-corporation-tax-aligning-vat-and-ct.html "Becoming data-ready for MTD for Corporation Tax: aligning VAT and CT") that it affects.

**Finding the Footprints in the Data**

GDPR affords new rights to EU residents over their personal information, regardless of where it is processed. This includes the right to be forgotten, how data can be used and, importantly, that it should be protected against unauthorised disclosure. It mandates that personal data [must not be transferred to jurisdictions that do not have equivalent data protection](https://www.financedigest.com/must-know-facts-about-the-protection-class-rating-on-your-home.html "Must-Know Facts about the Protection Class Rating on Your Home") laws, unless suitable legal safeguards are in place. This includes treaties, such as the EU-US ‘Privacy Shield’ and contractual protections to bind the recipient to the laws of the source country; for example, ‘model clauses,’ ‘binding corporate rules,’ or obtaining unequivocal consent to transfer from the individual.

Article 4 of the regulation [defines personal data as ‘any information relating to an identified or identifiable natural](https://www.financedigest.com/exponentially-innovative-slingshot-to-define-the-natural-food-preservatives-market.html "Exponentially Innovative Slingshot To Define The Natural Food Preservatives Market") person … such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical physiological, genetic, mental, economic, cultural or social identity of that natural person.’

It can include information obtained directly from someone, from other sources, and even inferred through processing or aggregation with other information.

Even if an individual’s name is removed, the data may still be personal in nature depending on additional information the organisation holds. For example, were the organisation to store a database anonymised with account numbers but also hold a separate [record](https://www.financedigest.com/record-number-of-migrants-arrive-in-britain-by-boat-on-a-single-day.html "Record number of migrants arrive in Britain by boat on a single day") of customer contact details that includes the account number, then both would be deemed personal under this regulation.

What must be remembered is that it does not just cover customer information, but also employee details; and not just electronic records- paper records stored in a filing [system or archive are subject to the new rules](https://www.financedigest.com/telehealth-monitoring-to-rule-the-the-transseptal-access-systems-market.html "Telehealth monitoring to rule the The Transseptal Access Systems Market") as well.

**Following the Footprints**

As explained above, GDPR is wide-reaching legislation that will touch on various data repositories within financial organisations that have [potentially](https://www.financedigest.com/delivering-on-the-potential-of-open-finance.html "Delivering on the potential of open finance") been gathered over many years. This will be further complicated by the evolving working practices. For instance, employees may have been utilising online data repositories to exchange data with colleagues, or even between their own devices.

Organisations will [need to follow these data trails to identify where information is stored and ensure it is adequately protected](https://www.financedigest.com/regulators-need-to-strike-the-balance-between-protection-and-strangulation.html "REGULATORS NEED TO STRIKE THE BALANCE BETWEEN PROTECTION AND STRANGULATION").

Looking internally is just one element.Arguably, any and [every business is sharing information](https://www.financedigest.com/repository-of-analysis-and-information-for-every-facet-of-the-hydroxymethylbutyrate-hmb-supplement-market-2021-2031.html "Repository of Analysis and Information for Every Facet of the Hydroxymethylbutyrate (HMB) Supplement Market 2021 – 2031") in some way, shape or form. Organisations will need to ensure that these third-parties are also working to apply the correct level of security to comply themselves.

One point that the [European Commission](https://www.financedigest.com/ftx-collapse-shows-urgent-need-to-finalise-eu-crypto-rules-says-european-commission.html "FTX collapse shows urgent need to finalise EU crypto rules, says European Commission") has made is that this legislation is not just about fining organisations for suffering a data breach, but instead to encourage them to make the right moves towards compliance. This means organisations [need to be able to demonstrate that they have taken reasonable steps](https://www.financedigest.com/british-pensions-step-up-multi-billion-pound-asset-fire-sale-as-need-for-cash-soars.html "British pensions step up multi-billion-pound asset fire sale as need for cash soars") to implement processes that allow them to identify personal information.  Moreover, they must show they have placed reasonable protection around personal information, including any shared with third-parties, prove that they can remove data in a reasonable timeframe if requested and be able to report a breach within 72 hours.

**Protecting the Footprints**

Data [protection is the combination of processes and technologies](https://www.financedigest.com/recent-technological-advancements-to-propel-growth-of-the-2k-protective-coatings-market-in-foreseeable-future.html "Recent Technological Advancements to Propel Growth of the 2K Protective Coatings Market in Foreseeable Future") that ensure personal data is processed in accordance with an individual’s wishes and the requirements of the law. Here are five steps to help financial organisations assess and [manage](https://www.financedigest.com/how-application-management-can-help-tackle-the-finance-industrys-carbon-emissions.html "How application management can help tackle the finance industry’s carbon emissions") these requirements:

**Determine applicability:** examine personal [data processing activities](https://www.financedigest.com/oil-slips-on-china-covid-curbs-weak-factory-activity-data.html "Oil slips on China COVID curbs, weak factory activity data") to determine if GDPR applies and, if so, identify the data, functions or business units who may process it. Should the organisation [share personal data](https://www.financedigest.com/world-shares-rise-u-s-yield-curve-inverts-after-strong-jobs-data.html "World shares rise, U.S. yield curve inverts after strong jobs data") with a third-party, it is still responsible for ensuring adequate protection is in place. Third party (processor) assurances should be requested ahead of next May’s regulation introduction.

**Evaluate controls:** implement specific, defined controls over personal data if the [number of records](https://www.financedigest.com/record-numbers-resign-in-france-as-bargaining-power-balance-shifts-labour-ministry.html "Record numbers resign in France as bargaining power balance shifts -labour ministry") exceeds a certain size, a certain level of sensitivity, or when processing of personal data is the main activity of the organisation.

**Assess capabilities:** GDPR stipulates a number of ‘outcomes’ and organisations need to make sure that they have the capabilities to achieve these requirements or, if needed, seek additional external support. For example source legal guidance, employ an independent audit to check controls, seek advice and/or [assistance from management](https://www.financedigest.com/virtual-assistance-to-pave-the-way-for-pain-management-devices-market.html "Virtual assistance to pave the way for Pain Management Devices Market") consultants, etc. There is also a wealth of information, such as ISF’s [_‘Preparing for the GDPR: Implementation Guide_](https://www.securityforum.org/research/preparing-for-thementation-guide/) _’_ for organisations to find practical advice and guidance.

**Understand consequences:** Failure to uphold information rights can carry a fine of up to 4% of the organisation’s group turnover or €20m, whichever is the greater. In addition,failure to implement the specified controls can carry a fine of up to 2% of the organisation’s group turnover or€10m, even if information rights have been upheld. Companies cannot underestimate the potential impact of an enforcement, which is just as significant – particularly if it requires an organisation to suspend [business activities](https://www.financedigest.com/euro-zone-business-activity-contracted-again-in-august-pmi.html "Euro zone business activity contracted again in August -PMI") whilst it remedies data protection problems. Not to mention the associated adverse publicity arising from a data protection incident. An organisation should ensure that these new consequences are reﬂected in risk assessments and mitigated by training,procedural, technical and legal controls.

**Prepare for compliance:** The GDPR will be enforced from 25 May 2018 and an organisation should understand which aspects of its preparations will – or will not – be in place by that [time so that they can plan](https://www.financedigest.com/sterling-plunges-to-all-time-low-in-scathing-appraisal-of-fiscal-plan.html "Sterling plunges to all-time low in scathing appraisal of fiscal plan") their implementations and mitigate residual risks if they are not ready.

To become compliant with GDPR could require an immense amount of effort, but the bolstered security could prevent a brand-destroying data breach. If the [worst were to happen](https://www.financedigest.com/so-you-have-the-dream-job-nice-car-and-big-house-but-is-your-lifestyle-sustainable-do-you-have-the-products-in-place-if-the-worst-were-to-happen.html "So you have the dream job, nice car and big house, but is your lifestyle sustainable? Do you have the products in place if the worst were to happen?"), the organisation would be able to demonstrate that it had acted responsibly and implemented reasonable protection, including evidence such as audit trails and vulnerability assessments, risk assessments, which demonstrate that the organisation and its senior management are taking their responsibility to protect sensitive information seriously. While it may not prevent a fine being levied, it should limit the amount imposed.

Rather than seen as an inhibitor, good data protection practices actively protect both brand and reputation and can ultimately [improve data quality](https://www.financedigest.com/av-power-conditioners-market-will-gain-traction-over-2026-owing-to-improvements-in-audio-and-video-quality.html "AV Power Conditioners Market Will Gain Traction Over 2026 Owing To Improvements In Audio And Video Quality"). It is an [opportunity to enable strategic change that can help the business grow](https://www.financedigest.com/title-homeopathic-veterinary-medicines-market-growing-at-a-cagr-of-5-business-and-future-opportunity-2031.html "Title: Homeopathic Veterinary Medicines Market Growing at a CAGR of ~5% | Business and Future Opportunity – 2031") – just don’t leave it until May 2018 to identify the data footprints in your organisation.

_ISF has published_ [_‘Preparing for the GDPR: Implementation Guide_](https://www.securityforum.org/research/preparing-for-thementation-guide/) _’ to provide organisations with the structured method needed to achieve sufficient levels of compliance._


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

