dcsimg

How to respond to a data breach

Under the EU GDPR (General Data Protection Regulation), organisations must report personal data breaches to their supervisory authority within 72 hours of discovering or becoming aware of it. You might think that’s an impossibly short deadline, but don’t fear, you’re not expected to provide a comprehensive report at this stage. The process is simply to ensure that organisations are aware of … [Read more...]

Finding the right candidate to be your DPO

Complying with the EU GDPR (General Data Protection Regulation) is mostly about hard work and organisation, but there’s also a little bit of luck involved – at least when it comes to appointing a DPO (data protection officer). The position, which is mandatory for many organisations under the GDPR, has caused a massive spike in demand for data protection experts. Unless the perfect candidate falls … [Read more...]

Online anonymity has allowed cyber crime to thrive

Online anonymity is a complicated topic. There’s no doubt that the elasticity it gives our identities is a massive benefit. We can explore different sides of our personality without affecting the reputation of any other part of us. Unfortunately, that’s also proven to bring out the worst in some of us, with people committing acts online that they would never do in person. Cyber bullying and mob … [Read more...]

Norwegian study finds Google and Facebook manipulate users to share data despite GDPR

A recent study by the Norwegian government has found that Facebook and Google push users to share private information by using “invasive” and limited default options. The Norwegian Consumer Council’s Deceived By Design report suggests that the tech giants’ privacy updates clash with the new GDPR (General Data Protection Regulation). In a statement, the council’s director of digital services, … [Read more...]

3 tips for maintaining GDPR compliance

For the past year or so, cyber security experts have been asking, with increasing concern, whether you’ve complied with the EU General Data Protection Regulation (GDPR) yet. Hopefully you have, but it’s important to remember that compliance isn’t a fixed state. It’s not a point you get to where you can stop and think “mission accomplished”. It’s something that needs to be achieved and maintained – … [Read more...]

Most GDPR emails are unnecessary or illegal

The majority of privacy policy emails sent by organisations in preparation for the EU General Data Protection Regulation (GDPR) were unnecessary, and some were even illegal, a number of data protection experts have said. The problem is with organisations’ interpretation of the GDPR’s consent requirements. Many believe that organisations need to obtain everybody’s consent again or else delete them … [Read more...]

The GDPR and junk mail

Lawmakers and journalists have made bold claims about the EU General Data Protection Regulation (GDPR) over the past few years. ‘It will mitigate the threat of cyber attacks’. ‘It will give individuals more control over their personal data’. ‘It will lead to strict punishment for poor data protection practices’. These are all true, or at least there’s ample evidence to suggest as much. But some … [Read more...]

Top tips for writing a GDPR-compliant privacy policy

After this past week, in which your inboxes were no doubt overloaded with emails about updated privacy policies, you might want a long break from those two words. But if your organisation didn’t contribute to the plethora of privacy policy epistles, you’re going to be stuck thinking about them a little longer. Organisations are required to update their privacy policy and share it with data … [Read more...]

Snapchat releases details of its GDPR compliance measures

Snapchat has announced changes to its privacy policy and user settings as it prepares for the EU General Data Protection Regulation (GDPR), which takes effect on 25 May 2018. Many organisations have downplayed the requisite changes as ‘tweaks’ to their policies, but Snapchat has made a point of emphasising its widespread alterations. The most significant revelation is that, unlike rival messaging … [Read more...]

9 steps to implementing ISO 27001

There are many reasons to adopt ISO 27001, the international standard that describes best practice for an information security management system (ISMS). It helps organisations improve their security, comply with cyber security regulations, and protect and enhance their reputation. But implementing the Standard takes a lot of time and effort. That should be obvious, at least if you believe the … [Read more...]