GDPR's Scariest Provision; You've Been Warned!
Courtesy of https://pixabay.com/en/regulation-gdpr-data-protection-3246979/

GDPR's Scariest Provision; You've Been Warned!

The entire world is wrapped around the European Union's Global Data Protection Regulations which become effective on May 25, 2018 (three days from the writing of this article.) . There are tons of rules businesses must follow under the GDPR and data subjects are recognized as having certain Rights to their data. From erasure to portability to correction. But there is one Right in the GDPR that should scare the crap out of all businesses: the Right to Compensation.

Under Article 82, Data Subjects, also known as private citizens, can bring civil actions against businesses regardless of where that business is located. Everyone is so focused on the governmental fines of 2% revenue and $20 million Euros that the Right to Compensation has gone almost unnoticed.

Article 82 is where the GDPR will be a bane for businesses around the world. I'm sure there are lawyers (barristers) just waiting to launch lawsuit after lawsuit in member states against all sorts of businesses. The burden of proof for such claims is rather simple: the business didn't erase the data subject's data or failed to correct an error amongst others.

The really scary part of Article 82 is the level of harm a data subject must show. It is practically non-existent. It allows for material and non-material harm to be considered in the penalty. Non-material harm includes things like anxiety, frustration, and distress. How do you place a value on those? We will find out shortly after the first cases are filed.

I'm not marketing any products or services so I don't consider this post the normal FUD (Fear, Uncertainty, and Doubt/Disorder.) Consider it more of a prediction of future events based solely on my opinion. I hope I can tell you in a few months that I was wrong. This is certainly one aspect of GDPR I would like to be wrong about! But I doubt it. So, consider yourself warned!

What can you do to avoid such cases? Follow the GDPR to the letter. Honor all requests received. Have a mechanism in place to handle and track such requests.

///Chris\\\

#GDPR #DataProtection #Datageddon #Privacy

要查看或添加评论,请登录

Chris Gebhardt的更多文章

  • Ferengi Rules of Acquisition as applied to Cybersecurity

    Ferengi Rules of Acquisition as applied to Cybersecurity

    My wife bought me the Ferengi Rules of Acquisition (RoA) book for Christmas this year. I'm sitting at my desk now…

    4 条评论
  • #10in20. Helping 10 People in Cybersecurity in 20 Days.

    #10in20. Helping 10 People in Cybersecurity in 20 Days.

    I am going to help 10 people in the next 20 days. I hope others will follow as well.

    6 条评论
  • SolarWinds Smacks Back: Poorly IMO

    SolarWinds Smacks Back: Poorly IMO

    #SolarWinds has posted a public reply to the #SEC saying the SEC is basically clueless to cybersecurity requirements…

    1 条评论
  • Head on a Swivel from "SWAT Team Skills for Cybersecurity"

    Head on a Swivel from "SWAT Team Skills for Cybersecurity"

    An abbreviated excerpt from my upcoming short book titled: "SWAT Team Skills for Cybersecurity." Please share your…

    2 条评论
  • Quirky Notes about the CMMC

    Quirky Notes about the CMMC

    Having wrapped up my training for the Certified CMMC Professional credential, I found myself dwelling on some of the…

    2 条评论
  • Security Preparedness (not Awareness) Training

    Security Preparedness (not Awareness) Training

    The world has adopted a term that drives me nuts: Cybersecurity Awareness Training. We've all been through the training…

    6 条评论
  • #Cybersecurity Failure is 100% a People problem.

    #Cybersecurity Failure is 100% a People problem.

    #Cybersecurity failure is 100% a People problem. More correctly, it is a single person problem often times.

    6 条评论
  • DevSecOps is a Process not a Person

    DevSecOps is a Process not a Person

    DevSecOps is a fast growing trend introducing a confluence of Software Development, Cybersecurity, and Infrastructure…

    3 条评论
  • TransUnion is Failing Cybersecurity

    TransUnion is Failing Cybersecurity

    As a victim of the #CapitolOne breach, I received free credit monitoring through @TransUnion "mytrueidentity" service…

    2 条评论
  • CapitalOne Hack Explained: What's in your Bucket?

    CapitalOne Hack Explained: What's in your Bucket?

    Lots will be talked about surrounding the CapitalOne hack. The sheer volume of names involved is generally the lead…

社区洞察

其他会员也浏览了