Tag: Data Protection

Tag: Data Protection

Data Retention – A €14.5million fine awaits for Real Estate Data Archive non-compliant with GDPR?
05/11/2019 DPO Blog, Security Advisory Blog admin

Data retention is always a challenge for organisations. Organisation just love retaining data and well, storage is pretty cheap these days. Whilst the costs of getting retention wrong (e.g. not being able to recover from a ransomware attack) are always high; a recent GDPR fine decision in Germany highlights the data retention problem could get

Read More
Public Information & GDPR – I can do what I like with it…wrong!
28/10/2019 DPO Blog, Security Advisory Blog admin

There seems to be this idea floating around that if the data is collected from publicly available sites then it is fair game for marketers. If someone has created a profile on LinkedIn for example and their email address can be harvested (say by a recruiter or data miner connecting with you) then this public

Read More
Cookie consent after C-673/17 – To Consent or not to Consent…
02/10/2019 DPO Blog, Security Advisory Blog admin

Firstly, this is legal information about cookie consent, not legal advice… The judgement of the CJEU case C-673/17 is now doing the rounds and as one has come to expect when it comes to Data Protection recently, there is a lot of hot air and bluster about what the ruling means. Is this some form of paradigm shift in

Read More
Climate Change Solved: GDPR mitigates climate change risk!
01/10/2019 CISO Blog, DPO Blog, Security Advisory Blog admin

Whether you believe climate change is a real thing or not there is no arguing 16-year-old Greta Thunberg is making headlines. Her efforts to raise awareness about this key issue of our time are pretty impressive. Whilst some people don’t think climate change is real, as a person who believes in evidence-based decision-making, I am going to pin my colours

Read More
Technical Debt: A Cautionary Tale!
19/09/2019 CISO Blog, DPO Blog admin

Once an organisation understands the technical debt borrowed by its project managers the more likely projects will deliver the expected outcomes.

Read More
Risk Management: Stop – you’re too controlling!!!
22/07/2019 CISO Blog, DPO Blog, Security Advisory Blog admin

What appears to be a well-intended improvement to reduce risk being completely unused because it was poorly envisaged, poorly implemented, with the original control measure still to be decommissioned and so that control is still being used whilst the new control is to all intents and purposes gathering dust.

Read More
CCPA & GDPR: Two Nations Divided by a Common Language
15/07/2019 DPO Blog admin

With six months to go before the California Consumer Privacy Act CCPA goes live in California, it seems we are progressively moving towards common ground when it comes to international privacy law…or are we…?

Read More
Are the big GDPR fines finally coming into land – and does it matter?
08/07/2019 CISO Blog, DPO Blog admin

So what was my prediction? Well, based on previous major data breaches (such as the TalkTalk breach) I hypothesised that, it seems to take the ICO around 12-18 months from a major incident occurring, to the ICO carrying out an investigation and subsequently issuing a fine…and then of course the inevitable appeal wrangling for reduction of the original fine amount. Therefore, if there were to be an in-scope breach on the 26th May 2018 it would likely be between May and November 2019 before a large fine would be finally agreed.

Read More
Data Protection – ‘The Knowledge’​ – Is your DPO incompetent?
03/07/2019 DPO Blog admin

This article looks at the different approaches organisations can take when assessing the competence of potential DPO candidates.

Read More
GDPR Process Inventory – 7 items to record
12/04/2018 DPO Blog admin

As a Controller, it is pretty challenging to meet the requirements of GDPR without great records detailing where, what and how personal data is processed. If you’re an organisation with more than 250 employees, there is a requirement to document your processing activities (See Article 30) but if you’re one of those organisations with less than 250 people, then you have a [partial] get-out-of-jail card. The thing is, even if it’s not mandatory, it’s still incredibly useful to document processing activities. This will help you comply with all the other aspects of GDPR you are still ‘on-the-hook’ for. In this brief article, we will look at 7 items which all organisations – small or big – should (or in certain cases must) include in an inventory of their processing activities.

Read More