These are the top 5 concerns IT leaders have about the GDPR

Tom Allen
clock • 5 min read

The lack of clarity is making business leaders nervous

The General Data Protection Regulation (GDPR) comes into full force in May next year - but confusion is still widespread, and awareness is low. At one of Computing's free events for IT CIOs this month, we heard some of the top concerns the industry has about the new law.

Compliance

The right to be forgotten topped Computing's research into GDPR worries among IT leaders; once such a request has been made, companies will have 72 (business) hours to locate all of a user's personal data in their system. Clearly, that is easier said than done.

Several attendees thought that the system could be simplified by technology. One said, "My hope is that, from a technology point of view, we can apply something that will help us discover where data is and identify it… The onus is on IT for that bit of the GDPR." However, none of the group knew of any technology that would adequately fulfil this function.

Others supported the idea of driving data discovery with a process: having a clear system in place for what to do with personal data that is received (although it was acknowledged that that wouldn't help with existing archived data).

No attendees felt comfortable with the level of data discovery that they currently had.

Another recognised problem was BYOD: firms have no control over the data on their employees' own devices, even if it is personal information about their clients. One CIO expressed a reluctance to stop staff from using their own devices to take notes and pictures, saying, "One of the reasons we're a successful firm is because of that maverick nature." If devices are used in this way - and some attendees admitted that even they were guilty of doing so - then that data could be stored in the cloud.

The cloud

Under the GDPR, the personal data of European citizens must be kept within Europe, and can only be transferred out under certain conditions - but with the cloud, that suddenly becomes a very sticky issue. Who can say where a specific byte of data is kept when it's on Google Drive or Dropbox?

One CIO's company has already implemented a complete block on the public cloud: "There's no way I want anyone to be able to sit at home and log in from their home PC to their work OneDrive account and download the information [that] they want, willy-nilly. We've been paranoid about that for years." He added, "It's a shame because we moved to Office 365 and I look at all of the features of OneDrive that I want to embrace as much as I can, but I have to be really careful about how I do it."

Another attendee said that his company takes it on "a data-centric approach," allowing the use of the public cloud but blocking all personal data.

There was a shared hope that, like Microsoft with OneDrive, more companies would open dedicated European data centres.

 

You may also like
Regulation has made EU firms less data-hungry

Legislation and Regulation

GDPR has cut storage and processing

clock 21 February 2024 • 2 min read
Microsoft, Google and UK make moves on sovereign data storage

Privacy

EU and Big Tech have been negotiating over the handling of European data

clock 15 January 2024 • 3 min read
Most read
01

Intel splits in two, signs deal with Microsoft

22 February 2024 • 7 min read
03

Cambridge University hit by DDoS attack

20 February 2024 • 1 min read
05

Gemma: Google unveils open AI models

22 February 2024 • 3 min read

Sign up to our newsletter

The best news, stories, features and photos from the day in one perfectly formed email.

More on Finance and Reporting

Nvida revenues rise 265% on AI chips

Nvida revenues rise 265% on AI chips

Looks set to make Nvidia more valuable than Amazon and Alphabet

John Leonard
clock 22 February 2024 • 2 min read
Tech giants make big revenue waves: Meta and Amazon reach new highs while Apple faces setback

Tech giants make big revenue waves: Meta and Amazon reach new highs while Apple faces setback

Meta's market capitalisation skyrocketed to $1.16 trillion

clock 05 February 2024 • 3 min read
ServiceNow's strong Q4 results fuelled by AI growth

ServiceNow's strong Q4 results fuelled by AI growth

Subscription revenue exceeded estimates

clock 26 January 2024 • 2 min read