Are You Ready for The New European General Data Protection (GDPR) Law?

A new EU regulation, European General Data Protection Regulation(GDPR) [1] has been proposed to improve the data protection of individuals. This regulation is the subsequent to the 1995 directive. It was agreed on 17 December 2015 and its implementation starts from 2018.

All the EU-based organizations that work with personal data records of individuals come under this law. Data records include but not limited to name, email, contact number, photo, bank details, addresses, social media network posts, computer’s IP addresses and medical information; no matter if this information is private, professional, public or personal.

As you can imagine, every company will be impacted by this law.

We wrote another article on this topic to explain GDPR in more detail and the impacts it has to companies that operate mobile apps.

The following security rules are encompassed by the GDPR:

1. Right to Delete Data

The users need to provide an explicit permission to the companies for them to handle the personal data. The individual users have the right to get their data deleted, and all the companies who have any data related to the individuals will have to fulfill the request.

2. Data Portability

The users can ask the companies how they are using the data and how they are exchanging with other service providers e.g. mobile operators.

3. Data Breaches

All data breaches that can affect the privacy of an individual in any regard should be informed to the national authority by the companies. The companies also have to tell the individual about data breaches and advise the user on security measures such as changing the passwords, etc.

4. Privacy by Design and by Default

Companies are advised to design their information systems while keeping privacy and security in mind, especially cryptography, pseudonymization, and anonymization.

5. Data Protection Officer (DPO)

There should be a Data Protection Officer post in every company that has more than 250 employees. The officer will oversee the data security of the company, and it's recommended to have a full-time contractor or employee for this position. Companies with less than 250 employees also need to assign someone this role if they working with personal data records.

What does this mean for individuals and companies?

If any company doesn’t comply with the regulation and doesn’t integrate the security rules that the law has mandated to their security policies, then they are subjected to a fine of 2 % from their annual worldwide turnover or up to 1,000,000 EUR.

The impact of GDPR will be really interesting. Though all individuals will be happy that they will have same right on their personal data records, companies and organizations will have to integrate security rules, change organizational or business processess which are probably difficult tasks.

Every application gathers and processes data in one way or the other. Hence, the application developers will have to think about the security aspect of their apps. Today, we are facing severe application security failures. We recently wrote an article explaining why mobile apps suck in security. Fortunately, it is not necessary to reinvent the wheel and implement security measures from scratch. There are many companies who focus on security measures, and integrating a widely used and proven security solution is easy and more cost effective rather than building a new one.

Take this short survey https://teskalabs.com/surveys/gdpr to see if your organization will be impacted by GDPR.

Alternatively, contact us to know more about our application security platform and prevent major cyber threats related to the apps that can affect your organizational and user data privacy.

Reference

  1. https://www.dlapiper.com/en/us/insights/publications/2016/04/european-gdpr-are-you-ready

About the Author

Jiri Kohout

TeskaLabs’ VP of Application Security, Jiri Kohout, brings years of experience in ICT security, having served as the Chief Information Security Officer for the Ministry of Justice and Chief Information Officer for Prague Municipal Court. He cooperated with the Czech National Security Agency to prepare the Czech Republic cyber security law.


TurboCat.io

Data encryption tool for GDPR

More information


You Might Be Interested in Reading These Articles

Binary distributions of OpenSSL static libraries

The official source of OpenSSL software is the OpenSSL website. One can download OpenSSL source codes archives and compile them for a given platform. The compilation work can sometimes be quite tedious, especially for exotic platforms. We, at TeskaLabs, set up this page because we frequently compile OpenSSL for various platforms for our internal purposes and this may save some time to other developers.

Continue reading ...

development android windows ios security

Published on July 20, 2017

You Can Build Apps for the Apple TV, But Do You Know How to Do It Securely?

Apple will want to dominate the market for TV apps. To achieve this objective, it’s understandable that Apple makes it easy for app developers to create apps and games for the Apple TV platform using tvOS and profit from them just as they have already done so for the iPhone and iPad devices. Developers can leverage similar frameworks and technologies since tvOS is just a modified version of the iOS. They can even retrofit the apps that were previously developed for iOS to support the Apple TV’s tvOS.

Continue reading ...

mobile security

Published on June 29, 2016

A Warning about Zero-Day Vulnerability

A zero-day, also called zero-hour, vulnerability is a security flaw in the code that cyber criminal can use to access your network. Zero-day attacks call for new technologies built from the ground up for today’s advanced threat landscape. There is no known fix, and by the time hackers attack, the damage is already done

Continue reading ...

security

Published on May 12, 2015