By: Drew M. Smith
This piece of legislation came about as fear of data loss increases across Europe. This legislation, passed in 2016, updated their privacy laws. Corporations now must meet a certain standard in protecting consumer privacy and protection. However, that standard is much higher than most companies expected and it is also much higher than in the U.S. This has led many companies to scramble to put together a plan to protect this information. The infrastructure, the personnel required and the training will cost companies hundreds of millions of dollars to meet this.1
GDPR is an evolution of a previous data law that was passed over 20 years ago. In the wake of multiple breaches across the continent, many people were concerned about the loss of their personal data. This new regulation only covers their personal data, or what the U.S. calls Personal Identifiable Information (PII). It also requires the following:
There is a monetary incentive to adapting to this new regulation. Most people will not want to work with a company that’s had a recent breach. According to one report, “Seventy-two percent of US respondents said they would boycott a company that appeared to disregard the protection of their data. Fifty percent of all respondents said they would be more likely to shop at a company that could prove it takes data protection seriously.”
A key point to this legislation is that it affects any company doing business in the EU that concerns personal data, not just those based in the EU. That means international businesses must comply with the regulation, including those that don’t have a physical presence but works with personal data from Europe. As a result, many American and Asian companies might be hesitant to expand in the Union if they must abide by these rules. 68 Percent of U.S companies would be expected to spend between $1 Million to $10 million with another 9 percent being forced to shell out more than $10 million.
This regulation coming into effect should prompt people to look at their cyber coverage and their general liability coverage. With this regulation forcing companies to add additional security, programs concerning cyber liability should be updated to compensate for the changes. Always make sure data is secure with correct security patches and vigilant surveillance.
For more information about privacy risks and insuring them, click here.
1https://www.csoonline.com/article/3202771/data-protection/general-data-protection-regulation-gdpr-requirements-deadlines-and-facts.html
2https://www.varonis.com/learn/what-is-eu-gdpr/