Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article

Skip to comments.

GDPR – How To Comply – What To Expect – And How To Work With Those You Serve.
IWB ^ | Ruby Henley

Posted on 05/21/2018 12:10:52 PM PDT by davikkm

www.superoffice.com/blog/gdpr/

Companies tell you that they collect this type of information so that they can serve you better, offer you more targeted and relevant communications, all to provide you with a better customer experience.

But, is that what they really use the data for?

This is the question that has been asked and answered by the EU, and why in May 2018 a new European privacy regulation called GDPR will be enforced and permanently change the way you collect, store and use customer data.

In a study of more than 800 IT and business professionals that are responsible for data privacy at companies with European customers, Dell and Dimension Research found that 80% of businesses know few details or nothing about GDPR.

But, perhaps worst of all is that 97% of companies don’t have a plan in place for when GDPR kicks off in 2018 (Tweet this!).

(Excerpt) Read more at investmentwatchblog.com ...


TOPICS: Business/Economy; Government; Politics
KEYWORDS: blogtrash; gdpr; rubynuttery; uslesscrap

1 posted on 05/21/2018 12:10:53 PM PDT by davikkm
[ Post Reply | Private Reply | View Replies]

To: davikkm

EU regulations.

All our systems are located and operated in the US.

They can go pound sand.


2 posted on 05/21/2018 12:15:09 PM PDT by ConservativeWarrior (Fall down 7 times, stand up 8. - Japanese proverb)
[ Post Reply | Private Reply | To 1 | View Replies]

To: davikkm
But, is that what they really use the data for?

I'd ask someone better qualified than Ruby the nutcase blog writer.

3 posted on 05/21/2018 12:19:33 PM PDT by humblegunner
[ Post Reply | Private Reply | To 1 | View Replies]

To: ConservativeWarrior

Quite wrong.
Any organization anywhere that collects, creates, manages, uses, transfers or stores EU citizen personally identifiable data, is subject to GDPR data subject rights laws.
Our own FTC is one of the regulatory agencies that will aid prosecution of GDPR violations.
See IAPP.org to get a better under standing of GDPR and compliance.

RE:
“EU regulations.
All our systems are located and operated in the US.
They can go pound sand.”


4 posted on 05/21/2018 12:43:52 PM PDT by MarchonDC09122009 (When is our next march on DC? When have we had enough?)
[ Post Reply | Private Reply | To 2 | View Replies]

To: MarchonDC09122009

We have no EU weenie data in our systems.

So again, they can go pound sand.


5 posted on 05/21/2018 12:47:17 PM PDT by ConservativeWarrior (Fall down 7 times, stand up 8. - Japanese proverb)
[ Post Reply | Private Reply | To 4 | View Replies]

To: ConservativeWarrior

That’s good.
Complying with GDPR is very challenging.


6 posted on 05/21/2018 12:56:12 PM PDT by MarchonDC09122009 (When is our next march on DC? When have we had enough?)
[ Post Reply | Private Reply | To 5 | View Replies]

To: ConservativeWarrior

So you have to comply with PCI (and/or HIPPA?)

All of them are confusing, and make for incredibly well paying consulting and certification jobs.

Mark


7 posted on 05/21/2018 6:28:32 PM PDT by MarkL (Do I really look like a guy with a plan?)
[ Post Reply | Private Reply | To 2 | View Replies]

To: MarchonDC09122009; ConservativeWarrior
Complying with GDPR is very challenging.

You're not kidding there! I've been through some GDPR training, and in it, there were 2 very similar situations, where I got the testing answer wrong,. The difference had to do with whether or not the web site had a conversion capability for dollars to euros. In once case, where the customer could choose to convert his purchase amount from dollars to euros, even though they did not market to the EU or have facilities in any EU country, they still had to comply with GDPR. Removing the ability to convert the dollar amount from the web site removed the requirement.

Any of the PII security certifications is very difficult and time consuming to implement and requires constant certification, testing, and auditing.

Mark

8 posted on 05/21/2018 6:40:02 PM PDT by MarkL (Do I really look like a guy with a plan?)
[ Post Reply | Private Reply | To 6 | View Replies]

To: MarkL

We need to comply with SEC/FINRA regulations. Less well-defined than HIPPA or PCI, but very similar. Think NIST guidance.

We maintain SSAE18 SOC 2 Type 2 certification, which seems to be enough of a challenge for us.

One of our Verizon data centers was recently acquired by IBM, and they came at us with all kinds of paperwork to sign. One form was GDPR compliance. We refused to sign, as we have no EU involvement whatsoever.

They persisted for about 3 months before we finally told them that we’d end our contract with them if they didn’t stop trying to force their one-size-fits-all global contracts on us.


9 posted on 05/22/2018 4:55:15 AM PDT by ConservativeWarrior (Fall down 7 times, stand up 8. - Japanese proverb)
[ Post Reply | Private Reply | To 7 | View Replies]

To: ConservativeWarrior

If your systems have data of EU citizens, then they need to comply.


10 posted on 05/22/2018 6:29:56 AM PDT by Cronos (Obama's dislike of Assad is not based on his brutality but that he isn't a jihadi Moslem)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Cronos

Agreed, but we don’t have any EU citizen data in our systems. We only conduct business with US citizens. Period.


11 posted on 05/22/2018 6:58:17 AM PDT by ConservativeWarrior (Fall down 7 times, stand up 8. - Japanese proverb)
[ Post Reply | Private Reply | To 10 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson