With the forthcoming introduction of the EU’s General Data Protection Regulations (GDPR) in May 2018, there is now a definite move toward privacy by design, meaning organisations must build data security safeguards into processes, from beginning to end.
Organisations will become accountable for the Personally Identifiable Information (PII) they hold; they must know where it resides and how to secure it (at rest and in flight).
Data breaches must be reported within 72 hours of being detected. Organisations are liable for any breaches, with penalties of a maximum of €20 million or 4% of annual revenue, whichever is greater.
Under GDPR, data protection and processing safeguards must become part of the DNA of all systems and processes, with data protection by design based on seven “foundation principles”: