Cyber Week Sale! 50% Off All Access

The New EU General Data Protection Regulation: Big Data Protection Gets Personal The stage for profound repercussions to digital privacy is set. Here's how it affects you:

By Dimitri Sirota

Opinions expressed by Entrepreneur contributors are their own.

You're reading Entrepreneur India, an international franchise of Entrepreneur Media.

The adoption by the European Parliament of the General Data Protection Regulation (GDPR) sets the stage for profound repercussions to digital privacy on both sides of the Atlantic. The GDPR is a prominent example of new wave of global privacy regulations that is forcing business to rethink how they collect, manage and govern access to personal data. And unlike past generations of legislation, GDPR provides organizations ample motivation to perform; failure to comply could result in penalties as high as 4% of global revenue.

The regulation's broader intention is to galvanize a new, integrated approach to data protection that drives transparency and puts privacy on an equal footing with information security. Transparency is not just an operational requirement — it also means that organizations will have to maintain intelligence into their use of private data, ensure usage compliance as well as regularly verify their data protection and privacy policies.

Getting Past Good Intentions

Many organizations have already initiated governance programs to manage how data about their customers and consumers is processed and accessed in anticipation of more stringent data privacy and data residency requirements (especially with advent of Privacy Shield and the demise of Safe Harbor). The implicit assumption in the GDPR provisions is that these incremental efforts won't be sufficient. Doing your best with the current approach will not be enough.
Instead, GDPR exacts very specific requirements around how personal data is collected and processed. Rather than accumulate data with the expectation that at some point in the future it will help to drive insights into revenue generation opportunities or uncover potential operational efficiencies, the GDPR is structured on the assumption that organizations will know beforehand why they are collecting customer and consumer data.

At a point when many organizations have taken advantage of new technologies to amass literally petabytes of data about customer and consumer behavior, the GDPR mandates that organizations only process and collect the data needed to support a service. This requires new levels of understanding for what data is collected, where it resides and how it is consumed by applications and data scientists.

It also places greater focus on consent. The Regulation described a "purpose limitation', which stipulates that "Only personal data necessary for each specific purpose of processing are processed". In the language of the Regulation, any other operations on the data that are not consistent with the initial justification for collecting the data is referred to as an "incompatible purpose', unless the data controller can show there is a legitimate interest. The GDPR stipulates
informed consent to collection of personal data, with the requirement for either "a statement or a clear affirmative action" — an emphatic shift away from the implied consent model.

Further complicating matters for privacy, compliance and risk officers is that all the new rules and requirements apply to a more rigorous definition of what is personal data. It has long been common practice for organizations to "de-identify" data before it is analyzed. However the threshold for successfully removing direct or indirect identifiers in data has in recent years proven to more challenging as researchers have shown an ability to re-identify previously assumed anonymous data. For this reason, under the new GDPR regime it will be critical for organizations to not only classify what is personal data accurately but also score the degree of identifiability to control how different data is shared and analyzed.

Operationalizing Privacy

It's not entirely alarmist to speculate that the GDPR will force organizations to re-engineer their privacy practices for Big Data. Certainly, new technology and processes will be necessary to manage privacy and monitor compliance for GDPR before it becomes binding in two years' time. Given the significant penalties for failing to do so however, the EU likely has the necessary stick to change corporate practices around privacy.

What is clear with the passage of GDPR is that organizations will now need to prioritize privacy like they previously did security. Modern business is built on personalized service. But with personalization comes an equal responsibility to ensure and document privacy protection. GDPR is a clarion call to business that personalization without privacy is not just bad, it's illegal. Operationalizing privacy from data discovery through data governance will require new thinking around Big (personal) Data.

Dimitri Sirota

CEO & Co-founder BigID

Dimitri Sirota is a 10+ year privacy expert and identity veteran. He is currently the CEO & Co-founder of the first enterprise privacy management platform, BigID –and wears many hats as an established serial entrepreneur, investor, mentor and strategist. He previously founded two enterprises software companies focused on security (eTunnels) and API management (Layer 7 Technologies), which was sold to CA Technologies in 2013.
Leadership

How to Master the Art of Delegation — Lessons From Andrew Carnegie's Legacy

Here's what Andrew Carnegie can teach today's entrepreneurs about leadership, teamwork and effective delegation.

Science & Technology

You Have 1 Month Left to Prepare for These 5 AI-Powered Marketing Changes — Act Now Before It's Too Late.

Big changes in 2025 will redefine marketing as AI evolves rapidly, offering growth opportunities but also risks. Learn how to stay ahead in this week's video, covering new search platforms and avoiding over-automation.

Business News

Google CEO Sundar Pichai Says 'You'll Be Surprised' By How Google Search Changes Next Year

AI has already changed the look of search, but Google's CEO says there are more changes to come.

Growing a Business

This Breakthrough Technology is Poised to Accelerate Your Company's Growth

Discover a breakthrough technology stacked on top of generative AI, now poised to revolutionize businesses across nearly every sector. Unlock unprecedented growth and profitability potential, achieving levels once thought unattainable.

Side Hustle

'I Just Hustled': She Earned More Than $300,000 Wrapping Gifts Last Year — and It All Started With a Side Hustle

When Michelle Hensley lost her husband to cancer, she needed to figure out how to earn an income for her family.