GDPR breach notification: Time to focus on the requirements

Some large U.S. companies have been working behind the scenes on GDPR requirements for more than a year, but there's strong evidence that many have not been as diligent.

As U.S. companies scramble to meet the European Union's General Data Protection Regulation, security professionals question whether they can implement changes in time for the May 25, 2018, deadline. It's not clear whether they have the tools and processes in place to properly respond to the 72-hour GDPR breach notification requirement.

"I think the 72-hour time period is a really quick turnaround," said Bob West, CEO of consultancy Echelon One. "Even many of the banks I worked with on this were in a reactionary mode. And if the banks are reactionary, think about everyone else."

The mandatory 72-hour GDPR breach notification period has security professionals concerned because the U.S. has no national data breach notification requirement, and the hodgepodge of 48 state laws that exist typically require notification within 30 to 45 days. With potential sanctions and fines of up to $20 million or 4% of global revenue, companies are on alert.

GDPR replaces the Data Protection Directive of 1995. The GDPR breach notification requirement caught the attention of CISOs after the new regulations passed in April 2016, because compliance sets a high bar for data inventory, a defined risk management process and mandatory notification of the data protection authorities.

"Breach notification is a very big task and needs to have involvement from everyone inside the organization," said Neil Thacker, deputy CISO at Forcepoint, in a video interview last April, "Main GDPR Challenges for CISOs." In it, Thacker said, "CISOs need to get a very good understanding of data breaches and the data breach notification requirements, and make sure it is pervasive across the organization, so they are prepared to respond to security incidents."

Companies also need to be thinking about their vendors upstream and downstream. The result is that everyone is rewriting their contracts.
Carolyn Holcombpartner in PwC's National Data Privacy Practice

GDPR applies to any company that does business in Europe and collects the personally identifiable information of European citizens. And it's not only for large global companies; midsize businesses that have 250 or more employees must meet the GDPR requirements. Smaller companies are exempt, however, unless the data processing is "likely to result in a risk to the rights and freedoms of data subjects, … is not occasional, or the processing includes special categories of data … relating to criminal convictions and offenses."

Many global banks reached for comment declined.

However, one large U.S.-based bank said it has been preparing for GDPR for about a year now. The bank, which requested to remain anonymous, has assigned a governance team of senior level people across departments.

When asked about the GDPR breach notification requirement, a spokesperson for the bank said that they were not worried about it: "As a financial institution, we are accustomed to notifying regulators and have the existing infrastructure to respond," in part because the banking industry has been heavily regulated since the 2007-2008 financial crisis.

What's the norm?

International banks have more resources than most organizations, so they may be more likely to have the people and processes in place to meet the 72-hour GDPR breach notification period and the vast majority of the GDPR regulations.

But that's not the norm. Last fall, a PwC study found that 36% of companies surveyed have only recently started the assessment process. This means that they have just started with GDPR compliance. The reality is that many of these companies have no chance of being compliant when the regulations go into effect this May.

Carolyn Holcomb

Carolyn Holcomb, a partner in PwC's National Data Protection & Privacy Practice, pointed out that CISOs need to understand that the EU is serious.

"Failure to comply with the new regulations may result in hefty fines of up to 4% of global revenues," she said. "Companies are also going to have to prepare for the reality that employees and consumers will also be able to file class-action suits against them for noncompliance. Companies also need to be thinking about their vendors upstream and downstream. The result is that everyone is rewriting their contracts."

Moreover, the EU is likely to impose a hefty fine against a major company not long after the new regulations go into effect, security experts warned.

"I think the EU will make an example of a company within the first 90 days," consultant West said.

Bob West

"A lot of people are burying their heads in the sand, thinking that GDPR doesn't apply to them," he said. "Many are just taking the chance that it won't be them that gets hit with the fine. But anybody doing e-commerce over the web has to take a serious look at GDPR.

"Much of the problem is a lack of education," he added. "Security people have many priorities today, and many have just not found the time to focus on this."

Technology's role in compliance

Enterprise Strategy Group senior analyst Jon Oltsik concurred with West that the EU will make an example of a large global company by late summer 2018.

Given this backdrop, he advised companies to focus on the positive aspects of GDPR and take the opportunity it presents to formalize incident response plans. As a general rule, organizations that have met most of the International Organization for Standardization information security requirements should be in pretty good shape.

"Many companies have formal disaster recovery plans for events like a hurricane," Oltsik said. "What can happen is that people will get scared and just start buying products. Unfortunately, too many companies waited until now to focus on GDPR, and their service providers can't really help them."

Jon Oltsik

On the technology front, Oltsik said organizations need to have a broad-based security posture to comply with GDPR, underscoring that GDPR protection "doesn't come in a kit." Data loss prevention will be important, as well as encryption, key management and user behavior monitoring -- all technologies that work to secure and protect against unauthorized access to sensitive information.

DLP software can handle data classification and discovery, while analytics can eliminate much of the manual work and give security teams pertinent information quickly. "That kind of data can get very noisy," said Oltsik, who noted some vendor partnerships. "The analytics sits above the DLP and distinguishes between the noise and truly suspicious behavior."

The "right to be forgotten" is an important part of the GDPR requirements. This means that consumers will have the right to ask that their data be erased. Companies will need tools that can document that certain files were erased and show an audit trail to back it up, according to Oltsik.

One thing is certain: During the first few months of 2018, CISOs can expect to be hit from all sides by vendors claiming to have "the solution" to GDPR. Be very discriminating -- and don't panic. Start by asking pertinent questions: Is the company's incident response plan robust enough? Does the organization have the people it needs to respond to GDPR breach notification and do the nitty-gritty compliance work? Should the company consider hiring a data protection officer to head up the GDPR effort?

Time may be short, and the experts are right that many CISOs spent the last two years putting out fires and haven't had the time to focus on GDPR. But as we get deeper into 2018, the tide should turn, and companies will begin to focus on GDPR compliance. After all, nobody wants to be the one hit with a 4% fine.