The necessity of information governance and data classification

New article reveals the necessity of information governance and data classification for complying with the new data protection policy, the EU GDPR
By: www.minereye.com
 
HOD HASHARON, Israel - Dec. 14, 2017 - PRLog -- Approaching the new General Data Protection Regulation (GDPR), effective from May 2018, companies based in Europe or having personal data of people residing in Europe, are struggling to find their most valuable assets in the organization – their sensitive data.

The new regulation requires organizations to prevent any data breach of personally identifiable information (PII) and to delete any data if some individual requests to do so. After removing all PII data, the companies will need to prove that it has been entirely removed to that person and to the authorities.

Most companies today understand their obligation to demonstrate accountability and compliance, and therefore started preparing for the new regulation.

There is so much information out there about ways to protect your sensitive data, so much that one can be overwhelmed and start pointing into different directions, hoping to accurately strike the target.  If you plan your data governance ahead, you can still reach the deadline and avoid penalties.

Some organizations, mostly banks, insurance companies and manufacturers possess an enormous amount of data, as they are producing data at an accelerated pace, by changing, saving and sharing files, thus creating terabytes and even petabytes of data. The difficulty for these type of firms is finding their sensitive data in millions of files, in structured and unstructured data, which is unfortunately in most cases, an impossible mission to do.

The following personal identification data, is classified as PII under the definition used by the National Institute of Standards and Technology (NIST):

• Full name
• Home address
• Email address
• National identification number
• Passport number
• IP address (when linked, but not PII by itself in US)
• Vehicle registration plate number
• Driver's license number
• Face, fingerprints, or handwriting
• Credit card numbers
• Digital identity
• Date of birth
• Birthplace
• Genetic information
• Telephone number
• Login name, screen name, nickname, or handle

Most organizations who possess PII of European citizens, require detecting and protecting against any PII data breaches, and deleting PII (often referred to as the right to be forgotten) from the company's data. The Official Journal of the European Union: Regulation (EU) 2016/679 Of the European parliament and of the council of 27 April 2016 has stated:

"The supervisory authorities should monitor the application of the provisions pursuant to this regulation and contribute to its consistent application throughout the Union, in order to protect natural persons in relation to the processing of their personal data and to facilitate the free flow of personal data within the internal market. "

In order to enable the companies who possess PII of European citizens to facilitate a free flow of PII within the European market, they need to be able to identify their data and categorize it according to the sensitivity level of their organizational policy.

They define the flow of data and the markets challenges as follows:

"Rapid technological developments and globalization have brought new challenges for the protection of personal data. The scale of the collection and sharing of personal data has increased significantly. Technology allows both private companies and public authorities to make use of personal data on an unprecedented scale in order to pursue their activities. Natural persons increasingly make personal information available publicly and globally. Technology has transformed both the economy and social life, and should further facilitate the free flow of personal data within the Union and the transfer to third countries and international organizations, while ensuring a high level of the protection of personal data."

Phase 1 – Data Detection

So, the first step that needs to be taken is creating a data lineage which will enable to understand where their PII data is spread across the organization, and will help the decision makers to detect specific types of data. The EU recommends obtaining automated technology that can handle large amounts of data, by automatically scanning it. No matter how large your team is, this is not a project that can be handled manually when facing millions of different types of files hidden I various areas: in the cloud, storages and on premises desktops.

The main concern for these types of organizations is that if they are not able to prevent data breaches, they will not be compliant with the new EU GDPR regulation and may face heavy penalties.

They need to appoint specific employees that will be responsible for the entire process such as a Data Protection Officer (DPO) who mainly handles the technological solutions, a Chief Information Governance Officer (CIGO), usually it's a lawyer who is responsible for the compliance, and/or a Compliance Risk Officer (CRO). This person needs to be able to control the entire process from end to end, and to be able to provide the management and the authorities with complete transparency.

"The controller should give particular consideration to the nature of the personal data, the purpose and duration of the proposed processing operation or operations, as well as the situation in the country of origin, the third country and the country of final destination, and should provide suitable safeguards to protect fundamental rights and freedoms of natural persons with regard to the processing of their personal data."

Read more: https://minereye.com/?resources=new-article-reveals-neces...

Contact
Danit Kellmer
***@minereye.com
End
Source:www.minereye.com
Email:***@minereye.com Email Verified
Tags:Information Governance, Pii, GDPR
Industry:Technology
Location:Hod Hasharon - Tel Aviv - Israel
Account Email Address Verified     Account Phone Number Verified     Disclaimer     Report Abuse



Like PRLog?
9K2K1K
Click to Share