
Warwick Ashford, writing for Computer Weekly, reports that only a quarter of British law firms are ready for GDPR:
Most law firms in the UK do not yet comply with the EU’s General Data Protection Regulation (GDPR), with just over six months to go before the compliance deadline of 25 May 2018.
According to a report by managed services provider CenturyLink Emea, only 25% of more than 150 legal sector IT decision-makers said their firms were GDPR ready, despite the threat of fines of up to €20m or 4% of annual global turnover for serious data protection failings under the GDPR.
25% of UK law firms are ready for GDPR? To my mind that’s either actually a surprisingly impressive number, or some of the legal sector’s IT security chiefs are seriously deluded…
I would have imagined that the reality is that far fewer law firms are truly “ready” for GDPR.
And we shouldn’t make the mistake of thinking that this is a British or simply European challenge. Any organisation doing business with people based in Europe, regardless of where their firm is based, needs to wake up to the truth that they are also impacted by GDPR. In my experience many businesses in the rest of the world are largely oblivious to what’s coming around the corner.
Of course, it remains to be seen whether anyone will actually be hit by the considerable GDPR fines being talked about, but what firm would want to take that gamble?
If you’re still baffled as to what GDPR is, and how it might affect you and your business, be sure to check out our “Smashing Security” podcast on the topic from earlier this year:
Show full transcript ▼
This transcript was generated automatically, probably contains mistakes, and has not been manually verified.
Hello, hello, and welcome to another episode of Smashing Security, Episode 30, and it is a special Splinter episode. Woo!
Hi, Kevin.
This is Graham's little sack, and it's his little Scrabble sack, because I've got some letters in here. Okay? So I'm going to pull out—
He's not even— I mean, technically, Carole, you and I, as based in Britain, we're still at the moment part of Europe, right? And so—
This is a new European data legislation, and it's all about giving more control to the EU subject, okay, or EU citizen, more control over their personally identifiable information that's stored online all over the web.
We are having to share so much of it with businesses online, we don't always have great visibility as to what they're planning to do with it or indeed how well they're taking care of it, right?
I mean, there was a survey that three-quarters of people took part were like, "I don't trust companies with my personal information." So that's where we're starting from.
So back in 2012, this started taking shape, the whole concept behind this. This is really, really massive piece of legislation.
And it started all the way back in 2012 where they started scoping out the legal requirements of how personal data of EU residents should be handled by companies.
And it was only adopted in 2016. And because it's so huge, they gave a two-year post-adoption grace period before it fully comes into effect in May 2018. That's May next year.
It's so big that companies who do not meet the requirements or stipulations and are found guilty can face fines of up to €20 million or 4% of the previous year's turnover, not profits, but turnover.
And they will choose whichever one is higher if you're found guilty.
I would imagine that having to deal with this piece of legislation is probably better than having to deal with the different data protection legislation, the alternative, which could be — I mean, how many EU member states are there?
Something like 28 or something like that, right?
Just forget about Europe, too much of a hassle, right? No internet company's likely to do that. And it's not just internet companies, of course, but—
So companies maybe around the 500-employee mark, might be looking at how much return they get from providing services and products to EU citizens, right? And residents.
I keep saying citizens. It is any EU subject. So for the future of the podcast, if I can say it wrong. So not everyone in the world is affected by this legislation.
So maybe we need to define, okay, so how about we talk about how companies are affected and then what does this mean for the actually individuals? Right?
Where the European subject cannot in any way be identified to the data and correlated to the data, this falls outside the scope of this legislation, okay?
So the company has to make the assumption that every bit of data that gets entered on one of those forms is actually legitimate, that you're not using some anonymous name for yourself.
And they are going to have to take proper care to ensure that identifiable information about me doesn't fall into the wrong hands and that they are properly protecting it so it can't easily fall into the hands of hackers.
Now, one big misnomer about this whole thing is people think, oh, that's an EU regulation. It doesn't affect my company. I don't have any office or establishment inside the EU.
Well, wait, wait, wait. That's not true. It impacts any firm that processes in a large scale or has a focused process on EU subjects.
And that they process personally identifiable information.
If it's 500 individuals in the company, they're going to be subject to it. If I'm 250 or less, I'm not subject to this legislation, right?
So I don't have to worry about it quite as much.
But from my reading of the legislation, they seem to be focused on firms that have 250 employees or more, or companies that manage personal identifiable data on a regular basis, right.
So if you're doing that and you're a smaller company, you need to pay attention to GDPR.
It's like, think of all the forms, the web forms that are filled in, the geolocation you might have with cookies.
You know, how GDPR is defining what personal information is, or personally identifiable information is, is perhaps broader than current legislation in your neighborhood.
And wouldn't it make sense to follow these sort of guidelines which GDPR is proposing because of the general health of your company?
Because you never want some bad— you know, these rules are being introduced in order to protect people your customers. You should be doing these kind of things anyway.
And it's much easier to build this in from early on in your company rather than waiting until you get big, whereupon it's a huge overhaul of your organization.
For, I feel for companies that have to do this because some companies have been running systems for 20, 30 years, have been processing data in a specific way, and they have to kind of do a huge overhaul.
And not all, I mean, let's just think about what GDPR means. I don't think we've actually defined, there's a few mega, you know, big things that it does, right?
Obviously, if someone is not of consent-giving age, so a child, they need to get parent consent from that. EU residents have a lot more control over data in this case.
So for example, a EU resident can request that their data be sent to them in a common format, that it can be sent to a third party if they want to transfer their data from one enterprise to another, or that all their personal data be erased.
They can make that request anytime and you're not allowed to kind of dilly-dally on getting that done. You've got to move quite quickly.
And you have to bake in obviously data protection capabilities into the system, right? So this means things encryption and what this word that they use everywhere, pseudonymization.
It's a very difficult word to say. Pseudonymization is probably the easiest way to say it. And if you do have a breach, right, you have 72 hours to report it, right?
So think ID numbers, you know, but it's very separate so that if, for example, you did get breached and they managed to crack the encryption, they wouldn't be able to easily tie it all together.
And that's interesting, 'cause of course we've seen some breaches in the past where companies have sent CDs through the post of their customer database, including all kinds of information, personally identifiable information, which wasn't actually necessary for the person who was receiving the CD to process.
They only wanted some of the columns. So that's interesting, isn't it, that they would be planning to do that? It sounds it makes sense.
So you have to tell the user why you want to use their data.
And this makes things complicated because lots of companies obviously collect data and then sell it on for the third party.
You're going to see a big change in privacy policy come May 18th on them begging to be able to use your personally identifiable data in a very explicit way, hopefully.
If they want to comply with the rules. And you have to explicitly say yes or no, and it can't be a pre-ticked box. You have to click yes.
But as you've just mentioned, how often is that situation happening when people download apps today, right?
And when they're buying services, they're like, you know, have you agreed to the agreement? Yes, I have. Carry on.
And I think, you know, if we move on to what this means for end users or for EU citizens and subjects here, it's kind of like they're, you know, they have a job to maybe not click yes if they don't want to be personally identified with this information.
They'd all be more careful with it. They'd actually — businesses would have to change the way in which they collect information, right?
I mean, that's a cold — I mean, I don't read — dare I say it? I don't read all the legalese. I don't read all the terms and conditions.
I just think, yes, yes, yes, I need to buy this thing. I need it delivered, you know, next Tuesday.
And the other thing is, I mean, sometimes I make those sort of decisions based upon the site and the company and how established it is.
However, it may not actually be the company which is processing my data. They may have farmed that out to third parties, right, who are doing the actual processing.
And those companies are going to have to be on board with GDPR as well, aren't they? I think there's this difference between, is it the controller and the processor of the data?
And by that, I'm reading liability to the controller, right?
So the controller has to stipulate the, you know, the contract and the agreement that it makes with a third-party processor.
And they are responsible for making sure they cover all their bases, as I read it. So, there's a lot more responsibility for the controller here in managing the data.
So, they're providing a managed service or in some cases a self-managed service so that the controller is actually managing their own service, but the cloud provider is providing the infrastructure.
In the case of a breach, who's going to wind up picking up the check for the $20 million? Is it both of them?
Do they both get hit for $20 million, or does one or the other get hit for the $20 million?
Okay, now I understand how it works and what can happen."
It's funny, from some that are just not very well defined and putting responsibility back on themselves rather than the processor.
And then there's others that want to shirk that responsibility and shuffle it all over to the processor.
So your response, even if you're not basically doing more than storing the data. So I mean, I think there's a lot of things that are going to come into play contractually.
I think for citizens, for people who live in Europe, this is fantastic, you know, because there have been too many data breaches and it sounds like companies are going to have to buck their ideas up in terms of protecting data considerably.
You know, this is a real scare for companies and they— this is coming in in May 2018, right?
How they process their information.
However, if I put company shoes on, I have to say, wow, this is a big pain up the bottom, isn't it? Quite frankly.
So I think if you work in a company, 500, 1,000 employees, you're gonna be, you're gonna have seen, you know, the senior stakeholders, the IT guy, the legal guys, all in a room huddled up every week, and this is probably what they're discussing because it's big.
You know, it's a risky field to be working in.
Honestly, I would bet that there's a huge percentage of these firms that have no idea where this data lives within their environment.
You know, I think that when you said that, people are holed up in the corner trying to figure out what's the policy and what's the protection around this, everybody's looking at wrapping the data and protecting it so that the breach doesn't occur.
Yay team for that.
But we should be looking at how we're gonna categorize this information and the documentation that's gonna go, that has to be acquired for us to support any of these cases that we're gonna make going forward after we get bagged for personal data escaping or data leakage in any environment, right?
So some will either stop processing data from EU subjects and dump the data they currently have, or they could separate out the EU subjects into two different databases and treat them differently according to the laws of the land.
Or three, they review and revamp exactly the whole systems. And you would do that because you think the world's going this way, right?
This is going to be bigger and bigger, and it's not just going to impact on EU citizens. We expect this to move to the US, UK, and US, etc. Australia.
If they knocked out Europe, or at least the legislative part of it, maybe that would be the simplest thing to do. I mean, if this is really going to be a big pain.
It's a big fricking deal, as some people say. So where can people read more about this?
Because I mean, obviously we've only been able to skim the surface of this, but there must be places where people can go, where they can read more.
I imagine many companies are dealing with this.
There's a number of places because when you look at the actual legislation, and you scroll through the hundreds of pages that it takes, you know, in size 8 font, it can lose your will to live.
So there are a lot of places that have distilled the information in a more manageable way so people can introduce themselves. I suggest introduce yourself gently.
When I drew out those letters from my little Scrabble sack of GDPR— yes, I know, it was a strange coincidence— I wondered, you know, is this an interesting subject actually.
It's obviously important. There's so much hacking going on. There's so many data breaches going on. Organizations have to do it.
And oh, just one other thing, of course, reaching, you know, fulfilling these requirements isn't necessarily the end of the road for companies, is it?
I mean, I guess you should really view this as a minimum that your company should be doing.
And maybe if you really want to stand out from the crowd in terms of protecting your users, maybe you should go even further.
We are not ready.
It's a real pleasure having you here.
I'll tell you why, because if you do that, it actually helps more people find out about the podcast and it makes us feel loved and wanted, which is really important to me at least.
I don't know if it matters to Carole or not.
