Conference item
Are we there yet? Understanding the challenges faced in complying with the general data protection regulation (GDPR)
- Abstract:
- The EU General Data Protection Regulation (GDPR), enforced from 25th May 2018, aims to reform how organisations view and control the personal data of private EU citizens. The scope of GDPR is somewhat unprecedented: it regulates every aspect of personal data handling, includes hefty potential penalties for non-compliance, and can prosecute any company in the world that processes EU citizens’ data. In this paper, we look behind the scenes to investigate the real challenges faced by organisations in engaging with the GDPR. This considers issues in working with the regulation, the implementation process, and how compliance is verified. Our research approach relies on literature but, more importantly, draws on detailed interviews with several organisations. Key findings include the fact that large organisations generally found GDPR compliance to be reasonable and doable. The same was found for smallto-medium organisations (SMEs/SMBs) that were highly securityoriented. SMEs with less focus on data protection struggled to make what they felt was a satisfactory attempt at compliance. The main issues faced in their compliance attempts emerged from: the sheer breadth of the regulation; questions around how to enact the qualitative recommendations of the regulation; and the need to map out the entirety of their complex data networks.
- Publication status:
- Published
- Peer review status:
- Peer reviewed
Actions
Access Document
- Files:
-
-
(Preview, Accepted manuscript, pdf, 356.7KB, Terms of use)
-
- Publisher copy:
- 10.1145/3267357.3267368
Authors
- Publisher:
- Association for Computing Machinery
- Host title:
- Proceedings of the International Workshop on Multimedia Privacy and Security
- Journal:
- Proceedings of the International Workshop on Multimedia Privacy and Security More from this journal
- Pages:
- 88-95
- Publication date:
- 2018-10-16
- Acceptance date:
- 2018-08-22
- Event location:
- Toronto, Canada
- DOI:
- Pubs id:
-
pubs:911239
- UUID:
-
uuid:39d8cb99-8256-40d9-afc6-17b07f739ef0
- Local pid:
-
pubs:911239
- Source identifiers:
-
911239
- Deposit date:
-
2018-08-30
Terms of use
- Copyright holder:
- Association for Computing Machinery
- Copyright date:
- 2018
- Notes:
- Copyright © 2018 Association for Computing Machinery. This is the accepted manuscript version of the paper. The final version is available online from ACM at: https://doi.org/10.1145/3267357.3267368
If you are the owner of this record, you can report an update to it here: Report update to this record