The General Data Protection Regulation (GDPR), which came into force in May 2018, transformed how companies handle and protect personal data. To comply, a company has to put in place a set of technical and organisational measures to keep the information it processes secure and private. The steps below set out the essentials for meeting the technical obligations the GDPR imposes, informed by current thinking in data protection.
Initial assessment of your data processing
First of all, it is essential to map every business process that involves personal data. That means identifying which data is collected, how it is used, where it is held and who has access to it. A clear grasp of those processes is fundamental to spotting potential risks and weaknesses.
Applying privacy by design and privacy by default
The GDPR stresses the importance of building data protection into systems from the design stage (privacy by design) and of ensuring that, by default, only the data necessary for each specific purpose is processed (privacy by default). Companies should therefore build security measures into their processes and systems from the earliest stages of development.
Putting technical and organisational security measures in place
-
- Encryption and pseudonymisation: apply encryption to protect sensitive data, and use pseudonymisation to limit the damage if unauthorised access does occur.
-
- Access controls: implement robust authentication and role-based access controls so that only authorised staff can reach the data.
-
- Monitoring and logging: use monitoring systems to detect suspicious activity, and keep detailed logs so operations on the data can be traced.
-
- Updates and patching: keep every system and application up to date with the latest security patches, to prevent known vulnerabilities being exploited.
Training and staff awareness
The human factor is often the weak link in information security. Companies therefore need to invest in continuous training on data security best practice, on internal procedures and on awareness of threats such as phishing and social engineering.
Managing suppliers and processors
When personal data is shared with third parties, it is essential to be sure they are GDPR compliant too. That means contracts that clearly set out the responsibilities and the security measures each supplier applies.
Data Protection Impact Assessment (DPIA)
Where processing may present a high risk to the rights and freedoms of individuals, a DPIA is mandatory. The exercise helps identify and mitigate the risks that come with the processing.
Data breach notification
In the event of a personal data breach, companies are obliged to notify the competent supervisory authority within 72 hours and, where necessary, to inform the individuals affected as well. Having procedures ready to handle such incidents promptly is therefore crucial.
Keeping a record of processing activities
The GDPR requires companies to keep a detailed record of their processing activities. The document has to include information such as the purposes of the processing, the categories of data processed, the recipients of the data and the security measures applied.
Appointing a Data Protection Officer (DPO)
Depending on the size of the company and the type of data processed, appointing a DPO may be necessary. Their role is to oversee GDPR compliance and to act as the point of contact with the supervisory authorities.
Reviewing and updating security measures periodically
Information security is a field that never stands still. It is therefore important to audit regularly and to update security measures in line with new threats and emerging best practice.
Alignment with other rules and standards
Beyond the GDPR, companies should consider other relevant rules such as the Italian personal data protection code, and international standards such as ISO/IEC 27001 for information security management. Adopting such standards gives a structured framework for managing security and makes regulatory compliance easier.
Conclusion
Meeting the technical obligations of the GDPR takes a systematic and proactive approach. Companies need not only to implement adequate technical measures but also to foster a culture geared towards protecting data. Investing in data security does not merely avoid potential penalties: it also strengthens the trust of clients and stakeholders, which is a competitive advantage in today’s market.