Connect with us

Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website. .

Business

OVER TWO-THIRDS OF BUSINESSES AT RISK OF FALLING FOUL OF NEW EU DATA PROTECTION LAWS

OVER TWO-THIRDS OF BUSINESSES AT RISK OF FALLING FOUL OF NEW EU DATA PROTECTION LAWS

43% of businesses put customer privacy at risk by failing to anonymise test data

  • With the new EU General Data Protection Regulation (GDPR) finally agreed, 68% of businesses don’t yet have a comprehensive plan in place for how they will respond to its impact.
  • Just 52% of businesses could efficiently comply with the “Right to be Forgotten” mandate.
  • The difficulty of compliance with EU data mandates is being exacerbated by growing IT complexity, Agile and DevOps-enabled proliferation of new applications, ongoing collection of more data, and outsourcing.
  • To be prepared for GDPR compliance, companies must improve their data governance and test data management capabilities across all platforms—including the mainframe, where the majority of customer data resides.

Compuware Corporation, the world’s leading mainframe-dedicated software company, today released new research that reveals many European and U.S. businesses are ill-prepared for the recently agreed EU General Data Protection Regulation (GDPR) and are at risk of falling foul of its rules around the use and control of personal data. Key findings include:

  • Just over half (55%) of European businesses are well briefed on the GDPR and its impact on the way that customer data can be handled.
  • Over half (52%) of U.S. businesses hold European customer data, meaning they too will need to comply with the new regulations.
  • Just 43% of U.S. respondents claim to be well-briefed on the GDPR and its impact.
  • Despite the risks of failing to comply, 68% of businesses don’t yet have a comprehensive plan in place for how they will respond to the impact of the GDPR.

Factors contributing to the difficulty of EU GDPR compliance include growing IT complexity, the Agile and DevOps-enabled proliferation of new applications, ongoing collection of more data, and IT outsourcing. The overwhelming majority of respondents (63%) admitted that data complexity is one of the biggest hurdles to achieving compliance, whilst a further 53% said that securing and handling customers’ consent for their data to be used would be another major hurdle.

Poor control of the ‘Right to be Forgotten’

The research indicates that businesses are struggling to control their data, which will make it difficult to comply with the ‘Right to be Forgotten’ mandate laid out in the GDPR. Key findings include:

  • 68% of respondents said the complexity of modern IT services means they can’t always know where customer data is.
  • Over half (53%) said that it is especially difficult to know where all of their test data is.
  • Just over half (51%) of CIOs can locate all of an individual’s personal data quickly, whilst nearly a third (30%) admitted they could not guarantee they would be able to do so at all.
  • Respondents also said that the use of outsourcers (81%) and mobile technology (63%)is making it even harder to keep track of where customer data resides.
  • Nearly half (45%) of respondents said it would take their business a lot of time and resources to comply with a request to show an individual all of the data that the organisation holds on him or her across all of its systems.
  • Just over half (52%) would then be able to remove all of that data efficiently should the individual exercise their ‘Right to be Forgotten.’

“To comply with the GDPR, businesses need to keep stricter control of where customer data resides,” said Dr Elizabeth Maxwell, PC.dp, and Technical Director, EMEA, Compuware. “If they don’t have a firm handle on where every copy of customer data resides across all their systems, businesses could lose countless man-hours conducting manual searches for the data of those exercising their ‘Right to be Forgotten.’ Even then, they may not identify every copy, leaving them at risk of non-compliance.”

Testing the boundaries of consent

The research found that 86% of businesses use live customer data to test applications during software development. However, just one in five respondents ask for explicit customer consent for their data to be used in testing, leaving the majority non-compliant with the GDPR. Alarmingly, 43% of those that test applications with live data are further putting customer privacy at risk, as they cannot guarantee that data is depersonalised before it is used.

“Using customer data to test applications is fairly standard practice, but there’s no need or excuse for not depersonalising it first,” continued Dr Elizabeth Maxwell.  “Companies that fail to mask data before using it to test applications could soon find themselves slapped with an eye-watering fine from EU regulators. As well as being better for protecting customer privacy, anonymising test data eliminates the need to obtain customers’ explicit consent for it to be used in this way, which over half (53%) of CIOs identified as one of the biggest hurdles in GDPR compliance.”

Commissioned by Compuware and conducted by independent research company Vanson Bourne, the survey was administered to 400 CIOs at large companies covering a cross-section of vertical markets in France, Germany, Italy, Spain, the UK and the U.S.

Compuware Corporation

Compuware empowers the world’s largest companies to excel in the digital economy by fully leveraging their high-value mainframe intellectual property. We do this by delivering highly innovative mainframe application development and performance optimization solutions that uniquely enable IT to drive business value. Learn more at compuware.com

Global Banking & Finance Review

 

Why waste money on news and opinions when you can access them for free?

Take advantage of our newsletter subscription and stay informed on the go!


By submitting this form, you are consenting to receive marketing emails from: Global Banking & Finance Review │ Banking │ Finance │ Technology. You can revoke your consent to receive emails at any time by using the SafeUnsubscribe® link, found at the bottom of every email. Emails are serviced by Constant Contact

Recent Post