STEALTHbits-欧盟《一般数据保护条例》执行情况报告(英文)-2018-30页-3mb
报告摘要
EU GDPR Report Summary
Core Content
The EU General Data Protection Regulation (GDPR) is a major data privacy regulation that came into effect on May 25, 2018. It imposes strict requirements on companies that handle personal data, with a focus on transparency, user rights, and data protection measures. This report summarizes the findings of a comprehensive survey conducted by Stealthbits Technologies in collaboration with the Information Security Community and Crowd Research Partners, involving over 520 companies from various regions.
Main Findings
-
Familiarity with GDPR:
- Over 90% of surveyed organizations are familiar with the GDPR regulations.
- However, only 32% state they are compliant or on the path to compliance.
- Companies based in Europe show a higher level of familiarity than those in North America.
-
Compliance Priority:
- GDPR compliance is a top 3 priority for Technology, Energy, Financial Services, Healthcare, and Higher Education sectors.
- Organizations with a high compliance priority are further along the compliance process.
- 65% of companies with GDPR as a top priority already have or plan to have a Data Protection Officer (DPO).
-
Compliance Challenges:
- The top challenges in achieving GDPR compliance are:
- Lack of budget (32%)
- Limited understanding of the regulations (29%)
- Lack of expert staff with critical skills (28%)
- Lack of management support (28%)
- Lack of necessary technology is also a significant challenge.
- The top challenges in achieving GDPR compliance are:
-
Compliance Initiatives:
- The most important initiative is making an inventory of user data and mapping it to protected GDPR categories (49%).
- Other key initiatives include:
- Designing applications and databases to have privacy enabled by default (31%)
- Conducting audits to find “rogue” data records (25%)
- Evaluating solutions to enable users to exercise their data rights (19%)
- Identifying and integrating internally and externally developed solutions (15%)
- Stress-testing proposed GDPR solutions (15%)
-
Regulatory Impact:
- The anticipated impact of GDPR on security practices and budgets is strongly correlated with the priority given to compliance.
- 29% of respondents expect substantial changes to their security practices and technology.
- 56% expect relatively minor changes.
- 15% expect no changes.
- Companies with higher compliance priority are more likely to increase their IT security budget for GDPR compliance, with some expecting an increase of more than 50%.
-
Impact on Security Budgets:
- Less than 5% of the IT security budget is currently allocated to GDPR compliance.
- The proportion of budget allocated increases with the priority of GDPR compliance.
- The maximum fine for non-compliance can be up to €20M or 4% of annual global revenue (whichever is higher).
-
Data Governance Budget:
- A significant portion of companies report that their data governance budgets will increase in the next 12 months, with the growth strongly tied to the priority of GDPR compliance.
-
Demographics:
- Industry distribution:
- Technology (45%)
- Financial Services (10%)
- Government (6%)
- Higher Education (5%)
- Healthcare (4%)
- Retail (3%)
- Energy (2%)
- Other (23%)
- Department responsible:
- Information Security (48%)
- Information Technology (21%)
- Legal (7%)
- Other (22%)
- Career level:
- CISO (22%)
- DPO/Privacy Officer (4%)
- VP of IT (3%)
- VP of Security (2%)
- Director (19%)
- Manager (12%)
- Analyst (10%)
- Other (27%)
- Industry distribution:
GDPR Chapters and Articles of Concern
-
Chapter II (Principles):
- Focuses on the principles of processing personal data, including lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, and integrity.
-
Chapter IV (Controller and Processor):
- Highlights the responsibility of the controller and the role of the processor in data processing.
-
Article 5:
- Concerns control 1(f) and control 2 related to data minimization and storage limitation.
-
Article 24:
- Related to control 1 about data protection by design.
-
Article 25:
- Concerns control 1 and control 2 about data protection by design and by default.
-
Article 32:
- Related to control 1 (b, c, d), control 2, and control 4 about security of processing.
-
Article 33:
- Related to control 1 about notification of personal data breaches.
Impact on Security Practices
- The level of change in security practices and technology is directly linked to the priority of GDPR compliance.
- 29% of respondents expect substantial changes, while 56% expect minor changes.
- The primary area of concern is Chapter II (Principles), particularly data minimization and storage limitation.
5 Steps to GDPR Compliance
- Data Inventory & Mapping: Identify and map all personal data to GDPR-protected categories.
- Privacy by Design: Design applications and databases with privacy enabled by default.
- Enable Data Subject Rights: Develop solutions to allow users to exercise their rights under GDPR articles 15-22.
- Train Employees: Ensure employees are GDPR proficient.
- Incentivize Data Discovery: Encourage the identification of “rogue or non-obvious” personal data records.
- Stress Test Solutions: Evaluate the resilience of proposed GDPR solutions.
- Integrate Crowdsourced Solutions: Coordinate and integrate solutions from across the business.
- Hire GDPR Experts: Employ both a GDPR architect and a Data Protection Officer (DPO).
About the Report
- The report is based on a crowd-based research study involving over 520 companies.
- It was conducted in collaboration with Stealthbits Technologies, a cybersecurity company focused on protecting credentials and data.
- The report aims to provide insights into organizational perspectives on GDPR compliance, challenges, and future steps.
Conclusion
The EU GDPR is a transformative regulation that has significant implications for data privacy and security. While most organizations are familiar with it, compliance remains a challenge due to budget constraints, lack of expertise, and limited understanding. The report highlights the importance of data governance, privacy by design, and employee training in achieving compliance. Organizations with a high compliance priority are more likely to allocate more resources to GDPR initiatives, including budget increases and the hiring of DPOs.
试读结束,高清完整版pdf/doc/ppt,请点下载