CCG Insights

U.S. Companies Need to Gear Up Now For New EU Data Privacy Regulations

  • Insight

U.S. Companies Need to Gear Up Now For New EU Data Privacy Regulations

Innovation Centers Become Part of Finserv Culture

U.S. Companies Need to Gear Up Now For New EU Data Privacy RegulationsThousands of American companies including financial institutions that do business directly or online with European customers need to start reckoning with data privacy regulations enacted by the European Union that are due to go into full effect in just two years, according to the International Association of Information Technology Asset Managers, Inc.

“These are sweeping changes to how personal and corporate data is to be handled and they have far-reaching implications for many aspects of U.S. businesses, particularly in terms of how information security is addressed. The days are long past when U.S. businesses could worry only about complying with laws and rules in this country,”  IAITAM CEO Dr. Barbara Rembiesa said. “Companies that fail to start planning now to deal with the General Data Protection Regulation requirements are going to be in for a real shock.”:

Banks will be among the first organizations to receive huge fines not complying with the EU’s GDPR when it finally comes into play, according to European professionals polled by security firm Varonis.

IAITAM identified the top five impacts the new EU regulations will have on any organization:

  1. Data breaches. “A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed” – The changes the GDPR makes to the definition of a data breach are significant. If an organization experiences a data breach, it must report it within 72 hours of the company becoming aware of the breach.
  2. Data Protection Officer requirement. The EU has determined that an individual is necessary at each company doing business in Europe to ensure the maintenance of data privacy and data control at a high standard.
  1. Consent of those providing data. The data controller bears the burden of proof for the data subject’s consent to the processing of their data for specified purposes. This aspect of the GDPR requires active acceptance of the terms and conditions by the end-user. Consequently, mere “use” by the end-user will no longer be sufficient acceptance of the terms and conditions.
  2. Special handling of data related to Europeans. This provision protects EU citizen’s data once moved outside the EU. Any organization that is international in scope and handles personal information of EU citizens such as phone numbers, addresses or any other identifying information will be subject to the GDPR. In addition, any organization that received the information “third-hand” will also be subject to the regulation.
  3. Potential for hefty fines and court penalties. “For infringements of this regulation, in particular for infringements which are not subject to administrative fines, member states shall lay down the rules on penalties applicable to such infringements and shall take all measures necessary to ensure that they are implemented. Such penalties shall be effective, proportionate and dissuasive.” An effective policy is an enforced policy. Subject to what would be referred to as a “tort” in the United States, an organization will be fined by the member states to ensure that the damage to an individual is made whole in addition to penalties and fines meant to deter any additional infractions. This type of enforcement can become increasingly potent and result in monetary penalties reaching into the billions.

“What is important to take away here is that any organization that processes or handles data from EU citizens must become familiar with this legislation and fully understand the impact it will have on daily business processes. Between the sweeping scope of the GDPR and the penalty structure, this is a piece of legislation that should be treated seriously and with an eye to what it will take ensure full compliance,” Rembiesa said.

Get full access to this and other CCG Insights – Register Now

Already have an account? Log in

  • Paul Schaus - Chief Executive Officer Paul Schaus - Chief Executive Officer
  • May 19, 2016

You Might Like These, Too

A Look Back at 2016 Banking Trends
Insight

Mobile Banking Reaching Capacity but There is Room to Improve

Podcast

Raj Patel of MANTL on Saving Community Banks

Real-Time Payments Catching on Globally, Not So Fast in the U.S.
Insight

Lending Opportunities: Three Important Disruptors

Customer Experience in the Age of AI
Insight

Customer Experience in the Age of AI

Leaders in Bank Consulting

About CCG Catalyst
Latest Insights
CCG

PHOENIX • NEW YORK • LONDON • SINGAPORE

Phone: +1-480-744-2240  • Contact Us

© 2021 CCG CATALYST CONSULTING GROUP. Privacy Policy & Terms of Service.
Request a Call Back
Linkedin
Twitter
Subscribe
for Insights
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled

Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.

Non-necessary

Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.

SAVE & ACCEPT
BANK
FINTECH
FUSION
  • About
  • Services
  • Insights
  • Fintech
  • Research
  • Contact
  • Press
  • Careers
  • Events
  • Terms
  • Privacy
Linkedin
Twitter