GDPR Compliance in Your Area
Find, mask, and audit PII everywhere
What is GDPR?
The General Data Protection Regulation (GDPR) is a privacy law passed by the European Parliament designed to increase the security of EU citizens' personal identifiable information (PII). Its goal is to give individuals control over their personal data and facilitate international business by creating a standard for how personal data is handled within the EU. The regulation became fully effective on May 25, 2018, and serves as a model for similar data protection laws around the world.
Some notable aspects and impacts of the law are:
- Mandatory appointment of data protection officers for companies that collect, process, or store personal data as their core business.
- Notification of a supervisory authority following a personal data breach (usually no more than 72 hours after becoming aware of the breach)
- Promotion of pseudonymization (anonymization of data or rendering the data subject unrecognizable) of personal data files
- Supports data minimization rules and the right to erasure (Right to be forgotten) from data collections/searches
- provides for data portability, allowing individuals to transfer their information from one provider to another, and rectification, so that their data can be corrected.
- “The concept of personally identifiable information (PII) is at the heart of the General Data Protection Regulation (GDPR),„ writes the International Association of Privacy Professionals (IAPP). Within the GDPR, the IAPP specifically points to Recital 75, which instructs controllers to ‚take appropriate measures to prevent the ‘unauthorized reversal of pseudonymisation'.".
To mitigate the risk of data breaches and non-compliance, data controllers should have appropriate technical (e.g., encryption, hashing, or tokenization) and organizational (e.g., agreements, policies, privacy by design) measures in place that separate pseudonymous data from an identifying key.„
GDPR Flyer
Proven GDPR Compliance
Given these regulations, protecting personal data is not only a good way to safeguard your company’s reputation, but also key to your bottom line. The penalties for non-compliance are steep: up to €20,000,000 or 4% of global annual turnover, whichever is higher. Proactive compliance with GDPR regulations helps protect data, and demonstrating this compliance can serve as a buffer against penalties.
For compliance with GDPR, as well as other data privacy laws worldwide, it is important to have a powerful and extensible technology solution for protecting PII. Proven PII detection and de-identification software in the award-winning:
- IRI Data Protector Suite, the three products for static data masking (SDM) – IRI FieldShield, DarkShield, and CellShield – for finding, classifying, extracting, Delete and other Anonymize (or Correct) PII in structured and unstructured sources through multiple functions such as Pseudonymization, deletion, encryption, and redaction, as well as the ability to provide data [through searching for the above] to meet portability and rectification requirements, and the risk to assess re-identification and anonymize quasi-identifiers to comply with the provisions of Article 29.
and,
- IRI Voracity Data management and governance platform that bundles all three of the above SDM products (Shield) with data integration, migration, cleansing, reporting, and analysis…
delivers the rule-based and role-based data-centric auditing and protection features that you need to meet key GDPR provisions to achieve and demonstrate.
The PII detection and masking functions in IRI GDPR Solution software work across all databases and legacy/document formats – as well as images and faces – on-premises or in your cloud (not ours!). Data never leaves your firewall or domain.
Affordable GDPR data protection licensing, implementation, and support services are from authorized IRI representatives available throughout the EU and beyond. IRI is also a partnership with GDPR Local in the UK received, to offer a more comprehensive assessment service and remediation solution for companies requiring full documentation of GDPR-compliant processes and safeguards.