{"id":3640,"date":"2024-05-20T09:17:05","date_gmt":"2024-05-20T14:17:05","guid":{"rendered":"https:\/\/www.darkreading.com\/cyber-risk\/what-american-enterprises-can-learn-from-europe-gdpr-mistakes"},"modified":"2024-05-20T09:17:05","modified_gmt":"2024-05-20T14:17:05","slug":"what-american-enterprises-can-learn-from-europeaposs-gdpr-mistakes","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/20\/what-american-enterprises-can-learn-from-europeaposs-gdpr-mistakes\/","title":{"rendered":"What American Enterprises Can Learn From Europe&amp;apos;s GDPR Mistakes"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt4e9807662d546d74\/664b5fc271d5bf3dd318c6dd\/Privacy_Egor_Kotenko_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/what-american-enterprises-can-learn-from-europeaposs-gdpr-mistakes.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/what-american-enterprises-can-learn-from-europeaposs-gdpr-mistakes.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">After almost a decade of &#8220;will they or won&#8217;t they,&#8221; the United States is on the cusp of its own sweeping data privacy law.&nbsp;The recently proposed&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.spiceworks.com\/it-security\/data-security\/news\/us-lawmakers-reveal-bipartisan-data-privacy-legislation\/\" rel=\"noopener\">American Privacy Rights Act (APRA)<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> aims to establish robust regulations about eight years after the implementation of Europe&#8217;s General Data Protection Regulation (GDPR).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/thought-gdpr-compliance-was-hard-buckle-up\" rel=\"noopener\">the road to compliance won&#8217;t be smooth<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. A look back at Europe&#8217;s experience with the GDPR suggests significant business growing pains on the horizon. Even before the regulation kicked in,&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/uk.insight.com\/content\/dam\/insight\/EMEA\/blog\/2017\/06\/GDPR-Infographic-design-final.pdf\" rel=\"noopener\">one-third of EU companies<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;were concerned their technology couldn&#8217;t effectively manage data. Those fears proved well-founded as organizations grappled with the GDPR&#8217;s expansive scope, complex risk assessments, and stringent recordkeeping requirements. On average, firms spent a staggering <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/abs\/pii\/S0950584922000362\" rel=\"noopener\">1.3 million euros<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> just to prepare for the new rules.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As the US braces for its data privacy overhaul, enterprises should take heed of Europe&#8217;s trials and tribulations. Staying ahead of APRA by updating data practices, training staff, and ensuring compliance from the outset will be critical to avoiding the same costly missteps.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Long Road to Data Privacy\">The Long Road to Data Privacy<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">There&#8217;s a sense of inevitability regarding data privacy in the US. Slowly but surely, from California&#8217;s Consumer Privacy Act to Virginia&#8217;s Consumer Data Protection Act, states have taken the lead in the absence of national regulation. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/converging-state-privacy-laws-emerging-ai-challenge\" rel=\"noopener\">Eight more states are ready to enact comprehensive privacy laws<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in the next two years.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">State regulation is good for privacy, of course, but it creates a patchwork of varied rules. A federal approach would preempt the state legislation, level the playing field, and offer much-needed predictability for companies. Importantly,&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.pewresearch.org\/short-reads\/2023\/10\/18\/key-findings-about-americans-and-data-privacy\/\" rel=\"noopener\">polling data shows<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;broad public support for stricter data privacy across the political spectrum.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The bipartisan proposal makes for familiar reading. Much like GDPR, APRA puts the onus on companies to abide by stronger data security standards or face sanctions, giving consumers the power to opt out of targeted advertising and minimize the personal data held on them.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In theory, APRA is an overdue safeguard for consumers and their information. In practice, as shown by Europe&#8217;s GDPR, following the letter of the law is easier said than done.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Europe Is a Peek at the Future\">Europe Is a Peek at the Future<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The GDPR asked big questions about how companies handle consumer data. European companies needed big answers and fast, especially with potential fines of 20 million euros or 4% of annual turnover. The rush to compliance resulted in errors and inefficiencies that still ripple to this day.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">First, there&#8217;s the sheer scope of the regulation. European businesses grappled with overhauling their data management infrastructure from tracking life cycles to adhering to specific storage protocols. Companies without a clear policy or internal champion struggled to revamp existing systems and processes.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Training, or lack thereof, further hamstrung compliance efforts. Management didn&#8217;t always communicate the new data demands nor instruct employees on their evolving roles and responsibilities. This resulted in human error, like failure to safeguard personal data or sharing data with unauthorized parties.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Third, some made the mistake of not asking for help. Smaller businesses couldn&#8217;t keep up with the risk assessments or record-keeping required by the regulation. Again, without proper data mapping and a concrete understanding of responsibilities, companies set themselves up for failure.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Even today, these issues put full compliance out of reach for the majority of European companies.&nbsp; <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/noyb.eu\/sites\/default\/files\/2024-01\/GDPR_a%20culture%20of%20non-compliance.pdf\" rel=\"noopener\">A report published in January<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;surveyed more than 1,000 privacy professionals, only 7% of whom believe that &#8220;most&#8221; controllers completely comply with any chapter of the GDPR. Additionally, three-quarters share there are still relevant violations at an average company.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The lesson for American companies on the eve of our own data privacy regulation? Prepare now.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Get Ahead of the Regulation\">Get Ahead of the Regulation<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Even if APRA faces hurdles in this election year, which is likely, there is momentum behind federal data oversight. Each passing state adds weight to the argument, and a tipping point is near.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">American enterprises should take advantage of this important window. Get started early by creating or double-checking your data protection plan. Consider hiring a data protection officer, someone who monitors your ecosystem and understands where your consumer data lives. Importantly, this person can work closely with the executive team and ensure all stakeholders understand the importance of protecting consumer data (and the liability of not doing so).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Then, bring your employees along for the ride. Tailor training for employees based on their specific interaction with consumer data. This isn&#8217;t a one-off but an ongoing activity that ensures the entire team understands best practices, what&#8217;s at stake, and how to comply.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Finally, adopt intelligent tools and platforms that automate critical data responsibilities. Compliance solutions can be invaluable by continuously monitoring and gathering evidence of a company&#8217;s security controls. Additionally, unified endpoint management can facilitate data encryption and containerization while enforcing strong passwords and software updates. These platforms can also automate recordkeeping and error-logging processes. Further, implementing zero-trust security models, where no device is inherently trusted, can significantly reinforce your organization&#8217;s security posture and better protect consumer data.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Getting ahead of data privacy isn&#8217;t just a feel-good exercise \u2014 it&#8217;s critical for avoiding the regulation pitfalls experienced by European businesses. By developing data protection plans, training staff, and automating now, American businesses can prepare for the inevitable and maintain public trust.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/what-american-enterprises-can-learn-from-europe-gdpr-mistakes\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>After almost a decade of &#8220;will they or won&#8217;t they,&#8221;<\/p>\n","protected":false},"author":12,"featured_media":3641,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3640","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/what-american-enterprises-can-learn-from-europeaposs-gdpr-mistakes.jpg?fit=1819%2C1069&ssl=1",1819,1069,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/what-american-enterprises-can-learn-from-europeaposs-gdpr-mistakes.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/what-american-enterprises-can-learn-from-europeaposs-gdpr-mistakes.jpg?fit=300%2C176&ssl=1",300,176,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/what-american-enterprises-can-learn-from-europeaposs-gdpr-mistakes.jpg?fit=640%2C376&ssl=1",640,376,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/what-american-enterprises-can-learn-from-europeaposs-gdpr-mistakes.jpg?fit=640%2C376&ssl=1",640,376,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/what-american-enterprises-can-learn-from-europeaposs-gdpr-mistakes.jpg?fit=1536%2C903&ssl=1",1536,903,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/what-american-enterprises-can-learn-from-europeaposs-gdpr-mistakes.jpg?fit=1819%2C1069&ssl=1",1819,1069,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/what-american-enterprises-can-learn-from-europeaposs-gdpr-mistakes.jpg?fit=1024%2C602&ssl=1",1024,602,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/what-american-enterprises-can-learn-from-europeaposs-gdpr-mistakes.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/what-american-enterprises-can-learn-from-europeaposs-gdpr-mistakes.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/what-american-enterprises-can-learn-from-europeaposs-gdpr-mistakes.jpg?fit=1819%2C1069&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3640","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3640"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3640\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3641"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3640"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3640"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3640"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}