Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


02:30 PM
Marc French
Marc French
Connect Directly
E-Mail vvv

GDPR 101: Keeping Data Safe Throughout the 'Supply Chain'

There are a lot of moving pieces involved with data collection, retention, and processing in the EU's new General Data Protection Regulation. Here's how to break down responsibilities between your security team and service providers.

While there has been a lot of chatter about the magnitude of penalties organizations may find themselves hit with (up to €20 million in fines) under the impending General Data Protection Regulation (GDPR), there isn't nearly enough talk about how to avoid penalties in the first place.

Sure, there are conversations about pre-ticked opt-in boxes and breach notification protocols ("You have 72 hours to report personal data breaches to the appropriate authorities," for one). But businesses are failing to address the root of the problem — the data itself.

To ensure compliance with GDPR, personal data must be kept only for as long as necessary, an issue that clearly is up for debate, as length of time varies by organization and industry. Then there is the "right to be forgotten," which means that data subjects can request that their data be deleted at any time.

But to understand how to identify, recall, and protect that data, organizations must first understand the nature of the data itself. For example, if I, Marc French, log in to your website, you need to keep track of where I go — and in a timely manner. If I ask for you to remove my data so the Googles and Facebooks of the world can't access bits and pieces of my "identity," you're now obligated by law to destroy any trace of it. And, if you don't know where that data is, you can't get rid of it.

Whether it's in the finance department's hands, the marketing department's in-boxes, or even with your shipping company for deliveries, there are a lot of different parties that are constantly using, holding, and updating personal data. That's why it's important to look at the data custody process in terms of tiers and outside forces — a supply chain, essentially.

Here are three examples of supply chain data you might not be considering but that could have GDPR impacts:

1. Escalation personnel phone numbers of your European IT staff for the cloud service to which you subscribe. Phone numbers are personal data, and you need to ensure that they do not leave the cloud service to its downstream partners without your consent.

2. The event registration data you collected for that big marketing conference that includes dietary restrictions for attendees. Not only is the attendee registration data considered personal data, but you are now also collecting sensitive medical data by way of the dietary restrictions. Because of this, you need to track what the caterer is doing with the information that is provided.

3. Your building's security desk that signs in visitors to your office, prints a badge, and gives it to the visitor, who later returns it upon leaving. Not only is data on the badge likely personal, but how you dispose of it, or how the security vendor handles it in its system, has GDPR implications.

As you can see with data collection, retention, and processing, there are a lot of moving pieces involved, and each of these parties comes into contact with personal data at some point along the line. Because of this, there's now a responsibility for both data processors (such as service providers) and data controllers (such as your organization) to work together in the case of a breach under GDPR.

According to the regulations, both parties might be liable for breaking the law and are required to notify regulators, their customers, and end users, and, ultimately, both parties are obligated to pay all fines and compensate customers for damages. If anyone in your supply chain loses control of the data, you too may also be responsible — and experience both pricey financial and reputational costs.

Before you develop a plan for working with the different tiers, the first step will be to consider how you classify the data. It's important that you qualify the data you collect and determine its value/risk to the business before doing anything else. For example: Is the data critical to your revenue stream (credit card data), or would the loss of the data be catastrophic to your intellectual property strategy (formula to your specialty cola)? If so, you rate the risk/value high.

Next, you'll need to rank your vendors. Ask employees who are provisioning new vendors what data they are collecting, and then rank the vendors based on the data valuation you developed during step one. They'll typically be split into two levels, which many organizations break down as:

Tier 1: Vendors that operate on the most sensitive data you have. You will want to do a dive deep with these folks and conduct a thorough vendor review, ensure contractual protections, and regularly review them for compliance and security.

Tier 2:  These vendors may operate on less sensitive data. Keep track of these folks in a central system on a regular schedule, so you can dust the list off and sample your internal customers to see if they are using additional services that might elevate them to tier 1. You may be surprised that the tier 2 vendor you set up two years ago has become tier 1 as the partnership has evolved.

With the GDPR deadline upon us, it is important to start work closely with tier 1 and tier 2 vendors to guide your organization's data protection strategy moving forward.

Related Content:

Marc French is the senior vice president and chief trust officer at Mimecast. He has more than 25 years of technology experience in engineering, operations, product management, and security. Prior to his current role, Marc was the CSO of Endurance International Group/Constant ... View Full Bio

Recommended Reading:

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/25/2020
9 Tips to Prepare for the Future of Cloud & Network Security
Kelly Sheridan, Staff Editor, Dark Reading,  9/28/2020
Attacker Dwell Time: Ransomware's Most Important Metric
Ricardo Villadiego, Founder and CEO of Lumu,  9/30/2020
Register for Dark Reading Newsletters
White Papers
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2020-10-01
Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from before version 3.4.6 and from 3.5.0 before 3.5.1.
PUBLISHED: 2020-10-01
The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in link targets.
PUBLISHED: 2020-09-30
An issue was discovered in MantisBT before 2.24.3. When editing an Issue in a Project where a Custom Field with a crafted Regular Expression property is used, improper escaping of the corresponding form input's pattern attribute allows HTML injection and, if CSP settings permit, execution of arbitra...
PUBLISHED: 2020-09-30
An issue was discovered in file_download.php in MantisBT before 2.24.3. Users without access to view private issue notes are able to download the (supposedly private) attachments linked to these notes by accessing the corresponding file download URL directly.
PUBLISHED: 2020-09-30
An issue was discovered in MantisBT before 2.24.3. Improper escaping of a custom field's name allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript when attempting to update said custom field via bug_actiongroup_page.php.