Two years after the GDPR, a standard helps companies
Since the entry into force of the European Data Protection Regulation (GDPR) in the EU in May 2018, many companies are struggling to comply. Not out of laziness and disinterest, but out of difficulty. The International Organization for Standardization (ISO) helps them
For many companies confronted with the management and protection of their customers’ personal data, the brainteaser has been going on for almost two years. The reason? On 25 May 2018 the European Data Protection Regulation (GDPR) entered into force in the Union. It aims no more and no less than to empower EU citizens with regard to personal data. Broadly speaking, the GDPR, gives more rights to individuals such as the right to forget and portability.
In other words, every European can now demand to know which companies collect his data, in what context and for what purposes. He may decide to transfer his personal information to the platform or company of his choice. Take the example of an Amazon customer who wants to shop online on Zalando. The latter will be able to transfer his data from one to the other (portability) and to require Amazon to delete all its data (right to oblivion). What’s wrong with that?
A late awakening
While the regulation empowers citizens, it obliges companies to ensure the informed consent of individuals for the collection and processing of their data. A change in mentality and practices that companies have been struggling to understand. Indeed, the deadline of 25 May 2018 had been known for a long time. But at the time of the implementation of the GDPR, only a handful of companies that manage, collect and monetize personal data compliant. Even today.
Let’s not blame them. The GDPR is a complex text, subject to multiple interpretations. Moreover, the authorities in charge of the issue failed by their lack of communication. At least as far as companies outside the EU are concerned. It is difficult in this context to mobilize companies that are struggling to find their way. Especially in Switzerland. Because if the regulation is European, it also concerns Swiss companies – both SME and multinationals. But which ones? For which services? In which sector? And what is meant by personal data? How can this legislative change be translated into reality? What are the costs of complying with the European regulation?
A profound cultural change
The International Organization for Standardization (ISO) is helping companies to better comply with the new regulation. It has just published a new standard ISO/IEC 27701. It specifies the requirements and guidelines to be followed by any organization with regard to the management of privacy in the digital age and its protection. This standard therefore aims at information security, cybersecurity and privacy protection.
In addition, it assists companies of all sizes in difficulty with the application of the GDPR in the implementation of a certification strategy for their various organizations. But why? Because the GDPR is not a simple alibi protecting the citizen-consumer. It is a regulation that radically changes the processes, management and safety policy of companies. In short, it is a profound cultural change. A real opportunity for Swiss companies to adapt to the new digital environment to better face it.






