ASUG News + Views
It’s Get­ting Per­son­al: Your Respon­si­bil­i­ties with EU Data and GDPR
Adrian Bridgwater Apr 29, 2018
Bookmark
Share Article:

There’s a lot hap­pen­ing in Europe at the moment. The Unit­ed King­dom is leav­ing the bloc of 22 Euro­pean Union (EU) nations after the uncom­fort­ably close nation­al ref­er­en­dum vote that led to Brex­it. France and Ger­many are busy get­ting along bet­ter than at any time in recent his­to­ry, giv­en their new sta­tus as de fac­to dual lead­ing Euro­pean nations.

As if the Euro­pean Union (EU) didn’t have enough on its plate right now, the Gen­er­al Data Pro­tec­tion Reg­u­la­tion (GDPR) will take effect on May 25, 2018. Though it’s an EU reg­u­la­tion, the GDPR has the poten­tial to send a rip­ple effect through­out any busi­ness in the world with data on Euro­pean cit­i­zens with­in its systems.

What is the GDPR, and Why Should North Amer­i­ca Care?

This new piece of leg­is­la­tion is intend­ed to pro­tect indi­vid­u­als’ data rights. It requires that any orga­ni­za­tion hold­ing per­son­al data for EU indi­vid­u­als must show that it has tak­en a defined lev­el of com­pli­ance steps to pro­tect that data. To become GDPR com­pli­ant, orga­ni­za­tions must also show that they com­ply with stip­u­la­tions gov­ern­ing how that data is man­aged and audited.

What kind of EU cit­i­zen per­son­al infor­ma­tion does it cov­er? The extent of the answer may sur­prise you. It includes cred­it card num­bers, bank­ing details, health reports, and even user data as seem­ing­ly insignif­i­cant as video game login details.

GDPR, a Glob­al Issue

Which nations are affect­ed by GDPR? The answer is sweep­ing. It will apply to all Euro­pean firms, includ­ing the British (despite their EU depar­ture). It will also affect all glob­al firms includ­ing those in the Unit­ed States and Cana­da that hold any per­son­al data relat­ing to EU cit­i­zens. Deep­er still, any U.S. or Cana­di­an firm that offers goods or ser­vices to EU res­i­dents or mon­i­tors their com­mer­cial or per­son­al behav­ior in any form (such as track­ing their buy­ing habits), will be required to com­ply with the GDPR.

A Poten­tial­ly Expen­sive Data Problem

Accord­ing to mlaw group, The pro­posed new EU data pro­tec­tion régime extends the scope of the EU data pro­tec­tion law to all for­eign com­pa­nies pro­cess­ing data of EU res­i­dents. It pro­vides for a har­mo­niza­tion of the data pro­tec­tion reg­u­la­tions through­out the EU, there­by mak­ing it eas­i­er for non-Euro­pean com­pa­nies to com­ply with these reg­u­la­tions; how­ev­er, this comes at the cost of a strict data pro­tec­tion com­pli­ance régime with severe penal­ties of up to 4 per­cent of world­wide turnover.”

That last line was impor­tant. The EU has promised that it will issue penal­ties to North Amer­i­can firms (or any for­eign orga­ni­za­tion) of up to 4 per­cent of world­wide turnover. Can North Amer­i­can firms just ignore those fines if they come? It’s dif­fi­cult to say how the inter­na­tion­al legal ram­i­fi­ca­tions and con­se­quences would ulti­mate­ly play out, but we can safe­ly assume that it would dent any firm’s abil­i­ty to con­tin­ue trad­ing with Europe in a full-blown capacity.

GDPR, an Issue for SAP Customers

It’s not hard to form the log­i­cal link between GDPR and SAP sys­tems. As ASUG mem­bers are all too aware, the major­i­ty of SAP sys­tems are deployed in what are clas­si­fied as mis­sion-crit­i­cal envi­ron­ments where busi­ness data relates to spe­cif­ic peo­ple and enti­ties. SAP itself has remind­ed enter­pris­es that they need to car­ry out Data Pro­tec­tion Impact Assess­ments (DPIAs) as a part of their over­all risk man­age­ment strat­e­gy to address GDPR. Many ASUG mem­bers may also now be think­ing about appoint­ing a Data Pro­tec­tion Offi­cer – if they don’t have one already.

The Risk of Dark Data May Lurk in Your Systems

The risk with GDPR ampli­fies when com­pa­nies har­bor so-called dark data. Gart­ner defines dark data as the infor­ma­tion assets orga­ni­za­tions col­lect, process, and store dur­ing reg­u­lar activ­i­ties, but gen­er­al­ly fail to use for oth­er pur­pos­es such as ana­lyt­ics or direct mon­e­ti­za­tion. This is the type of data that SAP cus­tomers may have in their vaults right now and regard as innocu­ous or incon­se­quen­tial. But it could put com­pa­nies at risk of GDPR noncompliance.

Once GDPR enforce­ment starts, com­pa­nies can retain per­son­al data for EU cit­i­zens if it is still being used for the orig­i­nal pur­pose that was stat­ed to that indi­vid­ual when the data was col­lect­ed. And com­pa­nies must delete this per­son­al data when it is no longer need­ed for that purpose.

When it comes to GDPR pre­pared­ness, on a scale of zero to one hun­dred, there are quite a few, most­ly small­er firms that are at zero, where­as most of the largest firms with inter­na­tion­al oper­a­tions are some­where between 90 and 95, and no one is at 100,” said Tim­o­thy Blank, man­ag­ing part­ner of the Boston office of the law firm Dechert, LLP and head of its data pri­va­cy and cyber­se­cu­ri­ty prac­tice, in an inter­view with Reuters.

SAP GDPR Resources

Tech­nolo­gies exist across sev­er­al of SAP’s major prod­uct lines to assist with GDPR com­pli­ance. SAP offers four core tools that can help: SAP Infor­ma­tion Life­cy­cle Man­age­ment, SAP Data Ser­vices and Infor­ma­tion Stew­ard, SAP Process Con­trol, and SAP Access Control.

SAP pro­vides fea­tures and tools that can be used as part of an over­all com­pli­ance effort, as well. These tools pro­vide key func­tions, such as locat­ing where per­son­al data exists in your sys­tems, delet­ing per­son­al data, restrict­ing and log­ging access to per­son­al data (includ­ing reads and changes), and mask­ing per­son­al data to make it anonymous.

SAP Gov­er­nance, Risk, and Com­pli­ance users can sign up for the Cus­tomer Engage­ment Ini­tia­tive, which gives SAP cus­tomers access to a col­lab­o­ra­tive project designed to help users improve their pri­va­cy man­age­ment pro­grams with SAP Gov­er­nance, Risk, and Com­pli­ance. A com­pre­hen­sive guide is avail­able here. This doc­u­ment down­load high­lights what you need to know about GDPR and SAP S/4HANA.

Catch up on this top­ic by watch­ing the record­ed web­casts in our GDPR Series.

You Might Be Interested In


Insights Included in Membership
View All Insights
Bookmark
Bookmark
Bookmark
Bookmark