Case Studies

Shredding tracker

by Mark Rowe

Most, 84 per cent of UK small business owners and 43pc of senior executives of large companies are unaware of the forthcoming General Data Protection Regulation. That is according to information destruction and shredding contract firm Shred-it’s seventh annual Security Tracker research, conducted by Ipsos.

The General Data Protection Regulation (GDPR) is due to replace existing European data protection laws from May 2018, covering the European Union (EU) and the UK regardless of the 2016 vote for Brexit.

The Security Tracker survey also found that only 14pc of small business owners and 31pc of senior executives were able to correctly identify the fine associated with the new regulation – up to 20 million euros or 4pc of global turnover. This is despite a large proportion of senior executives (95pc) and small business owners (87pc) claiming to have at least some understanding of their industry’s legal requirements.

Businesses which are unaware of the forthcoming legislation and its implications are not only putting themselves at risk of severe financial penalties, the shredding firm says, but also the reputational damage caused by adverse publicity associated with falling foul of the law. This can often have a greater impact than the fine itself, according to the firm. Of those respondents who claim to be aware of the legislation change, only 40pc of senior executives have already begun to take action in preparation for the GDPR, in spite of 60pc agreeing that the change in legislation would put pressure on their organisation to change its policies related to information security.

The survey also highlights that companies feel the UK Government needs to take more action. Some 41 per cent of small business owners (an 8pc increase from 2016) believe that the Government’s commitment to information security needs improvement.

Robert Guice, Senior Vice President Shred-it EMEAA, said: “As we approach May 2018, it’s crucial that organisations of all sizes begin to take a proactive approach in preparing for the incoming GDPR. From implementing stricter internal data protection procedures such as staff training, internal processing audits and reviews of HR policies, to ensuring greater transparency around the use of personal information, businesses must be aware of how the legislation will affect their company to ensure they are fully compliant.”

“Governmental bodies such as the Information Commissioner’s Office (ICO), must take a leading role in supporting businesses to get GDPR ready, by helping them to understand the preparation needed and the urgency in acting now. The closer Government, information security experts and UK businesses work together, the better equipped organisations will find themselves come May 2018.”

Related News

  • Case Studies

    Homeland award

    by Mark Rowe

    In the US, the federal Department of Homeland Security announced that Monsignor John Brown, Walgreens drugstores, and the New York Mets have…

  • Case Studies

    Sobriety tags

    by Mark Rowe

    Offenders in south Wales who commit alcohol-related crimes can now be ordered to wear a sobriety tag to ensure that they are…

Newsletter

Subscribe to our weekly newsletter to stay on top of security news and events.

© 2024 Professional Security Magazine. All rights reserved.

Website by MSEC Marketing