Impact Note: GDPR
- Date:October 18, 2017
- Author(s):
- Test
- Sean Sposito
- Research Topic(s):
- Cybersecurity
- Fraud & Security
- PAID CONTENT
Overview
On May 25, 2018, when the European Union’s landmark General Data Protection Regulation (GDPR) is scheduled to take effect, few, if any, financial institutions will be confident they’re in full compliance, here or abroad. The sweeping mandate — containing 99 articles and 173 recitals — basically covers everyone who resides in the EU.1 It also protects a broader set of personal data beyond the Social Security numbers, dates of birth, and addresses that are usually considered personally identifiable information in the United States. In the context of GDPR, personal data2 are defined as “any information relating to an identified or identifiable natural person.” That may include IP addresses; “social media posts; photographs; lifestyle preferences; and transaction histories” — regardless of format, digital, paper, audio, or otherwise.3,4 In short, FIs should assume that GDPR could potentially cover all of the data it stores on behalf of its customers and employees — especially dual citizens and overseas website visitors.
Book a Meeting with the Author
Related content
2025 Dark Web Threat Intelligence Vendor Scorecard
Javelin’s newest cybersecurity scorecard, the 2025 Dark Web Threat Intelligence Vendor Scorecard, evaluates leading dark web threat intelligence vendors on the market today. This i...
2026 Cybersecurity Trends
In the year ahead, financial services will face several trending challenges as they try to keep organizations and customers safe. Zero trust will come to the forefront of supply ch...
Social Signals, Malicious Motives: Emojis as a Cyber Weapon
Cybercriminals leverage emojis to evade defenses and use them in phishing and spoofing attacks to deceive victims and steal sensitive information. Emojis are also used to control c...
Make informed decisions in a digital financial world