Well, here we are, close of business May 25th, and oh look!, the sun is still shining, the world is still spinning, and no one [decent] went out of business.

What we do have however is an indication of who the world’s biggest muppets are. For example:

Continue reading “GDPR: Now We Know Who the Muppets Are”

If you hadn’t heard of the GDPR before the last month or so, you have now. You have all received at least one, and more likely dozens of emails from organisations with whom you have had some contact in the past. Most of whom you have probably forgotten about. e.g. I hadn’t used my Garmin account for over a decade but still received an email asking if wanted to ‘opt in’ to continue receiving its “many benefits”.

Continue reading “GDPR May 25th – Slow Down and Get it RIGHT!”

Even as a data protection novice, the GDPR makes sense to me. I get it. I may be partly wrong in some assumptions, but I am comfortable enough in my understanding of the intent of the Recitals and Articles to ask the right people the right questions.

All, that is, with the exception of Recital 80 / Article 27 – Representatives.

Continue reading “GDPR: How Will ‘Representatives’ Work?”

If you’re reading this, you likely fall into 1 of 3 camps:

  1. You are horrified at the concept and can’t wait to tear me a new one;
  2. You actually think I may be able to help you make lot of money; or
  3. You know me and realise that the title is nothing but click-bait

If 1., then good for you, I would do the same. If 2., then you’ve come to the wrong place unless you’re prepared to put in significant effort. If 3., then you’re right! 🙂

Continue reading “How to Make Lots of Money From GDPR”

This is the final part in my GDPR Step-by-Step series, and one that, in my cynicism, I see very few organisations even trying to attempt. I have lost count of the number of companies with whom I have tried to implement a continuous compliance program, only to have them stop once they received their initial ‘certification’. In this respect, GDPR will be no different from something like PCI.

Continue reading “GDPR Compliance Step-by-Step: Part 6 – Operationalise”