Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • PM Modi in Manipur
  • Charlie Kirk killer
  • Sushila Karki
  • IND vs PAK
  • India-US ties
  • New human organ
  • Downton Abbey: The Grand Finale Movie Review
fp-logo
It's Time For Cos To Create An Exit Strategy For Mgmt Of Personal Data: Gartner
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Business
  • Biztech
  • It's Time For Cos To Create An Exit Strategy For Mgmt Of Personal Data: Gartner

It's Time For Cos To Create An Exit Strategy For Mgmt Of Personal Data: Gartner

FP Archives • February 3, 2017, 00:06:33 IST
Whatsapp Facebook Twitter

Organisations should create a privacy program that keeps personal data not only at arm’s length, but under control, according to Gartner.

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
It's Time For Cos To Create An Exit Strategy For Mgmt Of Personal Data: Gartner

Organisations should create a privacy program that keeps personal data at arm’s length, but under control, according to Gartner, Inc. Gartner predicts that by 2019, 90 percent of organisations will have personal data on IT systems that they don’t own or control.

Enterprises have traditionally been the target of security threats, and until recently, those hackers focused on attacking vulnerable IT infrastructure. As protection for such infrastructure improves, the attackers’ attention shifts to softer targets, such as employees, contract workers, customers, citizens and patients.

STORY CONTINUES BELOW THIS AD

“As the amount of personal information increases multifold, individuals and their personal data will increasingly become a security target. And, yet in most scenarios the organisation is still ultimately accountable for the personal data on its IT systems,” said Carsten Casper, Research Vice President at Gartner. “The time has come to create an exit strategy for the management of personal data. Strategic planning leaders will want to move away from storing and processing personal data in the next five years.”

More from Biztech
Future Group - Reliance Retail Deal approved by CCI Future Group - Reliance Retail Deal approved by CCI RBI ban on cryptocurrencies takes effect; prohibition could force investors to tap the black market RBI ban on cryptocurrencies takes effect; prohibition could force investors to tap the black market

“The PCI Data Security Standard (DSS) requires the implementation of stringent controls of those who collect and store credit card data. In response, many companies have decided to eliminate credit card data from their own systems and completely entrust it to an external service provider,” said Casper. “The same could happen with personal data. If control requirements are too strong and implementation is too costly, it would make sense to hand over personal data to a specialised ‘personal-data processor’”

Gartner has identified the following steps to prepare for such a strategy:

Create Clear Delineations Between Personal and Non-personal Data

The first step should be to create a policy that draws a clear line between data that relates to human beings and data that does not. The former category includes contact information and health and financial information, as well as an Internet Protocol address, geolocation data and other traces an individual leaves in the online world. The latter category especially includes business plans, corporate financial data and intellectual property. Separating the two is necessary, because different laws apply.

The true challenge resides in handling data that can fall into both categories. Whether an organisation decides for or against declaring certain types of data as “personal data” depends on the organisation’s risk appetite. In most cases, companies tend to prefer to risk a little rebuke from a regulator rather than having to re-engineer complete business processes.

STORY CONTINUES BELOW THIS AD

Put a Fence Around Personal Data

Even the best data protection policy is worthless if you can’t live by it. Locating and documenting personal data have to go hand-in-hand with creating the policy. Once personal data has been located, it needs to be protected. Encryption is the most widely used protective control. An additional challenge exists where the organisation does not own the underlying IT infrastructure — be it a mobile device or a cloud environment.

Favour Purpose-Built Over General-Purpose Applications

Personal data should not be combined with other data, if possible. Any technology that processes personal data in the same way it processes non-personal data creates a risk. Content should be analysed before decisions are made about protection. Such decisions are easier if employee performance information is stored in an HR management system, customer information is stored in a CRM system, and financial and business information is stored in an ERP system.

Adhere to Privacy Standards, or Create Your Own

STORY CONTINUES BELOW THIS AD

Compliance with dozens of privacy laws and cultural expectations from multiple regions can be costly. Privacy standards simplify control frameworks, audits and information exchange, especially in scenarios where many players and stakeholders are involved. Regardless of the specific privacy standard and cross-border transfer mechanism used, the most difficult challenge for organisations is to make such rules binding on all entities involved, including all employees, and accept liability in cases where employees or customers suffer harm.

Logical Location Rules Over Physical and Legal Location

Privacy expectations are still influenced by laws, and jurisdictions have physical boundaries. This collides with the IT reality of cloud and mobile computing. The physical location is the location where the electrons and bytes are stored. Given that this information can be accessed from the other end of the world in a fraction of a second, the physical location should be increasingly irrelevant. Yet this physical location is still what many regulators insist on, although the legal location should be most relevant from a regulatory perspective.

STORY CONTINUES BELOW THIS AD

Companies and service providers prefer to move toward a more pragmatic approach — the logical location. As an example, personal data might be stored in a datacentre of a U.S. cloud provider, which is operated by a third-party service provider from India. However, data is encrypted, the Indian IT employees manage only routers and servers, and only European employees of the client can actually see the data. These employees are located in Europe, and bound by a European employment contract and European privacy laws. Logically, the data is in Europe, although legally and physically, it may be somewhere else.

Tags
strategy Management Gartner data Personal
End of Article
Written by FP Archives

see more

Latest News
Find us on YouTube
Subscribe
End of Article

Top Stories

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV