GDPR and employee data protection: Cyber security data example
Deborah Watson, Ryan Millerick — Cyber Security: A Peer-Reviewed Journal
How it connects
Related across sources
Full text
This paper explores the implications of the European Union (EU) General Data Protection Regulation (GDPR) on employee personal data, specific to data elements that might be collected by Information Security (IS) in the effort to protect and defend the environment from data breach and exfiltration. GDPR compliance became effective in May 2018, and many organisations are still working through the strategic complexities of GDPR’s impact on their organisation. Using an example of a phishing assessment data set, the paper traverses the potential challenges that an organisation is likely to face. GDPR further defines sensitive information, and using this phishing assessment data, the paper illustrates a project data flow that defines what data would exist, its sensitivity level, the data owner, the data source, the data use, data retention and destruction considerations, as well as reporting and storage.