CTO Advisor 067: Should you worry about GDPR?

We are currently in the grace period for GDPR. Should you be worried? With a potential fine of 4% of your organization’s revenue for each penalty, the regulation has teeth. GDPR is a case where size doesn’t matter. I sat down with PivotNine’s Justin Warren and CommVault’s Nigel Tazor to discuss the impact and considerations. Subscribe iTunes | RSS

Transcript 3,205 words · about 21 min to read

Machine-generated from the episode audio and not hand-corrected, so names and technical terms may be imperfect. The audio is authoritative.

Hey, how's it going? com, and you're listening to episode 66 of the CTO Advisor Podcast. We're without Mark this week. However, we have two great guests on the line. Well, no, not on the line. -based company, do you have to worry about GDPR? GDPR is the European Regulatory Actions Geared Towards Protecting Citizens' Data Within Corporations. , what does that matter to me? We talked through that. Before we start the conversation, we'd like to thank our sponsor, Druva.

Druva is the industry's first data management as a service, a single SaaS platform that unifies data protection and management for endpoints, infrastructure, cloud applications. Unlike traditional systems, Druva aggregates the business-critical data for scalable backup and disaster recovery, while also unlocking the true value of search and advanced analytics. For administrators, Druva means simplification. For IT leaders, Druva means scalability. For CFOs, saving a boatload of money. For InfoSec, security, by design, to the highest standards. And for VMware administrators, Druva means unified backup, disaster recovery, and archiving, all powered by AWS.

Druva roughly translates to saving your butt from data loss, litigation, mishaps, and regulatory fines. Druva, the future of cloud data protection. Now our conversation. All right. We get a two-four for CTO daily doses. We're still at Commvault Go, and Justin is still with me. We've been refreshed, and we just randomly plucked someone off of the show floor. Nigel, you want to go ahead and introduce yourself? Yeah, my name's Nigel. I'm the CEO of Commvault Go. I'm the CEO of Commvault Go.

I'm the CEO of Commvault Go. I'm the CEO of Commvault Go. I'm the CEO of Commvault Go. I'm the CEO of Commvault Go. I'm the CEO of Commvault Go. I'm the CEO of Commvault Go. My name's Nigel Toza. I'm the Solutions Marketing Director for Commvault in EMEA. All right. So big fines, big fines, big fines. GDPR is right around the corner, and, Justin, you look like an expert in all things. So I'm just going to throw this out to you.

Can you explain to the CTO Advisor audience what GDPR is in a nutshell? No. As if you can calculate it in a nutshell. So it is the General Data Protection Regulation, which has been passed by the EU, which basically means that if you are a resident of the EU, then your data needs to be protected. And it doesn't matter where in the world it's stored. If you're a company that is processing data that either originates from or relates to in some way a citizen of the EU, this regulation applies to you.

So, Nigel, this regulation actually has some pretty significant teeth. This isn't like the stuff that organizations have gotten deemed for in the past, where, you know, it was just a $250 million fine. Up to 4% of global revenue per incident. I don't know. Have you guys heard? Is there a max? There is no max. There's no max. And if you have a subsidiary that breaches the regulation, it actually applies to the global parent. Yeah. So that's where it gets really serious.

So, first off, most people are hoping that this just goes away. And it doesn't become, you know, not necessarily goes away, but it's scheduled to be implemented May of 2018. And people are hoping that the European Union kicks the regular enforcement down the road a little bit. But I don't get the impression that's what's going to happen. No, it's not. We're technically already in the grace period. It's technically already a law. It just gets enacted in May next year.

And, you know, I think the regulators, they're going to look for if you're trying to be compliant. If you are and you've done all the right things, then I think, you know, those things are going to mitigate those sort of fines. But I think organizations that just flaunt the rules, say they don't care, then they're the ones that I think are going to get hit. S. accent, I think. S. centric at times. When you think of, you know, things like HIPAA, PII, security first, how is this different from those considerations?

S. company, it's GDPR that's getting all the headlines. But there's actually a lot of privacy regulations all over the world. You know, Australia, Japan, Singapore, China, South Africa enacted a similar kind of regulation earlier this year. You know, privacy is on the table in a lot of countries. So by going to the higher standard, you're going to help to cover yourself when you're trading all over the world. S. S. laws. Yeah, I think globally, I'm not sure that American companies realize, particularly in Silicon Valley, just how much the rest of the world is sick of their privacy and data protection not being taken seriously.

You know, that's always the tagline. Whenever there's a security breach, we take security seriously. And the way certain particularly very large American companies have basically not paid any attention to data privacy for individuals, it's not as big of a cultural thing in America, but it's far broader in the EU and where I come from in Australia. So I think that they're going to have to start taking that more seriously than they do or start being sensitive to those sort of cultural differences rather than trying to just bluster their way through that they've done, because people generally worldwide are pretty sick of it.

And it's it's now front of mind all the time. You can't open any kind of tech publication or go to a media site these days without data being called the new oil. And it's misuse of data. And all these things have happened since the last lot of data regulations were put in place. So that the world has changed around and even GDPR says that you now have to be a state of the art. And that worries some people, like, how do you define that?

What they're trying to do is make the regulation so that as business and the way we process and change technologies, it's still got to apply to that, too, because they don't want to go make some new regulations down the line. So it does seem to be a little bit more of the European tradition of law as well, which is different from the US. The US seems to be much more rule based where you need to comply with this specific rule. And if you if it's if you do something which is slightly different, that's OK, because the rule doesn't specifically say you can't do that.

Whereas certainly the European tradition and in Australia, we follow pretty much that, which is more around the method and the intent of law rather than the specific rules. So there are it is open to interpretation. And the intent there is that through the judicial system, as as cases are litigated, some of the specifics are worked out through litigation. So I think you're right, Nigel, that the companies that attempt to do things well and at least make a basic, you know, when we say what is state of the art, that'll be defined when people breach it.

You will. Yeah. And those who've made a genuine attempt, I think, will be treated far more leniently than any company that just says, you know what, we're just going to bluster our way through and pretend that the legislation doesn't exist and hope for the best of the other side. We'll litigate it on the, we'll litigate it. The US position is, you know what, that law is vague. We'll litigate it when it comes and we'll fight it to the letter. And if it doesn't, if we can win based on some loophole in the letter of the law, it's up to Congress to fix it.

And that generally doesn't happen. Yeah, that approach won't work with this kind of legislation. As Justin said, it's going to be, if you don't comply with the spirit of it, then that's going to get thrown out to the court. So let's shift towards the technology discussion. Even though this is not necessarily a technology first problem, data is the new oil. It's the new gold. I've been to NetApp, Insight, and now to Commvault Gold. This has been a consistent theme that data is a new asset.

And companies are starting to learn how to use this data to their advantage. So data is precious. If I have data on a European citizen and I'm a US-focused company, that's a valuable thing. And I don't want to have to give it up if I don't have to. But I'm forced to do so in certain cases. How do I start to compartmentalize, is the word I'm looking for, data for potentially US citizens, non-US citizens, keep those valuable assets? Because I don't think the US law is going to change anytime soon.

What I would say, if you're a US business and a global one, there's a lot of mistrust in politics, in business organizations these days. Consumers don't trust that their data is being treated properly, or even safe. And it's not just about being safe, it's about being misused. Are you going to use it for a purpose I never agreed to? Now, if you can take the GDPR regulation in spirit and apply it in the US, when you think about the extra trust you're going to get from your customers, you're going to potentially retain more customers and you're also going to potentially attract new ones because they trust you as an organization.

So there is quite a big benefit about complying with GDPR regulations. It's around the data being an asset. It's not just an asset, it's also a liability. Because if you keep data that you don't necessarily need for any given reason, we just might want to use it at some point for machine learning or AI magic, you're actually placing that data at risk because if you get hacked, if there's some sort of breach from either internal or external ways, then you will lose trust with your customers.

And this is just one of the regulations that you will be in flout of. So not purely looking at data as an asset and not also looking at it as a potential liability means that you're going to make the wrong decisions. I think more companies need to start looking at this as a liability. Going back to what you said about technology, this is one of those people, process and technology problems. You might not expect this from a tech vendor, but I'd say look at your processes and get your people educated first, and your technology needs will come out of that.

It affects everything. It affects your own employees. It's not just about external to your company. If you have European employees, it applies to them. And it doesn't mean you can't process this data. It just means you have to gain consent from the individuals whose data you intend to process. And actually, that's another area that's a big culture difference from the US to Europe. Most of Europe now has moved to an opt-in consent model, whereas here in the US, it's typically an opt-out model.

You have to tick a box to say, I don't want this stuff, or you will get it by default. So a couple of different models that I'm looking at is, one, we're talking about this, and there's the impression that this is a big company problem. If you have to be a Google, Facebook, et cetera, I'm a small business. I maintain a mailing list. I'm pretty sure there's some EU citizens on that mailing list. How does that impact my small business?

You're still obliged to comply with that. The thing is, are we going to get thousands or tens of thousands of regulators to go around every corporate entity, however small? No, that's not going to happen, right? What is going to happen is, if you're complained about to the regulator, then you might get an audit. That's not going to get you a big fine. They'll just probably advise you what to do. If you're a big business and you get a lot of complaints, again, you'll get that audit.

It might get some bad press because they'll put that stuff in the news if they have to. It's really then when you get to the breaches and those kind of things. I've heard some people say, I don't have to be faster than the lion that's chasing me. Just faster than the next guy. If a breach is a random event, that's like tripping up. That lion's going to be ready there to pounce. It's going to be people who make mistakes or are unfortunate that they're going to get hit.

I wonder how does this impact an organization like one of the credit bureaus, like Equifax here in the US? They have my information. I was an EU citizen. I just sent them an email and said, you know what? I don't want you to have my information. I'm not a direct customer of them. They have this relationship with the banks or whatever. I just said, you know what? I just don't want you to have my information. How would that impact that business model and the credit and blah, blah, blah down the road?

I think there's a lot of unanswered questions. It's your privacy statement from the bank and their terms of use. There are some things that you just might not be able to access unless you agree. That's actually problematic for me as an individual. There are some things that I wouldn't want to do that with. I just think that's all up for grabs now. There's going to be some big discussions, big court cases and things that are going to go on around that.

Basically, you can opt in to giving up. I don't think it's a good word. Giving up your privacy rights with a partnership. Just say, you know what? It's okay for you to have my data. It's okay for you to use my data in that way I consent. Then if you decide that that's no longer the case, you have to look at the language of the agreement that you signed. I think there's an opportunity here as well for multiple organizations to review the way in which they use individuals' data.

Again, it's a point of differentiation right now. If you say, actually, we will use your data only with your consent and only with very specific, strict controls around it. If you can credibly claim that and demonstrate that you have a really good culture of privacy and control over your own data, then I think a lot of customers will actually go, yeah, you know what? I'm sick of dealing with all these other people who don't respect my own privacy and don't look after my data.

I choose to go with you. It harks back to the point I made earlier about retaining customers and getting new ones. Actually, later on today here at Go, we're presenting on the business benefits of becoming GDPR compliant. We're talking about the soft benefits around customers. Also, if you treat your staff fairly, you might get better staff retention. There's almost a debit and credit balance of this is bad, this is going to cost me. There's a ton of other things that are going to be cost benefits.

If you collect only the data that you need and only retain it for as long as you need, that's going to affect things like storage purchases, cloud utility billing. It's going to affect the DR and other things that are a cost to your organization. If you start to look at managing dev and test processes instead of just letting the DBAs make database copies whenever they feel like it and you put that into more of an orchestrated tool that's got access and audit controls on it.

Again, our technology allows you to do all those things faster. That thing that you've done to stop you getting breached with a database in the wrong place also helps you be more agile and get dev and test jobs done much quicker, which adds to the bottom line. Actually, it's part of digital transformation. It's putting customers at the center. If you can't tell me things that are going to change just because of GDPR that are automatically going to do that for you as a business, it is a stepping stone to transformation in my opinion.

Let's wrap up. Nigel, where can people find out more about what Commvault is doing with GDPR? com forward slash GDPR, there's a page there. You get to see another great video of me talking if you really want to see that. But more seriously, we have some white papers, not just from Commvault. We've got white papers from analysts external to Gartner, IDC, those kind of organizations, and it's got practical advice. I think one of the biggest deficits we see is so much talk of fines and other things and the threats and all the problems of GDPR.

One thing that's missing is that practical advice. All right. And do you do social media at all? Yeah, me, Nigel, at Nigel Tozer. I'm tweeting all the time. In fact, we also had Sheila Fitzpatrick from NetApp present yesterday. She's one of the big influence on the topic. I interviewed her on the queue. There you go. She's very passionate about this topic. She's fantastic. And I don't just tweet about Commvault, by the way. I had today, yesterday, because it's our conference.

But I try and do a lot on privacy and industry articles and things that can help you learn about it. And Justin? com or you can find me on Twitter most of the time. It's at JP Warren. All right. com. And on Twitter at CTO Advisor. Subscribe to the podcast where we have great content like this. I'll probably publish this as a podcast. We went a little long for a CTO Daily Dose, but I think it was a great conversation and adds value.

Nigel, appreciate it. Thank you. See you soon. Talk to you next, CTO Advisor.