{"id":36872,"date":"2018-05-25T10:43:08","date_gmt":"2018-05-25T08:43:08","guid":{"rendered":"https:\/\/owncloud.com\/?p=36872"},"modified":"2020-10-21T15:30:17","modified_gmt":"2020-10-21T15:30:17","slug":"welcome-to-a-gdpr-world","status":"publish","type":"post","link":"https:\/\/owncloud.com\/de\/blogs\/welcome-to-a-gdpr-world\/","title":{"rendered":"Welcome to a GDPR World"},"content":{"rendered":"<p>Today on May 25, 2018 is the day that the EU-General Data Protection Regulation (GDPR) has officially been put into effect. For the past two years companies have been working to make sure that their companies are GDPR compliant in order to avoid penalties. If businesses fail to comply, <a href=\"https:\/\/owncloud.com\/blog-you-can-soon-be-fined\/\">fines of up to 20 million euros or 4% of the world\u2018s annual turnover<\/a> might be the consequence. But now that it\u2019s finally here, what does it mean?<\/p>\n<p>Well, according to <a href=\"https:\/\/www.theverge.com\/2018\/5\/22\/17378688\/gdpr-general-data-protection-regulation-eu\" target=\"_blank\" rel=\"noopener\">The Verge<\/a>\u2019s <a href=\"https:\/\/www.theverge.com\/users\/Sarah%20Jeong\" target=\"_blank\" rel=\"noopener\">Sarah Jeong<\/a>, \u201cno one is ready \u2014 not the companies and not even the regulators.\u201d And at the time of writing this blog, the <a href=\"https:\/\/www.eugdpr.org\/\" target=\"_blank\" rel=\"noopener\">GDPR informational website<\/a> is down; perhaps a sign that it has been completely overwhelmed by last minute scramblers?<\/p>\n<blockquote>\n<p style=\"text-align: center;\">\u201cIn a survey of over 1,000 companies conducted by <a href=\"https:\/\/iapp.org\/media\/pdf\/resource_center\/Ponemon_race-to-gdpr.pdf\" target=\"_blank\" rel=\"noopener\">the Ponemon Institute<\/a> in April, half of the companies said they won\u2019t be compliant by the deadline. When broken down by industry, 60 percent of tech companies said they weren\u2019t ready.\u201d<br \/>\n&#8211; Sarah Jeong, The Verge<\/p>\n<\/blockquote>\n<p>&nbsp;<\/p>\n<p><strong>But What is the GDPR?<\/strong><br \/>\nAs stated, the GDPR site is currently down, so I will refer to <a href=\"https:\/\/slate.com\/technology\/2018\/05\/what-is-gdpr-how-will-it-affect-you-guide.html\" target=\"_blank\" rel=\"noopener\">Slate\u2019s simplified description<\/a> of the mandate:<\/p>\n<p><em>EDIT 19.06.2018:\u00a0https:\/\/www.eugdpr.org\/ is back online.<\/em><\/p>\n<blockquote>\n<p style=\"text-align: center;\">\u201cThere are a host of new requirements rolled into the GDPR. Companies will now have to report data breaches within 72 hours and allow people to access the private data that has been gathered on them and find out how it\u2019s being used. Users also have the \u201cright to be forgotten,\u201d allowing them to demand that companies remove certain personal information from the internet, and the right to opt out of sensitive data collection. The GDPR further broadens the definition of \u201cpersonal data\u201d to include locations, browsing history, IP addresses, and other information.\u201d<\/p>\n<p style=\"text-align: center;\">&#8211; Aaron Mak, Slate<\/p>\n<\/blockquote>\n<p>Ok, so it\u2019s understandable that many companies are working to be compliant, but the regulators aren\u2019t even ready?<br \/>\nAccording to <a href=\"https:\/\/www.reuters.com\/article\/us-europe-privacy-analysis\/european-regulators-were-not-ready-for-new-privacy-law-idUSKBN1I915X\" target=\"_blank\" rel=\"noopener\">Reuters<\/a>,<\/p>\n<blockquote>\n<p style=\"text-align: center;\">\u201cSeventeen of 24 authorities who responded to a Reuters survey said they did not yet have the necessary funding, or would initially lack the powers, to fulfill their GDPR duties\u2026 Many watchdogs lack powers because their governments have yet to update their laws to include the Europe-wide rules, a process that could take several months after GDPR takes effect\u2026\u201d<\/p>\n<p style=\"text-align: center;\">&#8211; Douglas Busvine, Julia Fioretti, Mathieu Rosemain<\/p>\n<\/blockquote>\n<p><strong>What a Mess!<\/strong><br \/>\nIt\u2019s a good thing that you are an ownCloud user and, therefore, do not have to worry about any of this.<br \/>\nownCloud offers you a secure file-sharing alternative to conventional public cloud offerings. Through on-premises installation and a variety of administration and <a href=\"https:\/\/owncloud.com\/security\/\">security features<\/a>, you not only gain full control of your data, but a truly <a href=\"https:\/\/owncloud.com\/private-cloud\/\">private cloud<\/a> for your business that is fully compliant with the GDPR.<\/p>\n<p>When somebody is running ownCloud for you, make sure that they are in the EU jurisdiction or monitor regulatory changes to things like privacy shield very closely! Keep in mind that with the recent Cloud Act your data can be monitored \u2013 without your knowledge by US agencies at any time.<br \/>\nThe barrier for issues of National Security just got lowered this week dramatically \u2013 asked for by the President the US Ministry of Trade is inquiring if normal car imports are affecting National Security.<\/p>\n<p>Here is an overview of how ownCloud meets the GDPR requirements:<\/p>\n<ul>\n<li><strong>Integrity &amp; resilience of the systems:<\/strong> File changes must be detected and verified. ownCloud offers several features that meet this requirement including:\n<ul>\n<li>Multi-factor authentication<\/li>\n<li>Permissions management<\/li>\n<li>File firewall<\/li>\n<li>Audit log<\/li>\n<li>File integrity check<\/li>\n<li>Authentication<\/li>\n<li>Document classifications and policies<\/li>\n<li>Professionally developed and tested enterprise software<\/li>\n<\/ul>\n<\/li>\n<li><strong>Availability and access:<\/strong> Users must always be able to have availability and access to their data. ownCloud offers users ransomware protection and versioning with granular recovery incase an attack proves successful.<\/li>\n<li><strong>Transparency and procedure:<\/strong> Companies must have transparent and comprehensible processing of data and procedures for evaluating the effectiveness of protective measures. ownCloud offers users auditing\/logging module and transparent authorization management.<\/li>\n<li><strong>Encryption of personal data:<\/strong> The GDPR reduces procedures and notification needs if personal data is encrypted. ownCloud provides you with master key server-side encryption, even with HSM support to keep your data safely at rest. For critical data as covered under Article 9 of the GDPR we optionally offer client-side end-to-end encryption with optional key server and smartcard support for the best possible security!<\/li>\n<\/ul>\n<p><strong>For more information, be sure to visit our <a href=\"https:\/\/owncloud.com\/gdpr\/\">GDPR page<\/a>, download our <a href=\"https:\/\/oc.owncloud.com\/rs\/038-KRL-592\/images\/Flyer_GDPR_DSGVO_EN.pdf\">whitepaper<\/a> and check out our recorded webinar <a href=\"https:\/\/owncloud.com\/webinars\/?mkto=true&amp;id=how-you-can-beat-gdpr-cloud-act-and-other-regulatory-challenges-with-owncloud\">How you can beat GDPR, CLOUD Act and other regulatory challenges with ownCloud<\/a>.<\/strong><\/p>\n<p><a href=\"https:\/\/owncloud.com\/webinars\/?mkto=true&amp;id=how-you-can-beat-gdpr-cloud-act-and-other-regulatory-challenges-with-owncloud\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-36878 size-full\" src=\"https:\/\/owncloud.com\/wp-content\/uploads\/2018\/05\/ownCloud-GDPR-Webinar.png\" alt=\"\" width=\"969\" height=\"545\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today on May 25, 2018 the EU-General Data Protection Regulation (GDPR) has officially been put into effect. Now, that this privacy regulation finally is here, what does it mean?<\/p>\n","protected":false},"author":16,"featured_media":36873,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","inline_featured_image":false,"footnotes":""},"categories":[48],"tags":[],"class_list":["post-36872","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/owncloud.com\/de\/wp-json\/wp\/v2\/posts\/36872","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/owncloud.com\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/owncloud.com\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/owncloud.com\/de\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/owncloud.com\/de\/wp-json\/wp\/v2\/comments?post=36872"}],"version-history":[{"count":0,"href":"https:\/\/owncloud.com\/de\/wp-json\/wp\/v2\/posts\/36872\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/owncloud.com\/de\/wp-json\/wp\/v2\/media\/36873"}],"wp:attachment":[{"href":"https:\/\/owncloud.com\/de\/wp-json\/wp\/v2\/media?parent=36872"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/owncloud.com\/de\/wp-json\/wp\/v2\/categories?post=36872"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/owncloud.com\/de\/wp-json\/wp\/v2\/tags?post=36872"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}