About a-team Marketing Services
The knowledge platform for the financial technology industry
The knowledge platform for the financial technology industry

A-Team Insight Blogs

General Data Protection Regulation – Start Now to Meet May 2018 Compliance Deadline

Subscribe to our newsletter

General Data Protection Regulation (GDPR) is on the radar of most financial services firms, but its scale, scope and large penalties for non-compliance mean firms need to start planning and implementing now to meet the May 2018 compliance deadline.

The requirements of GDPR and how to build a data protection framework to achieve and evidence compliance, were discussed during a recent A-Team Group webinar. The webinar was moderated by A-Team editor Sarah Underwood and joined by experts Koen van Duyse, subject matter expert on regulatory compliance at Collibra; and Dennis Slattery, CEO at EDMWorks.

An early poll of the webinar audience showed 40% of respondents at the planning stage of GDPR compliance, 26% having not yet started on the regulation, 26% starting implementation, and 8% having made significant progress on a solution.

Opening the webinar discussion, Slattery talked about the development of the digital world, the ensuing scope of GDPR’s data protection requirements – which cover any organisations, wherever they are, processing EU citizens’ data – and key points of the regulation. These include new rights for data subjects, such as the right to provide consent to organisations to use private data, and rights around the portability, rectification and erasure of personal data.

Looking at the implications of GDPR in the financial services sector, van Duyse noted that firms must prove they have the best interests of their customers at heart and provide evidence of data protection compliance and accountability.

In terms of implementation, the speakers discussed the need for strong data governance to meet the regulation’s requirement for data protection by design and to track and alert customers and regulators of any breaches quickly and efficiently. With penalties for non-compliance running up to 4% of annual group turnover, the pressure is on for financial firms to use data governance to drive GDPR implementation, an issue reflected by an audience poll showing 36% of respondents planning to make provision for GDPR in their data governance frameworks from the start of implementation.

As well as data governance, the speakers noted the need to classify personal data to ensure control over sensitive data, such as political opinion and sexual orientation, and align architecture across the organisation to the requirements of the regulation. Mapping operational impacts to use cases, van Duyse described responses to particular articles of GDPR.

Summing up on the extent of GDPR’s requirements, its reach across organisations, and the penalties of non-compliance, the panel members concluded with some practical advice for practitioners involved in implementing the regulation. Slattery suggested a need for communication and training programmes to make people aware of and aligned with GDPR, a focus on data architecture to create a framework for data protection, and a need to sort out policies that make sense and can be sustained.

Van Duyse recommended that practitioners should step outside silos, check any overlap of GDPR with other existing and incoming regulations, and remember that GDPR is less about regulatory reporting than how your business is organised.

Listen to the webinar to find out more about:

  • Requirements of GDPR
  • Impacts on data management
  • The role of data governance
  • A data protection framework
  • Benefits of implementation
Subscribe to our newsletter

Related content

WEBINAR

Upcoming Webinar: Managing Non-Financial Misconduct Under SMCR

9 October 2025 11:00am ET | 3:00pm London | 4:00pm CET Duration: 50 Minutes Non-financial misconduct—encompassing behaviours such as bullying, sexual harassment, and discrimination is a key focus of the Senior Managers and Certification Regime (SMCR). The Financial Conduct Authority (FCA) has underscored that such misconduct is not only unethical but also poses significant risks...

BLOG

The Data Year Ahead: More Data Formats and Use Cases

In the second part of our preview of the next 12 months in data management, we take in the views of experts who offered Data Management Insight their thoughts on a range of developments, including the increased use of unstructured data, the wider application of data sets and distribution challenges. 1 Data Governance, Quality and Technologies Ian...

EVENT

AI in Capital Markets Summit London

The AI in Capital Markets Summit will explore current and emerging trends in AI, the potential of Generative AI and LLMs and how AI can be applied for efficiencies and business value across a number of use cases, in the front and back office of financial institutions. The agenda will explore the risks and challenges of adopting AI and the foundational technologies and data management capabilities that underpin successful deployment.

GUIDE

AI in Capital Markets: Practical Insight for a Transforming Industry – Free Handbook

AI is no longer on the horizon – it’s embedded in the infrastructure of modern capital markets. But separating real impact from inflated promises requires a grounded, practical understanding. The AI in Capital Markets Handbook 2025 provides exactly that. Designed for data-driven professionals across the trade life-cycle, compliance, infrastructure, and strategy, this handbook goes beyond...