About a-team Marketing Services
The knowledge platform for the financial technology industry
The knowledge platform for the financial technology industry

A-Team Insight Blogs

General Data Protection Regulation – Start Now to Meet May 2018 Compliance Deadline

Subscribe to our newsletter

General Data Protection Regulation (GDPR) is on the radar of most financial services firms, but its scale, scope and large penalties for non-compliance mean firms need to start planning and implementing now to meet the May 2018 compliance deadline.

The requirements of GDPR and how to build a data protection framework to achieve and evidence compliance, were discussed during a recent A-Team Group webinar. The webinar was moderated by A-Team editor Sarah Underwood and joined by experts Koen van Duyse, subject matter expert on regulatory compliance at Collibra; and Dennis Slattery, CEO at EDMWorks.

An early poll of the webinar audience showed 40% of respondents at the planning stage of GDPR compliance, 26% having not yet started on the regulation, 26% starting implementation, and 8% having made significant progress on a solution.

Opening the webinar discussion, Slattery talked about the development of the digital world, the ensuing scope of GDPR’s data protection requirements – which cover any organisations, wherever they are, processing EU citizens’ data – and key points of the regulation. These include new rights for data subjects, such as the right to provide consent to organisations to use private data, and rights around the portability, rectification and erasure of personal data.

Looking at the implications of GDPR in the financial services sector, van Duyse noted that firms must prove they have the best interests of their customers at heart and provide evidence of data protection compliance and accountability.

In terms of implementation, the speakers discussed the need for strong data governance to meet the regulation’s requirement for data protection by design and to track and alert customers and regulators of any breaches quickly and efficiently. With penalties for non-compliance running up to 4% of annual group turnover, the pressure is on for financial firms to use data governance to drive GDPR implementation, an issue reflected by an audience poll showing 36% of respondents planning to make provision for GDPR in their data governance frameworks from the start of implementation.

As well as data governance, the speakers noted the need to classify personal data to ensure control over sensitive data, such as political opinion and sexual orientation, and align architecture across the organisation to the requirements of the regulation. Mapping operational impacts to use cases, van Duyse described responses to particular articles of GDPR.

Summing up on the extent of GDPR’s requirements, its reach across organisations, and the penalties of non-compliance, the panel members concluded with some practical advice for practitioners involved in implementing the regulation. Slattery suggested a need for communication and training programmes to make people aware of and aligned with GDPR, a focus on data architecture to create a framework for data protection, and a need to sort out policies that make sense and can be sustained.

Van Duyse recommended that practitioners should step outside silos, check any overlap of GDPR with other existing and incoming regulations, and remember that GDPR is less about regulatory reporting than how your business is organised.

Listen to the webinar to find out more about:

  • Requirements of GDPR
  • Impacts on data management
  • The role of data governance
  • A data protection framework
  • Benefits of implementation
Subscribe to our newsletter

Related content

WEBINAR

Recorded Webinar: Navigating a Complex World: Best Data Practices in Sanctions Screening

As rising geopolitical uncertainty prompts an intensification in the complexity and volume of global economic and financial sanctions, banks and financial institutions are faced with a daunting set of new compliance challenges. The risk of inadvertently engaging with sanctioned securities has never been higher and the penalties for doing so are harsh. Traditional sanctions screening...

BLOG

How Firms Are Adapting to a Multi-Channel, AI-Driven Future – Global Relay Survey

Global Relay has published its 2025/26 Data Insights: Communications Capture Trends report, now in its third annual edition and rapidly becoming a reference point for how regulated financial institutions manage their communications obligations. Drawing on data from more than 12,000 regulated financial institutions using Global Relay’s connectors, the survey tracks which channels firms are archiving,...

EVENT

RegTech Summit London

Now in its 9th year, the RegTech Summit in London will bring together the RegTech ecosystem to explore how the European capital markets financial industry can leverage technology to drive innovation, cut costs and support regulatory change.

GUIDE

Regulatory Data Handbook – Second Edition

Need to know all the essentials about the regulations impacting data management? A-Team’s Regulatory Data Handbook is a great way to see at-a-glance: All the regulations that are impacting data management today A description of each regulation The impact each will have from a data and data management perspective Messages from sponsors with products related to...