Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity Newswire

Managing data-privacy risk in today's global environment

By Kate Barecchia
data privacy laws
July 19, 2021

Many organizations do not know how to find, access, or control personal data. That inability to accurately manage personal data creates a few different organizational risks. For organizations with global operations, those risks are magnified.

The first major risk organizations face relates to compliance with laws.  If an organization doesn’t know what personal data it has, where that personal data resides, and who has access to that personal data, compliance with data privacy laws like the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the new Colorado Privacy Act (CPA) becomes nearly impossible.

GDPR, CCPA, and CPA all have one thing in common:  they all require an organization to be able to produce records to an individual upon request within a relatively short time frame.  They also require organizations to take action on an individual’s request to be forgotten – in other words, they all require an organization to delete an individual’s personal data if requested.  If the organization doesn’t know what data they have or where it lives, they can’t action those requests.  A failure to action an individual’s requests can lead to high fines and reputational damage.

For businesses that operate in multiple jurisdictions, managing these data subject access requests can be a major operational challenge. Manually processing these requests can cost upwards of $240,000 per million records, according to industry experts (Source: DataGrail’s 2020 Consumer Privacy Expectations Report).

While GDPR, CCPA, and CPA are some of the most recent examples of relatively new data privacy laws, more than 100 countries have implemented data privacy legislation and many of those laws offer similar data access rights.  In the absence of a federal solution, many U.S. states are also debating and implementing their own data privacy laws.  To meet these varying compliance requirements, it’s critical that an organization know what personal data they have and where it resides. 

Another risk organizations onboard when they don’t know what personal data they have comes from data security incidents.  A report from Imperva Research Labs shows that personal data is a top target for attackers. If an organization doesn’t have an accurate data map, it is incredibly challenging to assess the severity of a data security incident and to determine any associated reporting obligations. Trying to build a data map in the midst of a data security incident creates unnecessary pressure and is likely to lead to a misunderstanding of the associated risk. As a result, an organization may miss a regulatory reporting deadline, which, in the EU, can be as short as 72 hours. 

An organization with an established, accurate data map can also leverage the benefits of a data retention program. If an organization knows its data inventory, it can begin to delete data it no longer needs. Once that data has been securely deleted, the organization can effectively shed the associated data security risk.

Another risk organizations face when they don’t know what data they have or where it resides comes from insider threats.  When users are given privileges which are not necessary for their role, that risk increases.  Having an understanding of user permissions and applying appropriate role-based access controls are effective ways to mitigate that risk.

The good news is that, in today’s market, tools exist to assist organizations with data discovery. By deploying these tools, organizations can locate and classify the types of data they have, can map where it resides, and can determine who has (or should not have) access.  Some tools even include integrated features which assist with the management of data subject access requests.  Based on the findings those tools provide, an organization can then develop a plan of action to reduce its overall data privacy risk. Making an investment in those tools can save an organization from substantial costs down the road, including fines, legal fees, and loss of reputation.

KEYWORDS: compliance data privacy data security GDPR risk and resilience risk management risk mitigation

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Kate Barecchia is Global Data Privacy Officer and Deputy General Counsel at Imperva.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Top Cybersecurity Leaders
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Leadership and Management
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Glowing police siren

Security Isn’t a Commodity. Neither Is Off-Duty Law Enforcement

Soccer stadium

How the Current Iran-US Conflict May Impact World Cup Security

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

Man with covered face

Why Most Workplace Violence Prevention Starts Too Late

SEC 2026 Benchmark Banner

Events

July 8, 2026

The 2026 Security Maturity Benchmark Report: Insights From Senior Security Leaders

LIVE: July 8, 2026 at 2 pm EDT In this webinar, speakers will share key insights from the report, including why today’s threat environment demands greater maturity and how to evaluate your organization’s current security posture.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • risk-assessment-freepik1170x658v.jpg

    Managing risk in today’s volatile economy

    See More
  • IFIIX virtual event

    Risk in Today's Uncertain World: Join the conversation

    See More
  • Understanding resiliency across businesses can help in your continuity planning

    Making sense of resilience in a shifting global environment

    See More

Related Products

See More Products
  • Hospitality Security: Managing Security in Today's Hotel, Lodging, Entertainment, and Tourism Environment

  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • 9780367030407.jpg

    National Security, Personal Privacy and the Law

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing