Learning from Enforcement Cases to Manage GDPR Risks
Saeed Akhlaghpour, Farkhondeh Hassandoust, Farhad Fatehi, Andrew Burton‐Jones, Andrew Hynd, Holding Redlich Lawyers (Australia) · MIS Quarterly Executive · 2021
The European Union’s General Data Protection Regulation (GDPR) is a ground-breaking data privacy and security law that affects organizations globally. Noncompliance can incur potentially hefty penalties, but compliance is not a box-ticking exercise and requires a risk-based approach. Based on an analysis of 93 cases of GDPR enforcement, we have identified 12 types of risk and their associated mitigation measures and risk indicators. We also describe the strategic actions that can be taken to manage GDPR risks.1,2