A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

Experian’s Head of Data Breach Response Services
Jim Steven
Data Breach Readiness and GDPR: The Goalposts Have Moved


Transparency and Speed…
GDPR has moved the goalposts. For UK businesses with European customers, it’s sometimes hard to interpret the new rules of the game, especially with a small 72-hour window in which to report a breach to regulators. I’m often on the receiving end of that blind panic moment. But what does remain a constant is this: readiness is still the catalyst for providing transparency and speed – the greatest priorities following a breach are to manage and communicate effectively with the authorities and customers.
EXPERIAN RESEARCH:POST BREACH
69% customers would be discouraged from using services
From Reactive to Proactive – but still not truly prepared…
Experian has experienced businesses becoming much more proactive, in recent years. And we welcome that mindset shift. However, there is still much work to be done in relation to educating about the range of potential pitfalls in responding.
How to Make Headway…
Most businesses we speak to do understand what is expected from them in terms of GDPR compliance. But they do not fully understand how to fulfil those obligations within the outlined timeframe. And a lot of this comes down to a lack of knowledge of where all their data resides – whether that’s customer’s, and their third-party suppliers’. It’s also linked to different jurisdictional data privacy laws that exist and need to be adhered to across different jurisdictional boundaries. The reality is; advanced assessment and preparation is where a business can make headway.
EXPERIAN RESEARCH: AFTER A BREACH
48% customers would stop using a company
It’s all in the Preparation Detail…
Within the new pan-European GDPR context, the notification process of a data breach comes as one of the biggest surprises to businesses we advise. Small details can become big dilemmas in the heat of the moment. The aftermath of a data breach is no time to be sourcing translators, nor is it an appropriate time to put up a language barrier by assuming everyone speaks English. What is more, any form of correspondence may be used in future litigation, so it needs to be legally watertight, premeditated, clear, and concise. And then there’s the intricate setting-up of phone lines for customer guidance. The question is - Do you have briefed experts, speaking in native tongue at the ready, all operating in the right time zone? And will you use a local, international of Freephone number? These points of detail need the right experts and preparation.
EXPERIAN RESEARCH: AFTER A BREACH
44% customers expect financial compensation
Changing your mindset…
With all this in mind, GDPR is a huge logistical challenge; but it is also a good thing. It puts customers back at the heart of products and services. The negative spin-off though, is that misinterpretation is game changing. Legislation can leave your business and your customers at risk, even if the intention is the opposite. However, despite news headlines, far-reaching international breaches do not have to be catastrophic. If you are prepared, they are challenging, but also manageable.
Weekly Brief
I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info


