Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

5 Focus Areas in Preparation for GDPR Compliance

By Jim Merrifield on August 28, 2017
Email this postTweet this postLike this postShare this post on LinkedIn

In less than 300 days, the European General Data Protection Regulation (GDPR) will go into effect and forever change the privacy landscape. Leading industry organization, Gartner, Inc., predicts that more than 50 percent of companies affected by the GDPR will not be fully compliant. Of course, the affected companies will include both European and non-European companies. Bart Willemsen, research director at Gartner, says “Threats of hefty fines, as well as the increasingly empowered position of individual data subjects tilt business case for compliance and should cause decision makers to re-evaluate measures to safely process personal data.”

How can organizations prepare for the GDPR? Gartner recommends organizations focus on five high-priority areas:

  1. Determine Your Role Under the GDPR – The GDPR applies to any organization that processes personal data for the offering of goods and serves to the European Union (EU).
  2. Appoint a Data Protection Officer – Organizations are required to appoint a data protection officer (DPO) if their processing operations require regular and systematic monitoring or if they have large-scale processing activities.
  3. Demonstrate Accountability in All Processing Activities – Accountability under the GDPR requires proper data subject consent acquisition and registration. A clear and express action is needed that will require organizations to implement streamlined techniques to obtain and document consent and consent withdrawal.
  4. Check Cross-Border Data Flows – Data transfers to any of the 28 EU member states are still allowed, as well as to Norway, Liechtenstein and Iceland. Transfers to any of the other 11 countries the European Commission (EC) deemed to have an “adequate” level of protection are also still possible. Outside of these areas, appropriate safeguards such as Binding Corporate Rules (BCRs) and standard contractual clauses (i.e., EU “Model Contracts”) should be used.
  5. Prepare for Data Subjects Exercising Their Rights – The rights of data subjects have been extended under the GDPR. These rights include the right to be forgotten, data portability and to be informed of a data breach. A well-defined process to handle data breach incidents needs to be documented and followed.
Photo of Jim Merrifield Jim Merrifield

Jim Merrifield is Robinson+Cole’s Chief Data Officer, a member of the Data Privacy + Cybersecurity Team, and a non-attorney contributor to the Data Privacy + Cybersecurity Insider blog. He has spent nearly 20 years helping organizations of all sizes, including law firms and…

Jim Merrifield is Robinson+Cole’s Chief Data Officer, a member of the Data Privacy + Cybersecurity Team, and a non-attorney contributor to the Data Privacy + Cybersecurity Insider blog. He has spent nearly 20 years helping organizations of all sizes, including law firms and Fortune 500 companies, develop and implement practical information governance strategies, policies, and best practices. Jim is a well-respected expert in the information governance industry. With an extensive background in policy development and enforcement, enterprise program deployment, and technology solutions, he has earned a strong reputation as a knowledgeable practitioner and reliable consultant. His deep understanding of the space is reflected by his many publications, lectures, and consulting services for top-tier companies and law firms. Jim holds a bachelor degree in Legal Studies from Quinnipiac University and is a certified information governance professional (IGP).

Jim’s innovative thinking and commitment for the industry has enabled him to create the popular podcast, InfoGov Hot Seat, a platform for candid conversations featuring practitioners, consultants and solution providers – offering valuable perspectives to listeners about legal technology and managing information as an asset.

Read more about Jim MerrifieldEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo