
Happy Data Privacy Day!
Did you know Data Privacy Day has been celebrated in the U.S. since 2008, and the U.S. federal government made it official in 2011?
It is a good time to reflect on the Principals of GDPR, which have now become the core privacy principals all business should follow for Data Privacy:
- Lawfulness, fairness, and transparency: Personal data must be processed in a lawful, fair, and transparent manner.
- Purpose limitation: Personal data can only be collected for specific, legitimate, and explicit purposes.
- Data minimization: Personal data processing must be relevant, adequate, and limited to what is necessary.
- Accuracy: Personal data must be accurate and kept up to date.
- Storage limitation: Personal data should only be kept for as long as necessary to fulfill the purposes for which it was collected.
- Integrity and confidentiality: Personal data must be protected with integrity and confidentiality.
- Accountability: Everyone who processes personal data must be able to demonstrate compliance with the other six principles.
And of course, here is just a reminder of some critical steps for businesses to take to protect their data:
- Know how your data is collected
- Know your data locations
- Know your data types
- Know where you data is going
- Classify your data
- Secure your data with encryption
- Manage access to your data based on classification and roles
- Delete data as it ages or becomes unnecessary
- Utilize data deliberately
ACSM has been helping businesses protect their assets and improve their security and privacy posture since 2006. Our skilled team can help your business understand its cyber weaknesses and potential threats as well as improve your security, privacy, and compliance postures. Our services include penetration testing, maturity assessments, cyber security and privacy implementation assistance, CISO-as-a-Service and DPO-as-a-Service, to mention a few.
To learn more about how ACSM can help support your cyber defense needs, please use our contact page https://www.americancsm.com/contact-us/ and schedule a free consultation call today.

As businesses are being impacted by the European Union’s (EU) enactment of the General Data Protection Regulation (GDPR), many are asking themselves questions around the ownership of their privacy program. Do I need a Data Protection Officer (DPO)? Can I get by assigning this to my CISO, Director of Compliance, or my General Council?
As the deadline for GDPR, May 25, 2018, nears, many companies are still struggling with their implementation and some are complete. This MeetUp brings together privacy practitioners, GRC leads, and others interested in and leading their GDPR transformations. The goal of this group is to discuss and share learnings, emerging best practices, technical solutions, and keep up to date on regulation changes.