Jake Dudson

Legislation

What is the “General Data Protection Regulation(GDPR)”?

The GDPR was a new regulation for organizations in the EU to follow. The aim of the GDPR was to protect the data of citizens and maintain their privacy. This regulation was enforced on May 25th 2018 and was the most important change to data privacy.


How does the GDPR impact organisations?

If your organisation was established or runs any operation within the EU you are subjected to comply with the GDPR. Noncompliance could mean a fine of 4% of your organisations annual income or 20 million euros. But it depends on which is more. These are harsh penalties.

Organisations that handle personal data will need to hire are advised to hire a data protection officer or data controller who handles with GDPR compliance.

When registering customers you will need to include a privacy policy so customers know what happens with their data.


What is the “Computer Misuse Act?” In your explanation, provide examples of where you may be in breach of the legislation and methods of minimising them.

The computer misuse act is a law that deals with accessing a computer and/or modifying the data without authorisation.

Ways you could be breaching this legislation:

• Hacking services and altering your accounts data. E.g - Altering bank balance.

• Using services, such as email, for other than what its for. E.g using work email for personal reasons without the administrators permission.

• Closing firewall for applications without admins permission.

Ways to minimise misuse:

• Administrator privileges to minimize what users can do.

• Blocking ports to block servers and sites

• Put policies in place so employees know what they can do