By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Start Your Business Magazine
Sunday, Jul 12, 2026
  • Connect:
  • Podcasts
  • Get the Book!
  • Contacts
  • Starting Up

    Starting Up

    a guide to starting a business

    • Business Planning
    • Business Ideas
    • Startup Checklists
    • Company Formation
    Reading: The myths of GDPR
    • Business Banking
    • How to Guides
    • eCommerce
    Reading: The myths of GDPR
  • Funding

    Funding

    raising finance and managing cashflow

    • Start Up Funding
    • Grants
    • Business Angels
    • Venture Capital
    Reading: The myths of GDPR
    • Venture Debt
    • SEIS/EIS
    • Growth Capital
    • Bridging Loans
    Reading: The myths of GDPR
    • Commercial Mortgages
    • Invoice Finance
    • Merchant Cash Advance
    Reading: The myths of GDPR
    Get Quotes
  • Running

    Running

    managing a small business

    • Advertising
    • Social Media
    • Email Marketing
    Reading: The myths of GDPR
    • Card Machines
    • Payment Gateway
    • Payments by Phone
    Reading: The myths of GDPR
    • Remote Working
    • Serviced Offices
    • Virtual Office
    Reading: The myths of GDPR
  • Growing

    Growing

    scale and grow your business

    • Scaling
    • Finance
    • Technology
    Reading: The myths of GDPR
    • Accounting
    • Manufacturing
    • Tax
    • Marketing
    Reading: The myths of GDPR
    • Import Export
    Reading: The myths of GDPR
  • SME Update

    SME Update

    the latest news and expert advice

    • Lastest
    • Business Experts
    • Blogs
    • Business Advice
    Reading: The myths of GDPR
    • Interviews
    • Books
    • Events
    • Agenda
    Reading: The myths of GDPR
    • Wellbeing
    • Women in Business
    Reading: The myths of GDPR
Reading: The myths of GDPR
Newsletter
Font ResizerAa
Start Your Business MagazineStart Your Business Magazine
  • How To
  • Books
  • Podcasts
  • Interviews
Search
  • Agenda
  • Contact Us
  • Book Review
  • Blogs
  • Finance
  • Growing Business
  • How To
  • Interviews
  • Categories
    • Marketing
    • Startups
    • Advertising
    • Market Trends
    • Tech Moves
  • Marketing
  • SME Update
  • Starting Up
  • Technology
  • Wellness
  • Contact

Trending →

Investing in ETFs

Marketing Agencies

How to Start a Building Material Business

Communicate Better

The Strawman Theory Explained

Follow US
Start Your Business Magazine > Blog > agenda > The myths of GDPR
agenda

The myths of GDPR

Start Your Business
Share
5 Min Read
SHARE

May 2019 will mark the first anniversary of the General Data Protection Regulation (GDPR), and early numbers make clear that its implementation has been a success as a breach notification law. As such, GDPR has affected multiple aspects of a business. It has created increased requirements for businesses to deal with issues such as security, compliance, data ownership, training and data management. The new regulation will require, for many of businesses, a fundamental change to their internal processes and ongoing focus on compliance.

There are several myths around who manages data inside an organisation which have been challenged as a result of GDPR regulations. From the shift from an IT-centric to a business process owner model, to educating internal teams and reviewing tools, here are the top five myths around management of data that GDPR effectively busted.

  1. Data Management is an IT function 

Data management used to be solely an IT function but, since GDPR came into force, organisations have been increasingly realising the criticality and value of their data assets. This is why the data management function has become a business and IT function. It requires a full commitment by every organisation to build data protection into its culture and all aspects of its operations, from support through accounting to product development. The GDPR is not specific to just IT, it must permeate all aspects of the organisation to ensure a culture of data privacy is built.

  1. Business organisations have always been familiar with data management

Since the new regulation made data management a business, not just an IT, concern, awareness around GDPR needed to be expanded to different departments in an organisation. Many parts of business organisations were not familiar with data management and had to be trained and managed around the issue. However, a recent paper by Osterman Research showed that only 42 per cent of organisations have trained their employees around data management and GDPR, meaning that 58 per cent left their employees in the dark.

  1. All departments understand how to manage and control data

As mentioned above, data management used to be exclusively an IT function and IT teams had a good understanding of the way data should be managed and control. Those in business functions tended to accumulate data and lacked access control, putting at that data at risk. Today, the responsibility for compliance is shared across the different  functions. Non-IT employees cannot simply close their eyes to the risks they take when handling their company’s data. Raising awareness is crucial to prevent data breaches and impacts on the organisation’s finances and reputation.

  1. GDPR isn’t relevant for everyone 

Departments have been affected in different ways and to different degrees: some have been living and breathing the regulation for several years, for others it may be new. But being data protection-aware is no longer optional, it’s critical and regulated. An ongoing continuous programme of education – from induction through regular refresher sessions – is essential. This helps make data awareness relevant for everyone from the Chairman of the Board to the customer service team and beyond.

  1. Data protection stops at the organisation’s perimeter

Suddenly, businesses realised that they were responsible not just for their own data protection compliance, but that of all the links in their supply chain. Cloud computing is a case in point where IT and business managers realised that their CSP needed to be just as compliant as they were in order to avoid a huge security gap. From client-supplier, the relationship shifted to that of a collaborative security partnership as the degree of trust and diligence needed between parties escalated.

From myth to reality

Overall, the understanding of the value and risks around personal data had to be propagated through organisations and actively monitored. GDPR didn’t act as a reminder of what ought to be done, but instead as a proper new regulation. It has changed how organisations collect and manage data and personal information, busting the myth that data management lived in the IT department silo and making it relevant for everyone. That has required extensive investment in people and tools to oversee, and a re-evaluation of business relationships with suppliers and customers alike.

By Frank Krieger, Vice-President, Governance, Risk and Compliance, iland

TAGGED:header
Share This Article
Facebook Copy Link

You Might Also Like ↷

Property still top for long-term investment

July 2, 2018

Bullying

November 1, 2022

Monday Blues

February 11, 2020

Digital PR

March 8, 2022
  • RSS
  • Terms And Conditions
  • Privacy Policy
  • Contact
  • Licensing
  • Contacts
  • Cookie Policy

Start Your Business Magazine: The Ultimate Business Start Up Guide provides information advice and guidance for entrepreneurs and new business start ups. Get the latest from us delivered directly to your inbox.

Start Your Business Magazine
  • Store
  • Features
  • Book
  • Trending
  • Topics
FacebookLike
XFollow
InstagramFollow
YoutubeSubscribe

Copyright 2026 Gambit Interactive Media Limited – All Rights Reserved.

Manage Cookie Consent
We use technologies like cookies to store and/or access device information. Cookies are used for ads personalisation We do this to improve browsing experience as well as show personalized ads. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Go to mobile version