Newsletter Subscribe
Enter your email address below and subscribe to our newsletter


Shorthand for the General Data Protection Regulation, this is a benchmark law aimed at tightening data control around personal data involving EU citizens. Not complying with GDPR can see a company excluded from any European business, while companies found in contravention of the regulation can face startlingly serious penalties, ranging from €20 million (almost R300 million) to 4 percent of annual global turnover – whichever is higher.
GDPR casts a wide net: anything from a name or photo to an IP address can qualify as protected data. Yet even though the law comes into effect this month, nearly half of companies surveyed by analyst firm Gartner will not be compliant even by the end of the year.
“A remarkable number of businesses haven’t yet prepared for GDPR, or for that matter other new regulations such as POPI,” said Riaan Bekker, Force Solutions Manager at Thryve, a supplier of risk integration and management technologies. “It’s tempting to blame negligence, but I think often businesses are intimidated by the complexity. One way to address this is to get specialists in, but that will be expensive and solves a problem. It doesn’t always introduce a new capability. Using technology, on the other hand, can cut through the red tape and also create a platform that the business can use to improve its competitiveness.”
GDPR readiness can demand some formidable preparation, not to mention analysis and visibility of company processes. Specifically, one of GDPR’s requirements is to have a risk-based approach to data protection, with policies that reflect this. Companies should have an inventory of the processes that are impacted and changed accordingly. At the very least, GDPR is a good example of how companies need to be agile as new regulations appear.
The right technology can help tremendously to identify the right processes, create appropriate workflow automation and keep a business ready for any future changes in the law. Riskonnect, a leading risk aggregation platform, recommends these nine features you should look for in technologies that can address the challenge:
There are many different parts of GDPR, including the creation of key data-related roles and a clear will from leadership to implement the changes. But without visibility and control, there can be no strategy.
Such an investment plays into the future. Data regulation is only set to expand as societies come to grips with this new era. At the same time, the speed of business is accelerating, but with high speed comes more risk. GDPR is not just a compliance demand, said Bekker:
“Regulations such as GDPR are just more indications of how the world is changing. Speed, automation and intelligence are becoming the crucial ingredients for business success, but that means the gaps between opportunities are closing. So don’t look at GDPR as a grudge, unless you just want to use consultants to pave over it. It’s an opportunity to make a business more resilient and responsive towards risk.”
By Riaan Bekker, Riskonnect Solution Manager, Thryve