Article

Many U.S. Companies Unaware that the GDPR Applies to Them

Topic: Business NetworkingBy Michael PetersPublished Recently added

Legacy signals

Legacy popularity: 1,027 legacy views

With just over three weeks to go until the May 25, 2018, deadline, many U.S. companies are woefully unprepared for the EU’s new General Data Protection Regulation, or GDPR. In fact, quite a few of them don’t yet realize they have to achieve GDPR compliance. A new survey by CompTIA found that “A full 52 percent of 400 U.S. companies surveyed are either still exploring the applicability of GDPR to their business; have determined that GDPR is not a requirement for their business; or are unsure.” Additional findings from the CompTIA study include: * Only 13% of U.S. companies surveyed reported having achieved full GDPR compliance, with 23% “mostly compliant” and 12% “somewhat compliant.” * Only 25% of U.S. companies surveyed reported being “very” familiar with the GDPR. * Only 22% of U.S. companies surveyed have developed a GDPR compliance plan, and only 21% have conducted data audits and readiness assessments * Nearly one-third of U.S. companies surveyed mistakenly believe that the deadline for GDPR compliance is the end of 2018. * 64% of U.S. companies surveyed are unaware of the [very stiff] penalties for not complying with the GDPR. Respondents to the CompTIA survey listed accountability and allowing users to correct inaccuracies; data transparency and the rights of users to access their data; user consent; data portability; and the “right to be forgotten” as the most challenging aspects of GDPR compliance. U.S. Companies and GDPR Compliance The applicability of the GDPR to your business is not based on where your company is located, but on where your customers are located. If you conduct business with any individuals or organizations in the European Union, you must comply with the GDPR. Further, in addition to customer data; it also governs employee and human resources data. How serious is the EU about enforcing GDPR compliance among U.S. companies? Last week, EU authorities flatly rejected a request from U.S.-based ICANN, which is in charge of the WHOIS “internet phonebook,” for more time to make WHOIS GDPR-compliant. Yes, that ICANN, and that WHOIS. This was not foisted on ICANN at the last moment; the organization had a two-year lead time to come up with a solution but dragged its feet. Because of the ICANN GDPR debacle, cyber security experts, law enforcement agencies, and IP atto eys fear that the WHOIS directory will become fragmented or go dark on May 25. What Does the EU GDPR Mean for U.S. Companies? The GDPR is arguably the most comprehensive, far-reaching data privacy law ever enacted. Among other things: * It will require impacted companies to fundamentally alter their data governance and bake data security into their products, policies, procedures, and systems from day one. * It will hold your organization responsible if one of your third-party vendors is breached. * It grants EU “data subjects” sweeping data privacy rights, including data portability, the right to access their data, the right to withdraw consent, and the “right to be forgotten.” * It mandates that organizations notify the authorities and affected customers within 72 hours of detecting a breach. Much like HIPAA, the GDPR specifies what organizations must achieve, but it does not prescribe the specific technical controls to get there.

Article author

About the Author

Michael Peters is the CEO of Lazarus Alliance, Inc., the Proactive Cyber Security™ firm, and Continuum GRC. He has served as an independent information security consultant, executive, researcher, and author. He is an internationally recognized and awarded security expert with years of IT and business leadership experience and many previous executive leadership positions. He has contributed significantly to curriculum development for graduate degree programs in information security, advanced technology, cyberspace law, and privacy, and to industry standard professional certifications. He has been featured in many publications and broadcast media outlets as the “Go-to Guy” for executive leadership, information security, cyberspace law, and governance.

Further reading

Further Reading

4 total

Article

Introduction There was a time when the call center was seen as a place where phones rang endlessly and agents simply answered questions. That picture has changed dramatically. Today the modern call center sits at the center of customer experience, quietly coordinating returns, managing fulfillment concerns, and shaping how customers feel about every interaction with a brand. Instead of reacting to problems, teams now guide customers through complex journeys. Their role has gr

February 6, 2026

Article

In today’s financial landscape, credit scores play a major role in determining access to loans, housing, and even employment opportunities. For individuals facing late payments, collections, or inaccurate credit reports, rebuilding credit can feel overwhelming. This is why many people turn to professional services for guidance. Among the growing number of Credit Repair Companies in Houston and providers offering Credit Repair San Antonio solutions, White Jacobs continues to

February 6, 2026

Article

Choosing the right POS terminal is more important now than ever. With customer expectations rising and payment methods changing quickly, businesses need a device that works fast, stays secure, and handles different payment types. The PAX A30 is a popular Android POS terminal that has gained attention for its modern design and strong features. In this review, we look at how well it performs in real life, what makes it stand out, and whether it can truly be called the best Andr

January 17, 2026

Article

Installing a rack mount server cabinet is an important task for anyone setting up a server room or a data center. These cabinets are designed to hold servers, networking devices, and other hardware safely and in an organized way. A well-planned installation helps improve airflow, manage cables neatly, and secure equipment, which makes the server room safer and more efficient. Whether you’re setting up a small office server or a larger business data center, knowing how to in

January 16, 2026