{"id":7849,"date":"2019-02-12T06:02:29","date_gmt":"2019-02-11T20:02:29","guid":{"rendered":"https:\/\/nsrd.info\/blog\/?p=7849"},"modified":"2019-02-12T06:02:36","modified_gmt":"2019-02-11T20:02:36","slug":"gdpr-do-your-backups-spark-joy","status":"publish","type":"post","link":"https:\/\/nsrd.info\/blog\/2019\/02\/12\/gdpr-do-your-backups-spark-joy\/","title":{"rendered":"GDPR: Do your backups spark joy?"},"content":{"rendered":"\n<p>itnews Australia is reporting on a DLA Piper analysis of GDPR operations within Europe since it came into law in May 2018.<\/p>\n\n\n\n<p>GDPR \u2013\u00a0the General Data Protection Regulation \u2013\u00a0is a fairly broad ranging set of laws aimed at ensuring Europeans have a right to understand what data businesses are holding on them, and request their data be erased, too. It&#8217;s easily the most far-ranging attempt to hand the right to data privacy back to individuals. GDPR is no laughing matter: breaching it can lead to fines up to 10 million Euros, or 2% of a company&#8217;s annual worldwide turnover, <em>whichever\u00a0is\u00a0larger<\/em>. Clearly those large fines are aimed at multinationals, and saw companies like Facebook, who profoundly lack substantive ethics when it comes to customer data privacy, frantically rearranging where and how data was stored for European citizens prior to the introduction of the law.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"900\" height=\"675\" src=\"https:\/\/nsrd.info\/blog\/wp-content\/uploads\/2019\/02\/bigStock-Data-Analysis.jpg\" alt=\"\" class=\"wp-image-7850\" srcset=\"https:\/\/nsrd.info\/blog\/wp-content\/uploads\/2019\/02\/bigStock-Data-Analysis.jpg 900w, https:\/\/nsrd.info\/blog\/wp-content\/uploads\/2019\/02\/bigStock-Data-Analysis-300x225.jpg 300w, https:\/\/nsrd.info\/blog\/wp-content\/uploads\/2019\/02\/bigStock-Data-Analysis-768x576.jpg 768w, https:\/\/nsrd.info\/blog\/wp-content\/uploads\/2019\/02\/bigStock-Data-Analysis-267x200.jpg 267w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/figure>\n\n\n\n<p>According to <a rel=\"noreferrer noopener\" aria-label=\"itnews, there were over 59,000 breach reports (opens in a new tab)\" href=\"https:\/\/www.itnews.com.au\/news\/over-59000-data-breaches-stretch-gdpr-watchdogs-518899\" target=\"_blank\"><strong>itnews, there were over 59,000 breach reports<\/strong><\/a>, ranging from innocuous issues such as mistakenly sending email to the wrong people through to significant hacks impacting very large numbers. You can find the original DLA Piper report that itnews Australia has covered <strong><a href=\"https:\/\/www.dlapiper.com\/en\/netherlands\/news\/2019\/02\/dla-piper-gdpr-data-breach-survey\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"here (opens in a new tab)\">here<\/a><\/strong>.<\/p>\n\n\n\n<p>Despite the large number of breach reports, there had only been 91 GDPR fines issued at the time the analysis was written, with most fines being tens of thousands of Euros. The largest fine of 50 million Euros was handed to Google France, though the report notes this wasn&#8217;t a personal data breach fine, but rather, where personal data was processed without authorisation for advertising purposes.<\/p>\n\n\n\n<p>But what&#8217;s all this got to do with Data Protection as a storage function?<\/p>\n\n\n\n<p>Data protection systems \u2013\u00a0backup and recovery systems in particular \u2013\u00a0within a business environment may hold many years worth of data relating to individuals the company has dealt with. So if a customer exercises his or her right to be forgotten, the backup team may very well <em>need to get involved<\/em>.<\/p>\n\n\n\n<p>It&#8217;s something that Dell EMC has been talking about for a while (e.g., <a rel=\"noreferrer noopener\" aria-label=\"this post (opens in a new tab)\" href=\"https:\/\/blog.dellemc.com\/en-us\/when-should-your-customers-think-about-gdpr-compliance\/\" target=\"_blank\">this post<\/a> from June 2018, and this <a rel=\"noreferrer noopener\" aria-label=\"dedicated site (opens in a new tab)\" href=\"https:\/\/www.delltechnologies.com\/en-us\/solutions\/gdpr.htm\" target=\"_blank\">dedicated site<\/a>), and has seen tightly fitting options provided by companies such as <a rel=\"noreferrer noopener\" aria-label=\"Index Engines (opens in a new tab)\" href=\"http:\/\/www.indexengines.com\/gdpr-webinar-dellemc\" target=\"_blank\"><strong>Index Engines<\/strong><\/a>. As you might imagine, one of the first exercises you need to consider is <a rel=\"noreferrer noopener\" aria-label=\"getting long term retention data off tape (opens in a new tab)\" href=\"http:\/\/www.indexengines.com\/dellemc\" target=\"_blank\">getting long term retention data off tape<\/a>, which impedes the various analysis functions you need to be considering if you&#8217;re affected by GDPR. <\/p>\n\n\n\n<p>Analysis is more than just text indexing, of course. It&#8217;s also a proper review of what truly needs to be retained. Look at the average retention policies you see in organisations: 13 monthlies for any production backup and 7 yearlies, or 84 monthlies retained for all production backups. Sometimes that even extends into non-production backups. But do all those backups truly contain information that needs to be retained? You might say that GDPR has the potential of fuelling the <em><a rel=\"noreferrer noopener\" aria-label=\"Marie\u00a0Kondo (opens in a new tab)\" href=\"https:\/\/www.netflix.com\/au\/title\/80209379\" target=\"_blank\">Marie\u00a0Kondo<\/a><\/em> moment of backup and recovery: grab the backup tapes, hold them close and ask yourself: <em>do they spark joy?<\/em>\u00a0The old approach of just performing LTR backups for systems regardless of whether they&#8217;re truly needed or not could possibly be approaching its use-by date.<\/p>\n\n\n\n<p>It&#8217;s not an easy journey, as evidenced by the fact the GDPR compliance teams themselves are swamped, but putting the journey off isn&#8217;t going to make it an easier one in the future. Eventually, the GDPR compliance teams will get up to speed, both in terms of resourcing and technical capabilities, and at that point, you don&#8217;t want to be pointing at a mountain of unmanaged tapes when someone comes to you and says, &#8220;John Smith has filed a <em>request-to-be-forgotten<\/em>&#8220;.<\/p>\n\n\n\n<p>To me, GDPR enables several discussions to be held between the business and IT:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>LTR classification<\/strong>: What data truly does need to be kept for long term retention purposes? The defaults \u2013\u00a0everything, or everything production related \u2013\u00a0need to be thrown out and replaced with more considered and targeted requirements.<\/li><li><strong>Data re-use<\/strong>: If we&#8217;re going to make this long term retention data more accessible for search and discovery, what else can we do with it? (within the legally permitted framework, of course)<\/li><li><strong>Anchor elimination<\/strong>: As companies evolve, some will change their backup software and\/or hardware. Old systems are often left as &#8216;anchors&#8217; to the IT department. That approach just won&#8217;t work in a GDPR environment, so real conversations can be had about consolidating records and completing the migration from retired products and hardware.<\/li><li><strong>Documenting adherence<\/strong>: Your business is going to need new procedures around complying to GDPR, and you need to get those procedures codified and documented. If you have to invent the process with each new GDPR request, there&#8217;s going to be a lot of wasted cycles in your teams.<\/li><\/ul>\n\n\n\n<p>The EU GDPR teams may be swamped at the moment, but that won&#8217;t always be the case: if you&#8217;re working in backup and recovery, you have new duties of care, and you&#8217;re in a prime position to become an internal data guardian in a new and exciting way.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>itnews Australia is reporting on a DLA Piper analysis of GDPR operations within Europe since it came into law in&hellip;<\/p>\n","protected":false},"author":1,"featured_media":7850,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[3,12,1438],"tags":[1505,1338],"class_list":["post-7849","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-architecture","category-general-technology","category-long-term-retention","tag-gdpr","tag-ltr"],"aioseo_notices":[],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/nsrd.info\/blog\/wp-content\/uploads\/2019\/02\/bigStock-Data-Analysis.jpg","jetpack_shortlink":"https:\/\/wp.me\/pKpIN-22B","jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/posts\/7849","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/comments?post=7849"}],"version-history":[{"count":1,"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/posts\/7849\/revisions"}],"predecessor-version":[{"id":7851,"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/posts\/7849\/revisions\/7851"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/media\/7850"}],"wp:attachment":[{"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/media?parent=7849"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/categories?post=7849"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/tags?post=7849"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}