Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • GDPR: The Importance of Data Protection by Design and Default current page
Link copied

GDPR: The Importance of Data Protection by Design and Default

Aug 17, 2018
Author:
Jonas Outlaw
Jonas Outlaw
Senior Product Manager
Blog banner default
GDPR: The Importance of Data Protection by Design and Default
Jonas Outlaw
Jonas Outlaw
Senior Product Manager

With the growth of the ‘always on’ culture, driven by the ever-expanding capabilities of mobile devices and the increase in the digital transformation of services, a wide range of identifiable and behavioral data that is now collected and processed by organizations every time we interact online. At the same time, how and where organizations store and process this data has moved from inside the traditional IT perimeter and server rooms into hybrid and cloud environments in data centers across the globe.

This change in the information landscape has brought something new to everyone’s as of late – the General Data Protection Regulation (GDPR), which went into effect May 25th, 2018. While most of you probably have heard of the new regulations, it’s now more important than ever to focus on getting your organization compliant.

The regulation itself has been around for a couple of years but the enforcement, including fines and penalties, have been in full effect for almost 3 months now. Really, the key for organizations is making sure that we continue to focus on the importance of protecting our data and what we do with it. We've already seen suits come out of several large, well-known companies right after the start of the enforcement, because – most likely – they were not ready.

Now that the enforcement date has passed, let’s not fall asleep at the switch. It’s important to continue to be vigilant, because it's not just the European Union but certainly countries around the globe are continuing to increase their enforcement of organizations of how personal data is treated. Here’s a few key concepts, or new trends emerging, to help clarify some of the new provisions within GDPR.

Martin Willoughby / SVP of General Counsel and Chief Privacy Officer / Bomgar

Martin shared more insight into the importance of data protection and design by default in an exclusive webinar, Post GDPR: The Critical Importance of Securing Remote Access. He also calls out some emerging trends as a result of GDPR going into effect, including:

Data Protection by Design and Default

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

A lot of times, this is also referred to as privacy by design, which has always been a part of data protection regulations. The difference now under GDPR is that it is an actual legal requirement.

That's an important distinction – now a legal requirement. GDPR requires you to put in place appropriate technical and organizational measures to implement the principles found in the GDPR and to safeguard the individual rights of users. Data protection by design is really about considering data protection and privacy issues up front in everything you do. Whether it's your products, processes or how you operate your organization.

Consent

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

The days of pre-ticked boxes and automatic opt-in are gone, and now we’ve moved more toward transparency. We want to let people know what data we're capturing, how we're going to use that data. There's really a burden or an obligation on the organization who's collecting that data to have a lot of transparency and to inform people of their rights as it relates to that data. An important key concept here that's changed is the level of scrutiny on the consent and the transparency of information that we provide about the use of data.

Right to Erasure

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Finally, if we bring all this back to what this whole regulation is about the data subjects rights, really thinking about this as a fundamental right of the individual: the right to erasure, also known as the right to be forgotten. The concept here is that when an organization no longer has a reason to keep the data for somebody, then there is an obligation to go ahead and remove it from your systems.

Bomgar Remote Support Fosters GDPR Compliance

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

For more details about the new regulations, what you could be held responsible for, and how Bomgar can help foster GDPR compliance, check out the full, on demand webinar!


Latest Posts
  • Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Jun 12, 2026 Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Blog
    7m
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
Related
  • Privilege Management for Unix & Linux Continues Rapid Growth by Securing Cloud Infrastructure
    Jan 21, 2021 Privilege Management for Unix & Linux Continues Rapid Growth by Securing Cloud Infrastructure
    Blog
    1m
  • Technology Alliance Tuesday’s Team Feature – Kalyn Kolaski
    Feb 7, 2023 Technology Alliance Tuesday’s Team Feature – Kalyn Kolaski
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.