Sick to the back teeth of GDPR? You ain’t seen nothing yet. Expect much more of this bland and unappetising diet as the days tick down to whenever in May 2018 this blasted piece of EU legislation is due to become law.
Channel partners are finding it tedious enough, but spare a thought for your customers who the entire IT industry has been lambasting about GDPR for at least the last 12 months. GDPR talk is everywhere, fatigue is setting in and business leaders are finding it a major turnoff.
That’s a shame because GDPR is a good opportunity for organisations to get a better governance and cyber security regime around their communications and data processes, and it’s a potentially fruitful money-spinner for trusted advisors who know what advice to give too. But therein lies the rub. No-one wants to hear another pitch about how the sky is going to cave in if they don’t do anything about GDPR, or how buying such-and-such a product will ‘help them move towards’ becoming GDPR compliant.
The big question is, how do you get the message across to customers and do the right thing by them, without coming over as selling fear, uncertainty and doubt?
The truth is that GDPR will end up changing little in the life of ordinary businesses, and you’d be a charlatan to suggest otherwise. Let me give you three reasons why.
Strength in numbers
[caption id="attachment_10415" align="alignright" width="200"]
Elizabeth Denham, Information Commissioner[/caption]
There are about 5.5m businesses incorporated in the UK, and all of them handling data on EU citizens (including UK staff and customers) will be liable to the full force of the new law. None of them want the disruption of a prosecution under GDPR, or the damage to their reputation.
However, if you believe some of the surveys being bandied around lately, apparently hardly anyone in Britain is GDPR compliant yet; millions either haven’t got their acts together or haven’t got the foggiest ideas what the law requires. But let me assure you, there is absolutely no way that the combined machinery of the ICO, the police and the judiciary can possibly cope with a body of this size. Hence GDPR will become like speeding on the motorway; people will get caught (and so they should) but most people will carry on doing 75-80mph from time to time, with relative impunity.



