Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Business > Time Is Ticking: Top GDPR Considerations for SaaS and Managed Service Providers
    Business

    Time Is Ticking: Top GDPR Considerations for SaaS and Managed Service Providers

    Time Is Ticking: Top GDPR Considerations for SaaS and Managed Service Providers

    Published by Gbaf News

    Posted on April 6, 2018

    Featured image for article about Business

    Written by Jose Casinha, Chief Information Security Officer, OutSystems

    The General Data Protection Regulation (GDPR) Is right around the corner. The new regulation, which goes into effect on May 25, 2018, is arguably the most significant change in global privacy law in 23 years. Businesses must not only ensure that cybersecurity processes are in place to avoid facing financial penalties, but they must also take the time to assess that their software-as-service (SaaS) and managed service providers are compliant.

    With May 25 less than two months away, the regulation places important new obligations on any business that handles the data of individuals living in the EU, independent of where the business is located. SaaS and managed service providers will need to ensure that they are complying with these regulations, and organisations choosing a SaaS or managed service provider should make sure the vendors they are considering comply with these regulations.

    SaaS and managed service providers need to adapt and amend their services, contracts, and business processes to address the new requirements of the regulation. The consequences for non-compliance will be very costly. Infringement on certain articles of GDPR carries fines of up to €20M or up to 4% of the total global revenue for the preceding year, whichever is greater. Other fines carry penalties up to €10M or up to 2% of the total global revenue of the preceding year, whichever is greater.

    The regulations apply regardless of where the personal data is retained—whether on paper or on servers in the cloud. However, the cloud poses quite a few specific compliance challenges.

    Controllers and Processors

    It’s important to understand everyone’s role in GDPR compliance. GDPR expands the scope of data security regulations. Previously, regulations only applied to the “controller,” meaning the person or organisation that determines the purpose and means of processing personal data. For example, a business would be the controller if it managed customer and employee data.

    However, the GDPR extends the compliance responsibility to the “processor” of the data, which includes SaaS and managed service providers. The GDPR requires processors to develop and implement some internal procedures and practices to protect personal data. Most of those procedures and practices are related to information security management. Those who follow international standards like ISO 27001 or SOC2 are the most prepared for the GDPR challenges. Also, the processor must ensure that any subcontractors follow the requirements.

    Data Location

    GDPR requires that controllers and processors know where personal data is located for storage and processing. This restricts the ability to transfer personal data to countries or international organisations outside the EEA. SaaS and managed service providers may have or use servers outside the EEA, but the transfer of personal data must comply with GDPR data transfer principles. For example, a vendor’s cloud could be on Amazon Web Services (AWS), which would enable customer data to be stored in Europe, therefore complying with GDPR. Data transfer is easier if organisations select a provider with infrastructures located in multiple regions.

    Businesses, as the controllers, must assess whether the security measures of their SaaS or managed service provider, the processor, meet the security requirements by conducting periodic audits. The same applies to a processor using a sub-processor. Each International Security Standard has its own security programme as part of the certification process. This means that, periodically, controls that are in place are evaluated, as is their compliance maturity level. As an example, ISO 27001 Annex A specifies 114 security controls that they are required to adopt, and any exclusions of adoption must be justified.

    Rights of Individuals and Cloud Contracts

    GDPR extends specific rights to individuals regarding the use of their personal data. These include the processes for transferring data and when to erase it. Even though these responsibilities are assigned to the controller, it will fall on the processors to adapt infrastructure or services to accommodate this. For example, choices about shared or dedicated databases must be considered according to the nature of the data schema.

    The GDPR is prescriptive about the contents of the contracts established between controllers and processors and sets out many stipulations, including when to process personal data. As people become far more security-conscious about their personal data, there will be more regulations like GDPR. The best approach is to stay ahead of the regulations by launching security initiatives and keeping up with the latest security certifications. By adopting international standards in information security management, companies are much more prepared to handle new requirements.

    Data Centre Providers

    Data centre providers are also an important link in the GDPR compliance chain that cannot be overlooked. They have the ownership of the physical assets where information is stored. In that sense, they are considered processors and are required to manage personal data related to physical access control like biometrics, video surveillance, their own employees, and subcontractor information.

    Getting Ready

    The GDPR deadline is fast approaching and organisations have less than two months to be compliant.  Without a doubt, the protection of customer and partner data is essential to the survival and success of every organisation. Everyone must understand these regulations and take responsibility for the data they work with, be they controllers or processors. Importantly, organisations must take the time to assess that their SaaS and managed service providers are compliant with GDPR before the deadline. GDPR compliance will ultimately improve data security, which is vital in today’s volatile cybersecurity landscape.

    Written by Jose Casinha, Chief Information Security Officer, OutSystems

    The General Data Protection Regulation (GDPR) Is right around the corner. The new regulation, which goes into effect on May 25, 2018, is arguably the most significant change in global privacy law in 23 years. Businesses must not only ensure that cybersecurity processes are in place to avoid facing financial penalties, but they must also take the time to assess that their software-as-service (SaaS) and managed service providers are compliant.

    With May 25 less than two months away, the regulation places important new obligations on any business that handles the data of individuals living in the EU, independent of where the business is located. SaaS and managed service providers will need to ensure that they are complying with these regulations, and organisations choosing a SaaS or managed service provider should make sure the vendors they are considering comply with these regulations.

    SaaS and managed service providers need to adapt and amend their services, contracts, and business processes to address the new requirements of the regulation. The consequences for non-compliance will be very costly. Infringement on certain articles of GDPR carries fines of up to €20M or up to 4% of the total global revenue for the preceding year, whichever is greater. Other fines carry penalties up to €10M or up to 2% of the total global revenue of the preceding year, whichever is greater.

    The regulations apply regardless of where the personal data is retained—whether on paper or on servers in the cloud. However, the cloud poses quite a few specific compliance challenges.

    Controllers and Processors

    It’s important to understand everyone’s role in GDPR compliance. GDPR expands the scope of data security regulations. Previously, regulations only applied to the “controller,” meaning the person or organisation that determines the purpose and means of processing personal data. For example, a business would be the controller if it managed customer and employee data.

    However, the GDPR extends the compliance responsibility to the “processor” of the data, which includes SaaS and managed service providers. The GDPR requires processors to develop and implement some internal procedures and practices to protect personal data. Most of those procedures and practices are related to information security management. Those who follow international standards like ISO 27001 or SOC2 are the most prepared for the GDPR challenges. Also, the processor must ensure that any subcontractors follow the requirements.

    Data Location

    GDPR requires that controllers and processors know where personal data is located for storage and processing. This restricts the ability to transfer personal data to countries or international organisations outside the EEA. SaaS and managed service providers may have or use servers outside the EEA, but the transfer of personal data must comply with GDPR data transfer principles. For example, a vendor’s cloud could be on Amazon Web Services (AWS), which would enable customer data to be stored in Europe, therefore complying with GDPR. Data transfer is easier if organisations select a provider with infrastructures located in multiple regions.

    Businesses, as the controllers, must assess whether the security measures of their SaaS or managed service provider, the processor, meet the security requirements by conducting periodic audits. The same applies to a processor using a sub-processor. Each International Security Standard has its own security programme as part of the certification process. This means that, periodically, controls that are in place are evaluated, as is their compliance maturity level. As an example, ISO 27001 Annex A specifies 114 security controls that they are required to adopt, and any exclusions of adoption must be justified.

    Rights of Individuals and Cloud Contracts

    GDPR extends specific rights to individuals regarding the use of their personal data. These include the processes for transferring data and when to erase it. Even though these responsibilities are assigned to the controller, it will fall on the processors to adapt infrastructure or services to accommodate this. For example, choices about shared or dedicated databases must be considered according to the nature of the data schema.

    The GDPR is prescriptive about the contents of the contracts established between controllers and processors and sets out many stipulations, including when to process personal data. As people become far more security-conscious about their personal data, there will be more regulations like GDPR. The best approach is to stay ahead of the regulations by launching security initiatives and keeping up with the latest security certifications. By adopting international standards in information security management, companies are much more prepared to handle new requirements.

    Data Centre Providers

    Data centre providers are also an important link in the GDPR compliance chain that cannot be overlooked. They have the ownership of the physical assets where information is stored. In that sense, they are considered processors and are required to manage personal data related to physical access control like biometrics, video surveillance, their own employees, and subcontractor information.

    Getting Ready

    The GDPR deadline is fast approaching and organisations have less than two months to be compliant.  Without a doubt, the protection of customer and partner data is essential to the survival and success of every organisation. Everyone must understand these regulations and take responsibility for the data they work with, be they controllers or processors. Importantly, organisations must take the time to assess that their SaaS and managed service providers are compliant with GDPR before the deadline. GDPR compliance will ultimately improve data security, which is vital in today’s volatile cybersecurity landscape.

    Related Posts
    Five questions to ask before stepping into Employee Ownership
    Five questions to ask before stepping into Employee Ownership
    Cybersecurity as a Profit Engine: Turning Financial Services Security into Measurable Business Value
    Cybersecurity as a Profit Engine: Turning Financial Services Security into Measurable Business Value
    How Investability Helps Companies Navigate Transformational Times
    How Investability Helps Companies Navigate Transformational Times
    88% of UK and US organisations concerned about state-sponsored cyber attacks as national threat levels surge, IO research reveals
    88% of UK and US organisations concerned about state-sponsored cyber attacks as national threat levels surge, IO research reveals
    One in three SME leaders do not fully understand cash flow, despite 82% facing cash flow problems
    One in three SME leaders do not fully understand cash flow, despite 82% facing cash flow problems
    Inside the Company that Predicted the Remote Work Mega-Trend Before It Became Mainstream
    Inside the Company that Predicted the Remote Work Mega-Trend Before It Became Mainstream
    SEO Consultant Adrian Czarnoleski on How to Increase Business Value Before Exit
    SEO Consultant Adrian Czarnoleski on How to Increase Business Value Before Exit
    No SOC 2, No Deal: Why You’re Already Losing Clients - and What You Can Do About It
    No SOC 2, No Deal: Why You’re Already Losing Clients - and What You Can Do About It
    Jose Tolosa Guides Organizations Forward with Clarity, Purpose, and Integrity
    Jose Tolosa Guides Organizations Forward with Clarity, Purpose, and Integrity
    Reducing Freight Costs to Drive Global Trade Expansion
    Reducing Freight Costs to Drive Global Trade Expansion
    The Psychology of Music in the Modern Workplace
    The Psychology of Music in the Modern Workplace
    Revealed: Low-Cost/No-Cost Marketing Hacks For Results Oriented Businesses
    Revealed: Low-Cost/No-Cost Marketing Hacks For Results Oriented Businesses

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Previous Business PostBuilding for brilliance – tips for creating outstanding digital experiences to win user hearts and minds
    Next Business PostWhy customer service still remains the most valuable weapon in your digital strategy

    More from Business

    Explore more articles in the Business category

    Finance teams still stuck in spreadsheets as manual processes stall digital transformation

    Finance teams still stuck in spreadsheets as manual processes stall digital transformation

    The Future of Remote & Hybrid Leadership: Leading With Data-Driven Foresight

    The Future of Remote & Hybrid Leadership: Leading With Data-Driven Foresight

    2025-2030: The Next Technological Innovations for Business

    2025-2030: The Next Technological Innovations for Business

    The CFO’s New Playbook: 5 Ways AI Is Redefining Finance with Insights from Rishi Oberoi

    The CFO’s New Playbook: 5 Ways AI Is Redefining Finance with Insights from Rishi Oberoi

    Revolutionizing Payments: Secure, Scalable, Sovereign

    Revolutionizing Payments: Secure, Scalable, Sovereign

    Why Trademark Abuse in Paid Search Is a Growing Risk for Financial Institutions

    Why Trademark Abuse in Paid Search Is a Growing Risk for Financial Institutions

    E-commerce Customer Service: Tips

    E-commerce Customer Service: Tips

    When to Automate Your Warehouse: The Tipping Point for Operations Growth

    When to Automate Your Warehouse: The Tipping Point for Operations Growth

    Hurt at Work? 5 Financial Facts You Need to Know

    Hurt at Work? 5 Financial Facts You Need to Know

    Against the Odds: Resilience in Consumer Subsectors Offers Prime Opportunities for Investors

    Against the Odds: Resilience in Consumer Subsectors Offers Prime Opportunities for Investors

    Empower Your Workforce With Financial Wellness This Labor Day

    Empower Your Workforce With Financial Wellness This Labor Day

    Build a brand that stands out with five simple strategies, from defining your UVP to using storytelling and building loyalty. Find out more.

    Build a brand that stands out with five simple strategies, from defining your UVP to using storytelling and building loyalty. Find out more.

    View All Business Posts