{"id":14430,"date":"2018-09-12T07:00:11","date_gmt":"2018-09-12T11:00:11","guid":{"rendered":"https:\/\/www.kaspersky.co.uk\/blog\/?p=14430"},"modified":"2024-09-13T16:05:03","modified_gmt":"2024-09-13T15:05:03","slug":"data-protection-report","status":"publish","type":"post","link":"https:\/\/www.kaspersky.co.uk\/blog\/data-protection-report\/14430\/","title":{"rendered":"Businesses and personal data: In-depth analysis of practices and risks"},"content":{"rendered":"<p>Over the past year or so, we\u2019ve returned to the topic of personal data protection again and again. That\u2019s not only because of the GDPR regulation that came into effect on May 25 in Europe, but also because other regions are beginning to revise their approaches to storing and processing that data. That is why our colleagues decided to analyze how businesses globally handle <a target=\"_blank\" href=\"https:\/\/encyclopedia.kaspersky.com\/glossary\/personally-identifiable-information-pii\/?utm_source=kdaily&amp;utm_medium=blog&amp;utm_campaign=termin-explanation\" rel=\"noopener noreferrer\">personally identifiable information<\/a> (PII), based on data from our annual \u201cGlobal corporate IT security risks\u201d survey.<\/p>\n<p>One of the rather unusual findings of this survey is that security breaches affect not only entire companies, but also management personally. When considering the risks of data breach, the people responsible for data protection usually think about fines, reputation losses, and direct damage to businesses. However, according to our respondents, a data breach often leads to job losses. That happened in almost one in three cases (31%). Typically, senior non-IT employees were held responsible and dismissed. That isn\u2019t the most significant finding of our survey, but it should definitely serve as a valuable argument while discussing security budgets with decision makers.<\/p>\n<p>It is little surprise that almost every company collects and stores some form of personal data, be it information on their employees (86%) or customers (88%). And almost one in three businesses stores data protected by the strict confines of the GDPR. Note that we are talking about global companies, not only European ones \u2014 to fall under the jurisdiction of the regulation, a company need only store data of European citizens.<\/p>\n<p>About three-fourths of the businesses surveyed think they know how to manage data protection and compliance. However, 46 % of large enterprises and 42% of SMBs worldwide have had one or more data breaches during the past year. That calls the actual degree of their readiness into question: In two-fifths of cases, customer PII was affected during those breaches.<\/p>\n<p>Part of the problem with data protection may be in the trend of cloud migration \u2014 nowadays 20% of sensitive customer and corporate data resides outside the corporate perimeter, making that data much more difficult to control.<\/p>\n<p>To learn more about the findings, you can fill out the form below and download a complete version of \u201cFrom data boom to data doom: The risks and rewards of protecting personal data.\u201d<\/p>\n<div class=\"interactive\"><form id=\"mktoForm_21101\"><\/form><script>MktoForms2.loadForm(\"\/\/app-sj06.marketo.com\", \"802-IJN-240\", 21101);<\/script><script>\n            MktoForms2.whenReady(function(form) {\n                form.onSuccess(function(vals, tyURL) {\n                    document.location.href = tyURL;\n                    dataLayer.push({\n                        'event': 'addEvents_makeConversions',\n                        'event_id': 'd-n01-e11',\n                        'conversion_name': 'Marketo Form',\n                        'conversion_step': 'Form Fill Out',\n                        'conversion_param': jQuery(location).attr(\"href\"),\n                        'eventCallback' : function() {\n                            jQuery(location).attr('href',tyURL);\n                        }\n                    });\n                    return false;\n                });\n            });\n            <\/script><\/div><!-- RECAPTCHA -->\n        <style>.googleRecaptcha { padding: 20px !important; }<\/style>\n        <script>\n            var GOOGLE_RECAPTCHA_SITE_KEY = '6Lf2eUQUAAAAAC-GQSZ6R2pjePmmD6oA6F_3AV7j';\n\n            var insertGoogleRecaptcha = function (form) {\n            var formElem = form.getFormElem().get(0);\n\n            if (formElem && window.grecaptcha) {\n                var div = window.document.createElement('div');\n                var divId = 'g-recaptcha-' + form.getId();\n                var buttonRow = formElem.querySelector('.mktoButtonRow');\n                var button = buttonRow ? buttonRow.querySelector('.mktoButton[type=\"submit\"]') : null;\n\n                var submitHandler = function (e) {\n                var recaptchaResponse = window.grecaptcha && window.grecaptcha.getResponse(widgetId);\n                e.preventDefault();\n\n                if (form.validate()) {\n                    if (!recaptchaResponse) {\n                    div.setAttribute('data-error', 'true');\n                    } else {\n                    div.setAttribute('data-error', 'false');\n\n                    form.addHiddenFields({\n                        reCAPTCHAFormResponse: recaptchaResponse,\n                    });\n\n                    form.submit();\n                    }\n                }\n                };\n\n                div.id = divId;\n                div.classList.add('googleRecaptcha');\n\n                if (button) {\n                button.addEventListener('click', submitHandler);\n                }\n\n                if (buttonRow) {\n                formElem.insertBefore(div, buttonRow);\n                }\n\n                if (window.grecaptcha.render) {\n                    var widgetId = window.grecaptcha.render(divId, {\n                    sitekey: GOOGLE_RECAPTCHA_SITE_KEY,\n                });\n                formElem.style.display = '';\n                }\n            }\n            };\n\n            function onloadApiCallback() {\n            var forms = MktoForms2.allForms();\n            for (var i = 0; i < forms.length; i++) {\n                insertGoogleRecaptcha(forms[i]);\n            }\n            }\n\n            (function () {\n            MktoForms2.whenReady(function (form) {\n                form.getFormElem().get(0).style.display = 'none';\n                jQuery.getScript('\/\/www.google.com\/recaptcha\/api.js?onload=onloadApiCallback');\n            });\n            })();\n        <\/script>\n        <!-- END RECAPTCHA -->\n","protected":false},"excerpt":{"rendered":"<p>How businesses globally handle personally identifiable information.<\/p>\n","protected":false},"author":700,"featured_media":14431,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1836,2361],"tags":[260,1802,2354,119],"class_list":{"0":"post-14430","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-business","8":"category-smb","9":"tag-data-protection","10":"tag-gdpr","11":"tag-pii","12":"tag-survey"},"hreflang":[{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/data-protection-report\/14430\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/data-protection-report\/14275\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/data-protection-report\/11969\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/data-protection-report\/16253\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/data-protection-report\/13395\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/data-protection-report\/16936\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/data-protection-report\/16287\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/data-protection-report\/21306\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/data-protection-report\/23824\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/data-protection-report\/9732\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/data-protection-report\/17637\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/data-protection-report\/17374\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.co.uk\/blog\/tag\/gdpr\/","name":"GDPR"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/posts\/14430","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/users\/700"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=14430"}],"version-history":[{"count":4,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/posts\/14430\/revisions"}],"predecessor-version":[{"id":28161,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/posts\/14430\/revisions\/28161"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/media\/14431"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=14430"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=14430"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=14430"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}