The Asian Age

Tech firms to feel pinch of tough EU privacy rules

Violations will attract huge penalties; major IT companies tweak customer contracts

-

Mumbai, May 22: As the European Union ( EU) prepares to implement strict data privacy laws from May 25 to protect its citizens, consumer- driven Indian firms, especially technology startups, fintech companies, and IT services, with exposure to the EU may feel the impact first, say experts.

“Consumer- driven companies that have exposure to the EU, in areas like IT services and fintech, that support the banking and other regulated sectors, are likely to be affected first, and have to comply,” Shree Parthasara­thy, national leader, cyber risk services, Deloitte said.

However, he added that Indian consumers and regulators may not feel the strong impact of the General Data Protection Regulation ( GDPR) immediatel­y.

GDPR aims to strengthen and protect the data of individual­s within the European Union and also deals with export of personal data outside the region.

The laws are relevant due to rising instances of data breaches, with the latest involving social media platform Facebook, where the data of around 87 million users globally, including over 5.6 lakh Indians, was accessed by British political research firm Cambridge Analytica through its app, without authorisat­ion.

Mr Parthasara­thy said GDPR will impact companies with operations in Europe and those that handle vast amounts of customer or client data, the most.

Large informatio­n technology firms like TCS, Infosys, Wipro and HCL reportedly are already rushing to tweak their vendor and customer contracts.

Mr Parthasara­thy pointed out that areas like life sciences, manufactur­ing sector and the government entities will find it much harder to comply to the GDPR in time, that comes into effect from May 25.

Kroll, a New York- based corporate investigat­ions and risk consulting firm also corroborat­ed that the IT companies, which have exposure in Europe, will be impacted the most.

Further, it indicated that GDPR regulation­s stipulate significan­t fines for companies that do not comply with the law, which will be a concern.

Flouting the GDPR could attract fines of up to 20 million euros or 4 per cent of a firm’s global turnover.

Reshmi Khurana, managing director and head of investigat­ions and disputes, South Asia, Kroll, said it remains to be seen which regulator will oversee the compliance of the law, which companies will be up for scrutiny in the first generation ( probably European firms and those handling data from inside or outside Europe), and how the checks will be delivered and fines will be levied.

 ??  ??
 ??  ??

Newspapers in English

Newspapers from India