Meet GDPR Compliance Requirements
The General Data Protection Regulation (GDPR), implemented May 25, 2018, intends to give Europeans greater ability to protect and control their sensitive personal data in the digital space.
Protecting Personal Data of EU Citizens
Requiring Data Protection for All Organizations
The General Data Protection Regulation (GDPR) is intended to strengthen and unify data protection for all individuals in the European Union. It also affects non-EU companies that may hold personal data of EU citizens. Other jurisdictions are also implementing similar regulations to protect personal information.
Severe Non-Compliance Penalties
The penalty for is non-compliance is severe – fines of up to 4% of global turnover can be levied on a company for a personal data breach that contains EU citizen data – and organizations must be able to demonstrate compliance to the regulation.
Examples of Addressed GDPR Compliance Requirements
Cygna Auditor primarily addresses topics in Chapter 2 (Principles) and Chapter 4 (Controller and processor) of the GDPR, though there may be other areas addressable depending upon your compliance implementation.
Ch 2/Article 5 / Para 1
Personal data shall be processed in a manner that ensures appropriate security of the personal data
Ch 2/Article 5 / Para 2
The controller shall be able to demonstrate compliance with paragraph 1
Ch 4/Article 24 / Para 1
The controller shall implement technical measures to be able to demonstrate that processing is in accordance with this Regulation
Ch 4/Article 24 / Para 1
The controller shall implement technical measures to be able to demonstrate that processing is in accordance with this Regulation
Ch 4/Article 25 / Para 2
The controller shall implement technical measures to be able to demonstrate that processing is in accordance with this Regulation
Ch 4/Article 32 / Para 1
The controller shall implement technical measures to be able to demonstrate that processing is in accordance with this Regulation
Ch 4/Article 32 / Para 2
In assessing the appropriate level of security, account shall be taken of the risks presented by processing personal data
Ch 4/Article 33 / Para 1
In the case of a personal data breach, the controller shall not later than 72 hours notify the supervisory authority
Monitor Activity on Secured Systems
Cygna Auditor monitors all successful and failed data activity such as file or folder creation, access, updates, deletions, who made the changes and when they were made.
Real-Time Notification of Sensitive Changes
Cygna Auditor's built-in and custom alerting notifies you of critical changes such as membership changes to privileged groups.
Privileged Account Management
Cygna Auditor allows you to monitor all changes made by privileged accounts to ensure they adhere to regulatory and organizational policies for the protection and privacy of data as well as that they do not abuse their unrestricted access.