Data Breach Notification Laws

Thales e-Security’s Vormetric Data Security Platform enables safe harbor from data breach notification laws and fines

Global Map

Regulation

Active now

Protecting You from Data Breach Notification Requirements

Data breach notification requirements following loss of personal information have been enacted by governments around the globe. They vary by jurisdiction, but almost universally include a “safe harbour” clause.

Thales eSecurity can help protect from the consequences of a data breach through a data-centric focus on security around personal information, including:

  • Encryption of personal data wherever it resides;
  • Policy-based access controls;
  • Monitoring data access to detect compromise.
Data Breach Disclosure Laws Widespread

National data breach disclosure laws include the UK Data Protection Act, EU General Data Protection Regulation (GDPR), South Korea’s Personal Information Protection Act, Australian Privacy Act and others.

Prevention of Data Breaches a Complex Task

Data breach protection and prevention is not as simple as implementing hardware level disk encryption or OS level encryption within systems. Attacks are increasingly able to penetrate perimeter defenses, compromise accounts, and mine data without targets even being aware of the attack. With this kind of activity, simple encryption schemes won’t prevent a data breach – attackers will access accounts that allow them to decrypt and extract personal data. Driving this are criminal groups willing and able to pay for stolen personal information that has direct monetary value.

Data Breach Protection Requires a Data-Centric Focus

A data-centric focus on preventing the loss of personal information in order to comply with data breach disclosure laws requires:

  • Encryption of personal data wherever it resides – including file systems databases, web repositories, cloud environments, big data environments and virtualization implementations.
  • Policy-based access controls to assure that only authorized accounts and processes can see the data.
  • Monitoring of authorized accounts accessing data, to ensure that these accounts have not been compromised.
Thales e-Security Provides Key Components of the Solution

Thales e-Security's Vormetric Data Security Platform provides key components of the solution to implementing data-centric security. These include security controls that enable organizations to safeguard and audit the integrity of customer records and information against a broad range of threats against data. Thales e-Security data breach protection solutions are transparent to existing operating processes and applications for rapid implementation of protection from data breaches.

This single platform solution to multiple data breach protection needs helps organizations meet compliance requirements with low TCO and an easy-to-deploy, centrally managed infrastructure and solution set.

Vormetric Transparent Encryption

Vormetric Transparent Encryption from Thales e-Security provides file and volume level data-at-rest encryption and integrated, secure key management with a best practices implementation. Access controls and data access monitoring information extend protection from data breaches by limiting data access to only personnel and programs authorized to do so. The same data provides the security intelligence information required for the Security Information and Event Management solution to identify accounts that may represent a threat because of a malicious insider, or a compromise of account credentials by malware.

Vormetric Application Encryption

Vormetric Application Encryption from Thales e-Security adds another layer of data breach protection, enabling organizations to easily build encryption capabilities into internal applications at the field and column level.

Vormetric Key Management

Vormetric Key Management from Thales e-Security enables centralized management of encryption keys for other environments and devices including KMIP compatible hardware, Oracle and SQL Server TDE master keys and digital certificates.

Research and Whitepapers : Bloor for the EU’s new data protection regulation, encryption should be the default option

There are many regulations and industry standards that require that stringent safeguards are applied to personal and sensitive data...

Download

Other key data protection and security regulations

GDPR

GDPR Thumbnail

Regulation

25 May 2018

Perhaps the most comprehensive data privacy standard to date, GDPR affects any organisation that processes the personal data of EU citizens - regardless of where the organisation is headquartered.

Learn More

PCI DSS

GDPR Thumbnail

Mandate

Active Now

Any organisation that plays a role in processing credit and debit card payments must comply with the strict PCI DSS compliance requirements for the processing, storage and transmission of account data.

Learn More

Data Breach Notification Laws

eIDAS

Regulation

Active now

Data breach notification requirements following loss of personal information have been enacted by nations around the globe. They vary by jurisdiction but almost universally include a “safe harbour” clause.

Learn More
Contact a Compliance Specialist Contact Us
Are you fit for GDPR Take our readiness assessment now
Read the Compliance and Regulations Solutions Handbook Read the eBook
Unsere interaktive Produkt-Demo ansehen Mehr erfahren
Eine Demonstration vereinbaren Zeitplan
Einen Spezialisten kontaktieren Kontaktieren Sie uns