The General Data Protection Regulation (GDPR) finally comes into effect on Friday, May 25, 2018. The most significant change to European data protection laws in twenty years, GDPR will not only impact firms resident in the European Union (EU), but around the world, as any organisation doing business with EU citizens must comply with the regulation.

When it comes to authentication in the new era of GDPR, there are three things that every organisation should know:

  1. GDPR requires companies to implement data protection safeguards. Last year, 81 percent of all breaches were due to attacks that exploited weak or stolen passwords*. Strong, multi-factor authentication (MFA) is a fundamental building block of cyber security and data protection. Any approach to data protection that does not include the use of MFA is incomplete. But it’s important to remember that not all forms of MFA are created equal – older, first-generation MFA technologies are less effective now that attackers have learned how to bypass them.
  2. GDPR requires firms to respond to requests from individuals to view, change, delete, or transfer their data. It also means that businesses have to demonstrate that they obtained the consent from individuals to process their data, or explicit consent if the data is of a sensitive nature. In order to fully comply with this requirement, organisations must also be able to authenticate the identity of people making these requests.
  3. Biometrics are one of the most promising technologies available to deliver strong authentication, offering enhanced security and a far simpler user experience. However, GDPR highlights biometric data as a “sensitive” category of personal information requiring robust protection. Therefore, any entity implementing biometric authentication must ensure that its use of biometrics is compliant.

FIDO Alliance standards were created from the outset with a “privacy by design” approach and are a strong fit for GDPR compliance. Crucially, FIDO delivers authentication with no third-party involvement or tracking between accounts and services. And when it comes to biometrics, FIDO standards prevent this information from being stored and matched in servers – it never leaves the user’s device – and FIDO(R) Certified devices do not allow for any biometric data to be captured.

For more information about GDPR and how FIDO Authentication works, download our new white paper.


More

World Password Day Had a Good Run. Now We’re Celebrating A Future with Less Passwords

Andrew Shikiar, executive director and CMO, FIDO Alliance World Password Day was created in 2013…

Read More →

Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard to Accelerate Availability of Passwordless Sign-Ins

Faster, easier and more secure sign-ins will be available to consumers across leading devices and platforms …

Read More →

Latest updates from FIDO APAC Marketing Forum: FIDO Members from the Region Get Together to Learn from Each Other and Stay Alert

By Joon Hyuk Lee, APAC Market Development Director According to recent research reports and news,…

Read More →


Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.