The article discusses the importance of data identification as the first step in achieving GDPR compliance. It states that organizations should begin by describing their personal data through definitions, algorithms, and sampling from existing records. They should then conduct a data discovery process to inventory all locations where personal data is stored, including scattered files and databases. Identifying personal data locations will help organizations respond to individual data requests and deletions as required by GDPR. The data identification process sets organizations on the path to implementing the remaining GDPR requirements by the May 2018 deadline.
Related topics: