TL;DR: GDPR makes organisations responsible for personal data they store and process, including requests for access and erasure, and Ground Labs argues that the cost of non-compliance can exceed the cost of preparation through fines, legal defence, and reputational damage. The core issue is not the deadline itself but whether data governance, retention, and transparency controls can support ongoing accountability.
NHIMG editorial — based on content published by Ground Labs: GDPR deadline and the organisational responsibility for EU citizen data
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
Questions worth separating out
Q: How should organisations prepare for GDPR data requests across distributed systems?
A: They should first build a current inventory of where personal data lives, which identities can reach it, and what retention rules apply.
Q: Why do IAM and data governance need to work together for GDPR?
A: Because GDPR obligations are operational, not abstract.
Q: What breaks when organisations cannot find all copies of personal data?
A: Erasure, retention, transfer governance, and breach scoping all break when personal data is not fully discoverable.
Practitioner guidance
- Map personal data to access paths Build and maintain a record of where EU citizen data is stored, which systems process it, and which identities can reach it.
- Operationalise subject rights workflows Create a repeatable process for Subject Access Requests and erasure requests that ties identity records to storage locations, retention schedules, and deletion evidence.
- Extend access reviews to non-human identities Review service accounts, API keys, and automation that can access personal data, not only employee accounts.
What's in the full article
Ground Labs' full article covers the operational detail this post intentionally leaves for the source:
- How the business liability argument maps to real GDPR enforcement and compliance exposure
- The practical impact of Subject Access Requests and Right to be Forgotten obligations on day-to-day operations
- Why poor transparency can become a reputational problem as well as a legal one
- How organisations should think about data discovery and governance in relation to personal data risk
👉 Read Ground Labs' analysis of GDPR liability and compliance responsibility →
GDPR data liability: what security and privacy teams need to know?
Explore further
GDPR exposes the cost of poor identity and data governance, not just poor legal process. The article is right to frame liability as organisational rather than technical alone. In practice, the ability to answer regulators depends on access control, retention enforcement, and audit evidence across human and non-human identities. The practitioner takeaway is that compliance breaks first where identity governance is incomplete.
A question worth separating out:
Q: Who is accountable when GDPR compliance fails across shared platforms and automation?
A: Accountability sits with the organisation that collects and processes the personal data, even when cloud services, vendors, or automation are involved. Shared platforms do not remove responsibility. Teams need named owners, documented controls, and audit evidence that covers both human and non-human access.
👉 Read our full editorial: GDPR compliance shifts data liability to every organisation