How GDPR is going to redefine the cloud
Box's EMEA head talks us through the impact of the new rules


This has lead to a lot of confusion within companies about what exactly it is that they need to be doing in order to reach compliance. Box has been helping customers to navigate this confusion where it can, by attempting to educate them about the best way to ensure they're up to standard. "Through sharing our own experience," Benjamin said, "we find that resonates a lot with some of our customers."
"This isn't a core part of our business, but it's the advisory services we provide, which we provide just because this is a subject we're really interested in, and we've got some really fascinating people internally," he said. "We've built up a huge amount of talent in this area, and we just like talking about it a lot."
"I personally think, for Box, that we are particularly well-positioned to help organisations navigate their way to making sure that they demonstrate the right activities in a post-GDPR environment."
Box is undeniably strong when it comes to matters of regulation and compliance; the company is one of only two organisations globally to possess the stringent C5 certification established by Germany's data protection authority, and has had its binding corporate rules approved by all 27 EU member states. Box prides itself on finding the highest data protection standards in the world, and then making a concerted effort to exceed them.
However, Benjamin was also keen to stress that although Box can help its clients meet the requirements of GDPR to a certain extent, at the end of the day it's up to the organisations themselves to ensure that they don't fall foul of the rules. The company runs webinars, group sessions and tutorials, for example, but it can't appoint a DPO or deal with the aftermath of a data breach within the company.
"Box doesn't extend its services to 'making customers GDPR-compliant'," he said; "that's not Box's responsibility. We can advise how we've done so, and we can actually point towards our own DPO, but it is a company's responsibility to appoint their own data protection officer."
Whether or not organisations think they should be concerned about GDPR, the fact is that the new regulations are going to fundamentally change the way that businesses think about compliance and data privacy.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"It's the next Y2K," Benjamin said. "And I don't think that's such a bad thing. At Box, we welcome and relish the opportunity for compliance standards to be set at an appropriate level, and we encourage our customers to think about raising the bar as well."
"I do think GDPR is setting a new tone and a new topic of conversation - what did we talk about before GDPR?"
Adam Shepherd has been a technology journalist since 2015, covering everything from cloud storage and security, to smartphones and servers. Over the course of his career, he’s seen the spread of 5G, the growing ubiquity of wireless devices, and the start of the connected revolution. He’s also been to more trade shows and technology conferences than he cares to count.
Adam is an avid follower of the latest hardware innovations, and he is never happier than when tinkering with complex network configurations, or exploring a new Linux distro. He was also previously a co-host on the ITPro Podcast, where he was often found ranting about his love of strange gadgets, his disdain for Windows Mobile, and everything in between.
You can find Adam tweeting about enterprise technology (or more often bad jokes) @AdamShepherUK.
-
RSAC Conference day two: A focus on what attackers are doing
From quantum to AI, experts discussed how new and experimental technologies could be used by hackers to access and decrypt sensitive data
-
The IT industry’s shift to circular, low-carbon solutions
Maximize your hardware investment and reach your sustainability goals with HP’s Renew Solutions
-
Data sovereignty a growing priority for UK enterprises
News Many firms view data sovereignty as simply a compliance issue
-
Elevating compliance standards for MSPs in 2025
Industry Insights The security landscape is set to change significantly in the years to come with new regulations coming into effect next year, here's how the channel needs to adapt
-
How ready is your company for NIS2?
Supported Content The EU’s latest cybersecurity legislation raises the stakes for enterprises and IT leaders - and ensuring compliance can be a daunting task
-
Forcing Apple to allow alternative app stores might cause major security risks
Analysis Apple will be forced to allow third-party marketplaces on its devices, but some experts have raised serious security concerns
-
Top data security trends
Whitepaper Must-have tools for your data security toolkit
-
Why bolstering your security capabilities is critical ahead of NIS2
NIS2 regulations will bolster cyber resilience in key industries as well as improving multi-agency responses to data breaches
-
Conquering technology risk in banking
Whitepaper Five ways leaders can transform technology risk into advantage
-
Advancing your risk management maturity
Whitepaper A roadmap to effective governance and increase resilience