Customer Logins

Obtain the data you need to make the most informed decisions by accessing our extensive portfolio of information, analytics, and expertise. Sign in to the product or service center of your choice.

Customer Logins

My Logins

All Customer Logins
S&P Global S&P Global Marketplace
Explore S&P Global

  • S&P Global
  • S&P Dow Jones Indices
  • S&P Global Market Intelligence
  • S&P Global Mobility
  • S&P Global Commodity Insights
  • S&P Global Ratings
  • S&P Global Sustainable1
Close
Discover more about S&P Global’s offerings
Investor Relations
  • Investor Relations Overview
  • Investor Presentations
  • Investor Fact Book
  • News Releases
  • Quarterly Earnings
  • SEC Filings & Reports
  • Executive Committee
  • Corporate Governance
  • Merger Information
  • Stock & Dividends
  • Shareholder Services
  • Contact Investor Relations
Languages
  • English
  • 中文
  • 日本語
  • 한국어
  • Português
  • Español
  • ไทย
About
  • About Us
  • Contact Us
  • Email Subscription Center
  • Media Center
  • Glossary
Product Login
S&P Global S&P Global Market Intelligence Market Intelligence
  • Who We Serve
  • Solutions
  • News & Insights
  • Events
  • Product Login
  • Request Follow Up
  •  
    • Academia
    • Commercial Banking
    • Corporations
     
    • Government & Regulatory Agencies
    • Insurance
    • Investment & Global Banking
     
    • Investment Management
    • Private Equity
    • Professional Services
  • WORKFLOW SOLUTIONS
    • Capital Formation
    • Credit & Risk Solutions
    • Data & Distribution
    • Economics & Country Risk
    • Sustainability
    • Financial Technology
     
    • Issuer & IR Solutions
    • Lending Solutions
    • Post-Trade Processing
    • Private Markets
    • Risk, Compliance, & Reporting
    • Supply Chain
    PRODUCTS
    • S&P Capital IQ Pro
    • S&P Global Marketplace
    • China Credit Analytics
    • Climate Credit Analytics
    • Credit Analytics
    • RatingsDirect ®
    • RatingsXpress ®
    • 451 Research
    See More S&P Global Solutions
     
    • Capital Access
    • Corporate Actions
    • KY3P ®
    • EDM
    • PMI™
    • BD Corporate
    • Bond Pricing
    • ChartIQ
  • CONTENT
    • Latest Headlines
    • Special Features
    • Blog
    • Research
    • Videos
    • Infographics
    • Newsletters
    • Client Case Studies
    PODCASTS
    • The Decisive
    • IR in Focus
    • Masters of Risk
    • MediaTalk
    • Next in Tech
    • The Pipeline: M&A and IPO Insights
    • Private Markets 360°
    • Street Talk
    SEE ALL EPISODES
    SECTOR-SPECIFIC INSIGHTS
    • Differentiated Data
    • Banking & Insurance
    • Energy
    • Maritime, Trade, & Supply Chain
    • Metals & Mining
    • Technology, Media, & Telecoms
    • Investment Research
    • Sector Coverage
    • Consulting & Advisory Services
    More ways we can help
    NEWS & RESEARCH TOPICS
    • Credit & Risk
    • Economics & Country Risk
    • Financial Services
    • Generative AI
    • Maritime & Trade
    • M&A
    • Private Markets
    • Sustainability & Climate
    • Technology
    See More
    • All Events
    • In-Person
    • Webinars
    • Webinar Replays
    Featured Events
    Webinar2024 Trends in Data Visualization & Analytics
    • 10/17/2024
    • Live, Online
    • 11:00 AM - 12:00 PM EDT
    In PersonInteract New York 2024
    • 10/15/2024
    • Center415, 415 5th Avenue, New York, NY
    • 10:00 -17:00 CEST
    In PersonDatacenter and Energy Innovation Summit 2024
    • 10/30/2024
    • Convene Hamilton Square, 600 14th St NW, Washington, DC 20005, US
    • 7:30 AM - 5:00 PM ET
  • PLATFORMS
    • S&P Capital IQ Pro
    • S&P Capital IQ
    • S&P Global China Credit Analytics
    • S&P Global Marketplace
    OTHER PRODUCTS
    • Credit Analytics
    • Panjiva
    • Money Market Directories
     
    • Research Online
    • 451 Research
    • RatingsDirect®
    See All Product Logins
BLOG Jul 10, 2017

Maersk cyber attack highlights importance of EU data protection rules

Maritime & Trade Expert

This story originally published on Fairplay.IHS.com.

With the Maersk hacking debacle still fresh, a presentation by Moore Stephens on the reinforcing of EU data protection law was timely reminder of the need for companies to maintain security on all their systems and to be vigilant at all times, according to Moore Stephens associate director Christopher Beveridge.

Had the new rules already been in place, Maersk would have been required to report the breach within the first 72 hours after its discovery. If any data has been lost there would be a requirement to report it.

Even without the General Data Protection Regulation (GDPR), which will become enforceable on 25 May next year, the rules are strict, particularly when it concerns the personal data of individuals, but the GDPR will mean that companies holding sensitive personal data such as crew information, including passport and banking details, will need to look at their systems and ensure that they meet the new rules, said Beveridge.

Essentially the GDPR will supersede national legislation such as the UK's Data Protection Act of 1998, but it will maintain the general principles of the Data Protection Act, such as data controllers will need to show that the data is being used fairly, for a specific purpose, that it is adequate and accurate, and that it maintains an individual's rights and their security.

The GDPR will require companies and any data processors such as ship managers and crewing agents to have a good security infrastructure in place. Data processors are required to report any breaches without undue delay to the data controllers.

However, in a shift away from established data protection rules the GDPR will govern all organisations processing or handling personal data operating within the European Union, but it also applies to all organisations regardless of where they are based, though Beveridge points out the EU has not specified how it will enforce this element of the GDPR.

Enforcement will, it is promised, be rigorous and onerous with fines of 4% of annual global turnover or EUR20 million (USD22 million) whichever is the greater, and penalties can be levied on ship managers and agents and crewing agents, with the onus on data controllers to be aware of third-party data processors working on their behalf, explained Beveridge.

Consent rules have also been bolstered placing a requirement on data controllers to show "legal consent from all data subjects on how data collected is to be used", according to Beveridge. In addition, the GDPR stipulates that the data subject must be made aware of the implications of giving consent without the use of jargon, as "consents must be provided in an accessible form using clear and plain language".

Among the other rights that will be enshrined in the GDPR will be the right for individuals to request data is held in commonly used formats to allow portability and the transfer to other data controllers, while the individuals will have the right to confirmation that their data is being processed and these requests must be supplied free of charge. In addition, individuals will have the right to be 'forgotten' by all those holding data on them, including third-party processors.

Being prepared is the best method of compliance, said Beveridge, and that includes being aware of what information is already held through an information audit and looking at processes for dealing with portability and deletion requests. Companies should also consider what procedures are currently in place for the detection, investigation, and reporting of data breaches and look at whether they need to be updated.

Beveridge points out that a new data control system must have data protection designed into it; it must not be an afterthought. Another important requirement of the GDPR will be the appointment of a data protection officer (DPO) or a designated data controller within the organisation who will take care of compliance issues.

"Time is running out - there is less than one year before the enforcement of the GDPR and a failure to comply could have serious effects on an organisation, not just financially through penalties, but also through the loss of reputation," said Beveridge, adding that in the worst-case scenario some companies may be prevented from trading within some jurisdictions.

Previous Next
Recommended for you

Maritime & Trade: Maritime Solutions
Global Trade Solutions
How can our products help you?

We can optimize your trade data to help your business grow

Learn more

Hire industry-leading consultants by the hour

Get the objective, authoritative analysis you need without delays.
FIND AN EXPERT
Related Posts
VIEW ALL
Blog Oct 14, 2024

Maersk rules out Suez Canal routings for Gemini launch

Blog Oct 14, 2024

Heavy frontloading sets up US-Asia trade for falling rates, imports

Blog Oct 11, 2024

Brief ILA strike alters once-placid labor landscape on East, Gulf coasts

VIEW ALL
{"items" : [ {"name":"share","enabled":true,"desc":"<strong>Share</strong>","mobdesc":"Share","options":[ {"name":"facebook","url":"https://www.facebook.com/sharer.php?u=http%3a%2f%2fprod.azure.ihsmarkit.com%2fmarketintelligence%2fen%2fmi%2fresearch-analysis%2fmaersk-cyber-attack-highlights-importance-of-eu-data-protection-rules.html","enabled":true},{"name":"twitter","url":"https://twitter.com/intent/tweet?url=http%3a%2f%2fprod.azure.ihsmarkit.com%2fmarketintelligence%2fen%2fmi%2fresearch-analysis%2fmaersk-cyber-attack-highlights-importance-of-eu-data-protection-rules.html&text=Maersk+cyber+attack+highlights+importance+of+EU+data+protection+rules","enabled":true},{"name":"linkedin","url":"https://www.linkedin.com/sharing/share-offsite/?url=http%3a%2f%2fprod.azure.ihsmarkit.com%2fmarketintelligence%2fen%2fmi%2fresearch-analysis%2fmaersk-cyber-attack-highlights-importance-of-eu-data-protection-rules.html","enabled":true},{"name":"email","url":"?subject=Maersk cyber attack highlights importance of EU data protection rules&body=http%3a%2f%2fprod.azure.ihsmarkit.com%2fmarketintelligence%2fen%2fmi%2fresearch-analysis%2fmaersk-cyber-attack-highlights-importance-of-eu-data-protection-rules.html","enabled":true},{"name":"whatsapp","url":"https://api.whatsapp.com/send?text=Maersk+cyber+attack+highlights+importance+of+EU+data+protection+rules http%3a%2f%2fprod.azure.ihsmarkit.com%2fmarketintelligence%2fen%2fmi%2fresearch-analysis%2fmaersk-cyber-attack-highlights-importance-of-eu-data-protection-rules.html","enabled":true}]}, {"name":"rtt","enabled":true,"mobdesc":"Top"} ]}
Filter Sort
  • About S&P Global Market Intelligence
  • Quality Program
  • Email Subscription Center
  • Media Center
  • Our Values
  • Investor Relations
  • Contact Customer Care & Sales
  • Careers
  • Our History
  • News Releases
  • Support by Division
  • Corporate Responsibility
  • Ventures
  • Quarterly Earnings
  • Report an Ethics Concern
  • Leadership
  • Press
  • SEC Filings & Reports
  • Office Locations
  • IOSCO ESG Rating & Data Product Statements
  • © 2025 S&P Global
  • Terms of Use
  • Cookie Notice
  • Privacy Policy
  • Disclosures
  • Do Not Sell My Personal Information