About Partners Contact Client Portal
LinkedIn Twitter
Services Industries Insights & Events Careers & Culture

Services

RubinBrown specializes in providing a comprehensive range of services to meet business and personal needs. Whether you require expert tax, strategic business consulting, audit services or more, RubinBrown's team of experienced professionals are here to support you.

View All Our Services
Assurance Services
Benefit Plan Audit Services Public Company Services SOC Examinations, IT Audit, & Third-Party Risk
Consulting Services
Business Process Improvement Services Business Restructuring & Bankruptcy Services Cyber Security Services Environmental, Social and Governance Services ERP & Enterprise Software Advisory Fraud & Forensics SOC Examinations, IT Audit, & Third-Party Risk Information Technology Services Litigation Services Mergers & Acquisitions Services Risk & Internal Audit Services Valuation Services
Entrepreneurial Services
Outsourced Accounting & Advisory Services
Tax Services
Federal Tax Services Private Client Services Credits & Incentives Services State & Local Tax Services
RubinBrown Advisors RubinBrown Corporate Finance

Industries

At RubinBrown, we bring experience across a range of industries. Our experience enables our professionals to offer tailored solutions catering to the intricacies of each sector. Our professionals have years of focused engagement and skills, allowing them to navigate industry-specific challenges to benefit our clients.

View All Our Industries
Colleges & Universities Construction Gaming Healthcare Law Firms Life Sciences & Technology Manufacturing & Distribution Not-For-Profit Private Equity Public Sector Real Estate Transportation & Dealerships

Insights & Events

At RubinBrown, we provide valuable insights detailing emerging trends and industry-specific information. Our events, hosted virtually and in-person, keep you informed and connected to the topics and industries that matter most to you and your organization.

View All Insights & Events
Jun 11

RubinBrown’s Leveraging Technology for Business Success

Learn More & Register
Jun 17

RubinBrown’s Rural Health Webinar Series

Learn More & Register

RubinBrown Sports Betting Index: March 2025 Analysis

Learn More

Tax Bill Watch 2025: Budget Resolution Compromise

Learn More

Careers & Culture

At RubinBrown, we are inspired team members, working as one firm, living our core values, and Being Our Best for Others while delivering totally satisfied clients. We invite you to learn more about the Firm's culture, the Be Your Best for Others mentality, and explore the available opportunities at RubinBrown.

Discover Our Culture
Baker Tilly International Campus Recruiting Diversity & Inclusion Experienced Recruiting RubinBrown Charitable Foundation Join The Team
Back to Insights

Focus on Cyber Security: GDPR – A Common Sense Approach

Contact Us

Focus on Cyber Security: GDPR – A Common Sense Approach

Contact Us

The General Data Protection Regulation (GDPR) went into effect on May 25, 2018. With fines as high as €20 million or 4% of global revenues, the GDPR cannot be ignored. How do you know if the regulation applies to your organization and how can you comply?

The first thing to understand is that GDPR is focused on privacy rights of the person (data subject), and the goal is to give the person more control over their own data (how much is allowed to be collected and how it is used). The regulation is designed to create transparency, minimize the use and collection, improve security and increase accountability by organizations for personal information.

Most of the tenets and goals of GDPR are good privacy practices that all organizations should consider adopting (i.e., only collect what you need, only use it for what you said you would, correct it if it is wrong and allow the person to opt out of further contact). Of course, there are many details and requirements listed in the GDPR – so how do you know if it applies to your organization?

The obvious cases where organizations must comply include those who:

  • Have a physical presence in the EU
  • Advertise, market or sell to people in the EU
  • Collect, use or provide online data for targeting people in the EU with advertising, marketing or sales
  • Collect, process, store or transmit personal data for other organizations with customers in the EU

Please note that a “data subject” and “personal data” have specific GDPR definitions. For instance, a data subject in GDPR terms is a person physically present in the EU, regardless of nationality. And, personal data under GDPR includes a person’s IP (computer) address if it can be linked to their other information (which is why so many websites have “cookie” warnings lately).

The only obvious case where GDPR does NOT apply is when your organization is not physically present in the EU, only does business in person and does not retain any personal information from anyone. Many organizations fall into the “it depends” category – and need to document their analysis of what aspects of GDPR apply to them and their business processes.

While assisting clients with GDPR readiness assessments, we’ve noted that a critical aspect of determining what applies to your organization is understanding what GDPR data your organization collects and how that data is handled. This is best understood by performing a data flow analysis for your business processes. Once you understand what the data is, how it is handled and how it is protected, you can begin addressing GDPR compliance requirements.

A good site for additional detailed information is the Article 29 Working Party, which provides information, insights and commentary on some of the more complex aspects of GDPR.

Remember the GDPR is focused on transparency and accountability, so whether you perform your own analysis, hire consultants or engage outside counsel, document your analysis and decision process.

 

Any federal tax advice contained in this communication (including any attachments): (i) is intended for your use only; (ii) is based on the accuracy and completeness of the facts you have provided us; and (iii) may not be relied upon to avoid penalties.

 

Contact Us:

Be Your Best for Others at RubinBrown

At RubinBrown, our firm fosters a culture built upon five vision points, and are guided by our philosophy of Being Our Best for Others. Discover how you can be your best at RubinBrown today by visiting our Careers & Culture Overview for available opportunities and more.

Discover Our Culture

Join Our Mailing List

RubinBrown periodically sends breaking regulatory updates, technical summaries, industry-specific information and event (in-person and virtual) invitations through electronic newsletters.

Sign Up for Our Communications
1-800-678-3134 Certified Public Accountants & Business Consultants

Ranked a Top 50 Accounting Firm by Inside Public Accounting

Firm News Disclaimers Privacy Policy Client Payment © 2025 RubinBrown LLP
RubinBrown Executive Recruiting RubinBrown Advisors RubinBrown Corporate Finance