GDPR Lessons Learned

Uncertainty and contradictions defined the first year of General Data Protection Regulation (GDPR) enforcement. 

Companies tiptoed into compliance under threat of colossal fines that would shut down their operations (€20 million or 4% of their annual global turnover, whichever is higher). However, despite the one-year anniversary of the GDPR being marked by 144,000+ complaints from users and 89,000+ reported data breaches, the fines levied in that period were relatively modest.

Analysts believe that the first year of GDPR was a teething period. As businesses continue to struggle with the law’s compliance requirements, it’s time to ask what we can learn from this transition, and where do we go from here?
GDPR Penalties Are Escalating

Other than Google being hit with a £44 million fine for lack of transparency, few companies felt the full force of the GDPR during the law’s first year. That is, until British Airways and Marriott set new records for data privacy penalties in July 2019.

British Airways was fined £183 million by the UK’s Information Commissioner's Office (ICO) after 500,000 customers’ personal data was compromised in a cyberattack. Only one day later, the ICO hit Marriott with a £99 million fine because 339 million guest records had been breached through an unsecured reservation database. 

Other fines across the EU corroborate that the GDPR’s one-year anniversary marks the end of regulator leniency. Spanish soccer league La Liga were penalised £222,000 for spying on fans, because they did not adequately explain in their terms of service that their official app activated the microphone on a user’s device during game time. 

Elsewhere, an online Polish retailer was fined £557,000 for “insufficient organizational and technical safeguards” that caused a data breach, and a Swedish school board received a fine of £16,000 when its facial recognition trial for student attendance didn’t stand up to GDPR scrutiny.

Although these fines aren’t as headline-grabbing as those against British Airways and Marriott, they do indicate that regulators believe all types of organisations have had sufficient time to understand the principles of the GDPR, and should be fined accordingly if they don’t comply. 

The key takeaway for businesses is that they can no longer be complacent about compliance — GDPR fines continue to escalate, and regulators do not discriminate.

Only the Beginning of International Privacy Laws 
The impact of the GDPR has been felt beyond its penalties, with its framework inspiring new privacy laws worldwide. A total of 107 countries have now introduced legislation to protect data privacy. For example, the California Consumer Privacy Act (CCPA) is on the horizon in the US, and is based on a model with similar principles to the GDPR.

As more laws get introduced, companies will be forced to rethink how they do business with the world. After the GDPR went into effect, over 1,000 US publications chose to shut off their content to users in the EU, either because they struggled with compliance, or didn’t think it was worth the cost.

The introduction of the GDPR has set in motion the creation of new global data boundaries, which companies must navigate with caution if they want to avoid financial consequences. In this way, any company that makes GDPR compliance a priority now is also giving itself a headstart with other international privacy laws as they come into force.

Conclusion
Regulators currently have a backlog of data breaches to process, which will likely lead to another wave of record-breaking GDPR penalties in the coming months. Moreover, while regulators have been catching up on this backlog, users have been gradually learning what new rights they have to their data.

According to a report by the ICO, 64% of data protection officers said they have seen an increase in customers and service users exercising their information rights since the GDPR came into effect on 25 May, 2018. Not only are regulators wielding their GDPR authority with more confidence, but users are becoming more aware of their data’s value - and further informed regarding the care companies must take when they process it.

From all angles, understanding compliance requirements and having a firm GDPR overview has never been more important.

___________

Simon Fogg is a legal analyst and data privacy expert for Termly. His focus for the past two years has been tracking the GDPR and its international impacts.

You Might Also Read: 

The GDPR Wake-Up Call Is Being Ignored By Business:

 

 

« Cyber Intelligence & Business Strategy
Cyber Training For Every US Federal Employee »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

Irish Reporting & Information Security Service (IRISS)

Irish Reporting & Information Security Service (IRISS)

IRISS-CERT is Ireland's first CSIRT (Computer Security Incident Response Team) to provide services to all users within Ireland.

Baker McKenzie

Baker McKenzie

Baker & McKenzie is an international law firm. Practice areas include Data & Technology.

Matta

Matta

Matta is a cyber security consulting company providing information security services and solutions including vulnerability assessments, penetration testing and emergency response.

SolutionsPT

SolutionsPT

SolutionsPT enables customers to strengthen their Operational Technology (OT) network to meet the ever increasing demand for performance, availability, connectivity and security.

RunSafe Security

RunSafe Security

RunSafe Security is the pioneer of a patented cyberhardening transformation process designed to disrupt attackers and protect vulnerable embedded systems and devices.

netfiles

netfiles

netfiles offers highly secure data rooms for sensitive business processes and secure data exchange.

LATRO Services

LATRO Services

LATRO Services is a complete solution provider to discover, locate, and eliminate telecom fraud.

BLUECYFORCE

BLUECYFORCE

BLUECYFORCE is the leading professional training and cyber defense training organization in France.

ABCsolutions

ABCsolutions

ABCsolutions is dedicated to assisting businesses and professionals achieve compliance with federal anti-money laundering regulations in an intelligent and pragmatic way.

OSI Security

OSI Security

OSI Security's primary services include penetration testing, security auditing, web application security testing and risk management.

RiskSmart

RiskSmart

RiskSmart empower risk, compliance, and legal teams with a tech-led and data-driven platform designed to save time, reduce costs and add real value to businesses.

Infoline Tec Group Berhad

Infoline Tec Group Berhad

Infoline Tec Group Berhad is principally involved in providing IT infrastructure solutions, cybersecurity service provider and solutions, managed IT and other IT services.

Aegis9

Aegis9

Aegis9 is an Australian owned and sovereign consultancy that specialises in providing tailored security solutions for both public and private sector clients based on their specific needs.

Chorus

Chorus

Chorus are a leading Managed Security Service Provider (MSSP), and member of the Microsoft Intelligent Security Association (MISA), with three Microsoft Advanced Specialisations in security.

Camms

Camms

Camms are a team of experienced professionals dedicated to providing innovative GRC software solutions that help organizations manage risk, make informed decisions, and drive positive change.

Career Smarter

Career Smarter

Career Smarter offers accredited online courses in cybersecurity and other sectors, helping learners gain industry-recognised certifications.