GDPR Lessons Learned

Uncertainty and contradictions defined the first year of General Data Protection Regulation (GDPR) enforcement. 

Companies tiptoed into compliance under threat of colossal fines that would shut down their operations (€20 million or 4% of their annual global turnover, whichever is higher). However, despite the one-year anniversary of the GDPR being marked by 144,000+ complaints from users and 89,000+ reported data breaches, the fines levied in that period were relatively modest.

Analysts believe that the first year of GDPR was a teething period. As businesses continue to struggle with the law’s compliance requirements, it’s time to ask what we can learn from this transition, and where do we go from here?
GDPR Penalties Are Escalating

Other than Google being hit with a £44 million fine for lack of transparency, few companies felt the full force of the GDPR during the law’s first year. That is, until British Airways and Marriott set new records for data privacy penalties in July 2019.

British Airways was fined £183 million by the UK’s Information Commissioner's Office (ICO) after 500,000 customers’ personal data was compromised in a cyberattack. Only one day later, the ICO hit Marriott with a £99 million fine because 339 million guest records had been breached through an unsecured reservation database. 

Other fines across the EU corroborate that the GDPR’s one-year anniversary marks the end of regulator leniency. Spanish soccer league La Liga were penalised £222,000 for spying on fans, because they did not adequately explain in their terms of service that their official app activated the microphone on a user’s device during game time. 

Elsewhere, an online Polish retailer was fined £557,000 for “insufficient organizational and technical safeguards” that caused a data breach, and a Swedish school board received a fine of £16,000 when its facial recognition trial for student attendance didn’t stand up to GDPR scrutiny.

Although these fines aren’t as headline-grabbing as those against British Airways and Marriott, they do indicate that regulators believe all types of organisations have had sufficient time to understand the principles of the GDPR, and should be fined accordingly if they don’t comply. 

The key takeaway for businesses is that they can no longer be complacent about compliance — GDPR fines continue to escalate, and regulators do not discriminate.

Only the Beginning of International Privacy Laws 
The impact of the GDPR has been felt beyond its penalties, with its framework inspiring new privacy laws worldwide. A total of 107 countries have now introduced legislation to protect data privacy. For example, the California Consumer Privacy Act (CCPA) is on the horizon in the US, and is based on a model with similar principles to the GDPR.

As more laws get introduced, companies will be forced to rethink how they do business with the world. After the GDPR went into effect, over 1,000 US publications chose to shut off their content to users in the EU, either because they struggled with compliance, or didn’t think it was worth the cost.

The introduction of the GDPR has set in motion the creation of new global data boundaries, which companies must navigate with caution if they want to avoid financial consequences. In this way, any company that makes GDPR compliance a priority now is also giving itself a headstart with other international privacy laws as they come into force.

Conclusion
Regulators currently have a backlog of data breaches to process, which will likely lead to another wave of record-breaking GDPR penalties in the coming months. Moreover, while regulators have been catching up on this backlog, users have been gradually learning what new rights they have to their data.

According to a report by the ICO, 64% of data protection officers said they have seen an increase in customers and service users exercising their information rights since the GDPR came into effect on 25 May, 2018. Not only are regulators wielding their GDPR authority with more confidence, but users are becoming more aware of their data’s value - and further informed regarding the care companies must take when they process it.

From all angles, understanding compliance requirements and having a firm GDPR overview has never been more important.

___________

Simon Fogg is a legal analyst and data privacy expert for Termly. His focus for the past two years has been tracking the GDPR and its international impacts.

You Might Also Read: 

The GDPR Wake-Up Call Is Being Ignored By Business:

 

 

« Cyber Intelligence & Business Strategy
Cyber Training For Every US Federal Employee »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Yubico

Yubico

Yubico sets new global standards for simple and secure access to computers, mobile devices, servers, and internet accounts.

REVI-IT

REVI-IT

REVI-IT is a Danish state-owned audit firm focusing on enterprise IT business processes and compliance,

SGCyberSecurity

SGCyberSecurity

SGCyberSecurity is Singapore's No.1 Cyber Security portal. From this platform, you will be able to find useful articles, resources and connect with the security companies for your business needs.

National Information Technology Development Agency (NITDA) - Nigeria

National Information Technology Development Agency (NITDA) - Nigeria

The National Information Technology Development Agency (NITDA) is committed to implementing the Nigerian National Information Technology Policy.

Approachable Certification

Approachable Certification

Approachable Certification is a UKAS accredited certification body offering down-to-earth and competitively priced audits against ISO Management Systems standards.

New Enterprise Associates (NEA)

New Enterprise Associates (NEA)

As one of the world’s largest and most active venture capital firms, NEA has developed deep domain expertise and insight into our industries of focus - technology and healthcare.

Baker Donelson

Baker Donelson

Baker Donelson is a law firm with a team of more than 700 attorneys and advisors representing more than 30 practice areas including Data Protection, Privacy and Cybersecurity.

Cytellix

Cytellix

Cytellix is an industry-standards-based, managed cybersecurity service provider, specializing in proactive behavioral analytics and situational awareness of an organization’s cyber posture.

Kinetic Investments

Kinetic Investments

Kinetic Investments provide entrepreneurs with the capital and support required to transform their vision into a success, in return for shared ownership of the company.

Force Majeure

Force Majeure

Force Majeure specializes in cybersecurity, incident response, and digital forensics, with experience spanning more than a decade.

SecureLayer7

SecureLayer7

SecureLayer7 is an international provider of integrated business information security solutions with an innovative approach to IT security.

Traced

Traced

TRACED is changing the detection paradigm. Empowering defenders to go on the offense to engage cyber attackers before they compromise your organization.

Ethiopian Cybersecurity Association (ECySA)

Ethiopian Cybersecurity Association (ECySA)

ECySA was formed to play an influential part in the ongoing and dawning cybersecurity practices of Ethiopia, efficiently creating public and private awareness on all kinds of cyber risks and threats.

Brightsolid

Brightsolid

Brightsolid are experts in Hybrid Cloud. We design, build and manage secure, scalable cloud environments that meet customers’ business ambitions.

Control D

Control D

Control D is a modern and customizable DNS service that blocks threats, unwanted content and ads - on all devices.

Cipher Net Shield

Cipher Net Shield

Cipher Net Shield specializes in secure E-wallet solutions with a strong focus on blockchain and cybersecurity, prioritizing both transaction security and the recovery of lost capital.