GDPR’s Impact: The First Six Months

GDPR is now six months old, it’s time to take an assessment of the regulation’s impact so far. At first blush it would appear very little has changed. 

There are no well-publicised actions being taken against offenders. No large fines levied. So does this mean it’s yet another regulation that will be ignored?  Actually nothing could be farther from the truth.

The day GDPR came into law complaints were filed by data subjects against Facebook and Google. Complaints, that does not sound like action by regulators, in fact it’s not, its action taken by lawyers. 

GDPR is a much-evolved form of European regulation allowing data subjects to file suits against data collectors whom they believe are violating their rights. 

This battle is going to be fought in 28 EU countries courts much sooner than in their Data Protection ministries who enforce the law and handout fines for violations.

Activist legal teams like Austrian noyb and its founder Max Schrems who had a strong hand in drafting GDPR are taking up these complaints. 

Meanwhile activist Privacy International is going after the likes of Oracle, filing complaints in the UK along similar lines as to the claims against Google and Facebook in that there is ongoing disregard to establishing legitimate-use of data collected and a disregard of individual’s rights because in fact those individuals do not know their data is being collected, so there is no expectation they can ask that their data be removed.

Regulator action will take time as six months is too early to get a proper read. Yet, we can still get a feel for what is going on by looking at what’s happening in a given country. 

The UK is interesting; their Information Commissioner predates GDPR as UKs privacy regulations go back to 1998 and the UK commissioner is currently publishing findings and leveling fines after investigations for activities dating back to 2016. That gives us a feel for how long investigations may take under GDPR.

Perhaps we will not know the full impact for another two years to the magnitude of fines levied. 

Facebook’s challenges with Cambridge Analytica were lucky in that they fell under the prior law resulting in a smaller 500K GDP fine than the billions allowed by GDPR. 

Breaches at British Airways and others, which took place since GDPR became active, are being carefully monitored to see if in fact they were properly reported to the UK commission within the 72-hour limit of being discovered.

The hotbed for US companies is Dublin as Ireland is where many US companies have their European headquarters. Helen Dixon, the current Republic of Ireland Commissioner, and her office is one of the busiest in Europe working with these companies as they scrabble to be complaint under the law.

GDPR has had influence internationally, 10 countries including Canada, whose law just went active this month, now have very similar laws. California also has a much-watered down version that went into effect as well. None of these laws carry the same fines, but most allow for litigation. 

California is just one of 26 states that have such laws on the books. These laws vary widely in their rules. Because of this the Internet Association, an influential lobby group for Internet based companies, has come out indicating it would be for a single US law to provide uniform privacy assurance.

The difference being in how they want the law to be written. Here is an example: Google’s Android OS terms and conditions states that the user, by activating their service, consents to Google’s collection of their personal data across All Google products for any use. 

Today once you activate you can’t go back and ask them to remove you. The Internet Association’s President Michael Beckerman, states that individuals should have a right to ask what has been collected and then have this information removed, if they discontinue using the product/service. The difference is GDPR does not force you to disconnect your $1000 phone.

Given all that, perhaps it’s not surprising that Apple CEO, Tim Cook, has come out strongly in favor of having a similar strength version of GDPR in the USA. Apparently they don’t collect the same data that Google, Facebook and Amazon do. Score one for capitalism?

Overall GDPR has had a subtle but extremely influential impact in the Internet world already. With all the lawyers involved, it’s not likely going by the wayside anytime soon.

Help Net Security:

You Might Also Read:

GDPR Survey Shows 80% Non-Compliance

GDPR Alert As Average ICO Fines Double In A Year

« Japan’s Cyber Security Minister Admits He Just Doesn't Get It
Britain's Top Soldier Warns Of Russian Threats »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Security Affairs

Security Affairs

Security Affairs is a blog covering all aspects of cyber security.

Paladion

Paladion

Paladion is a provider of managed IT security services.

Security Onion Solutions

Security Onion Solutions

Security Onion Solutions is the creator and maintainer of Security Onion, a free and open platform for threat hunting, network security monitoring, and log management.

AppViewX

AppViewX

AppViewX is a global leader in the management, automation and orchestration of network services in data centers.

Gallarus Industry Solutions

Gallarus Industry Solutions

Gallarus leads innovation within industrial Manufacturing, Production and Management Systems, including Cyber Security solutions specifically developed to protect against the latest cyber criminality.

Enclave Networks

Enclave Networks

Our mission is to give IT professionals a simple way to rapidly build secure connectivity between any application, computer system, device or infrastructure - regardless of the underlying network.

LOGbinder

LOGbinder

LOGbinder eliminates blind spots in security intelligence for endpoints and applications.

TechDemocracy

TechDemocracy

TechDemocracy are a trusted, global cyber risk assurance solutions provider whose DNA is rooted in cyber advisory, managed and implementation services.

Symmetry Systems

Symmetry Systems

Symmetry Systems is a provider of data store and object-level security (DSOS) solutions that give organizations visibility into, and unified access control of, their most valuable data assets.

Otorio

Otorio

OTORIO delivers industrial cybersecurity and digital risk-management solutions and services. We help our customers to keep their revenue-generating operations resilient, efficient, and safe.

Everything Blockchain

Everything Blockchain

Everything Blockchain is a development, architecture, and software designer of Blockchain that also provides services specializing in blockchain technologies and decentralized processing.

Althammer & Kill

Althammer & Kill

Althammer & Kill offers pragmatic solution concepts for data protection and digitization. We advise in the field of data protection, information security and compliance.

Darknone Global

Darknone Global

Darknone is a consortium of elite hackers and security leaders united by an unbridled passion for augmenting the security of the digital realm.

Firesand

Firesand

Based in Milton Keynes, Firesand Ltd provides penetration testing services to improve your cyber security and protect your company against hackers.

Liquis Inc.

Liquis Inc.

Liquis, founded in 2002, is one of the largest facility decommissioning services companies in the U.S.

Backblaze

Backblaze

The Backblaze Storage Cloud provides a foundation for businesses, developers, IT professionals, and individuals to build applications, host content, manage media, back up and archive data, and more.