GDPR Lessons Learned

Uncertainty and contradictions defined the first year of General Data Protection Regulation (GDPR) enforcement. 

Companies tiptoed into compliance under threat of colossal fines that would shut down their operations (€20 million or 4% of their annual global turnover, whichever is higher). However, despite the one-year anniversary of the GDPR being marked by 144,000+ complaints from users and 89,000+ reported data breaches, the fines levied in that period were relatively modest.

Analysts believe that the first year of GDPR was a teething period. As businesses continue to struggle with the law’s compliance requirements, it’s time to ask what we can learn from this transition, and where do we go from here?
GDPR Penalties Are Escalating

Other than Google being hit with a £44 million fine for lack of transparency, few companies felt the full force of the GDPR during the law’s first year. That is, until British Airways and Marriott set new records for data privacy penalties in July 2019.

British Airways was fined £183 million by the UK’s Information Commissioner's Office (ICO) after 500,000 customers’ personal data was compromised in a cyberattack. Only one day later, the ICO hit Marriott with a £99 million fine because 339 million guest records had been breached through an unsecured reservation database. 

Other fines across the EU corroborate that the GDPR’s one-year anniversary marks the end of regulator leniency. Spanish soccer league La Liga were penalised £222,000 for spying on fans, because they did not adequately explain in their terms of service that their official app activated the microphone on a user’s device during game time. 

Elsewhere, an online Polish retailer was fined £557,000 for “insufficient organizational and technical safeguards” that caused a data breach, and a Swedish school board received a fine of £16,000 when its facial recognition trial for student attendance didn’t stand up to GDPR scrutiny.

Although these fines aren’t as headline-grabbing as those against British Airways and Marriott, they do indicate that regulators believe all types of organisations have had sufficient time to understand the principles of the GDPR, and should be fined accordingly if they don’t comply. 

The key takeaway for businesses is that they can no longer be complacent about compliance — GDPR fines continue to escalate, and regulators do not discriminate.

Only the Beginning of International Privacy Laws 
The impact of the GDPR has been felt beyond its penalties, with its framework inspiring new privacy laws worldwide. A total of 107 countries have now introduced legislation to protect data privacy. For example, the California Consumer Privacy Act (CCPA) is on the horizon in the US, and is based on a model with similar principles to the GDPR.

As more laws get introduced, companies will be forced to rethink how they do business with the world. After the GDPR went into effect, over 1,000 US publications chose to shut off their content to users in the EU, either because they struggled with compliance, or didn’t think it was worth the cost.

The introduction of the GDPR has set in motion the creation of new global data boundaries, which companies must navigate with caution if they want to avoid financial consequences. In this way, any company that makes GDPR compliance a priority now is also giving itself a headstart with other international privacy laws as they come into force.

Conclusion
Regulators currently have a backlog of data breaches to process, which will likely lead to another wave of record-breaking GDPR penalties in the coming months. Moreover, while regulators have been catching up on this backlog, users have been gradually learning what new rights they have to their data.

According to a report by the ICO, 64% of data protection officers said they have seen an increase in customers and service users exercising their information rights since the GDPR came into effect on 25 May, 2018. Not only are regulators wielding their GDPR authority with more confidence, but users are becoming more aware of their data’s value - and further informed regarding the care companies must take when they process it.

From all angles, understanding compliance requirements and having a firm GDPR overview has never been more important.

___________

Simon Fogg is a legal analyst and data privacy expert for Termly. His focus for the past two years has been tracking the GDPR and its international impacts.

You Might Also Read: 

The GDPR Wake-Up Call Is Being Ignored By Business:

 

 

« Cyber Intelligence & Business Strategy
Cyber Training For Every US Federal Employee »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

CyberSecurityJobsite.com

CyberSecurityJobsite.com

CyberSecurityJobsite.com is a specialist job board designed to attract candidates working within Cyber Security, Information Security or Information Assurance.

Bastille

Bastille

Bastille’s patented software and security sensors bring visibility to devices emitting radio signals (Wi-Fi, cellular, IoT) in your organization.

SafeCharge

SafeCharge

SafeCharge is a global provider of technology-based multi-channel payments services and risk management solutions for demanding businesses.

Exida

Exida

Exida is a leading product certification and knowledge company specializing in industrial automation system safety, security, and availability.

MIT Internet Policy Research Initiative (IPRI)

MIT Internet Policy Research Initiative (IPRI)

IPRI's mission is to work with policy makers and technologists to increase the trustworthiness and effectiveness of interconnected digital systems

IoT Now

IoT Now

IoT Now explores the evolving opportunities and challenges facing CSPs, and we pass on some lessons learned from those who have taken the first steps in next gen IoT services.

Blue Lights Digital

Blue Lights Digital

Blue Lights Digital have developed a range of platforms to support digital investigations, as well as providing continued support and education for investigations professionals.

Haven Group

Haven Group

Haven Group and its companies are a cyber security one-stop-shop for our clients offering a full range of cyber security services to our clients in a unified and united way.

Satori Cyber

Satori Cyber

The Satori Cyber Secure Data Access Cloud is the first solution on the market to offer continuous visibility and granular control for data flows across all cloud and hybrid data stores.

Trapp Technology

Trapp Technology

Trapp Technology combines the very best cloud, Internet, IT managed services, and IT consulting to provide a true all-in-one IT solution for small to mid-sized businesses.

Kiteworks

Kiteworks

Kiteworks (formerly Accellion) creates a dedicated Private Content Network that ensures zero-trust private content protection and compliance.

Incognia

Incognia

Incognia have created a ubiquitous private identity based on location behavior, that enables a personalized frictionless experience with mobile apps and connected devices.

Dimension Data

Dimension Data

Dimension Data is a leading African born technology provider operating in the Middle East and Africa, offering a portfolio of services including intelligent security solutions.

Hummingbird International

Hummingbird International

Hummingbird International, LLC offers services for the collection, audit, computer recycling and safe disposal of laptops, monitor/LCD, hard drives, and IT disposal.

StealthMole

StealthMole

StealthMole is a deep and dark web threat intelligence company that delivers a cloud-based, unified platform for digital investigation, risk assessment, and threat monitoring.

SecureKloud Technologies

SecureKloud Technologies

SecureKloud is a global leader in the Cloud services arena. Our experience in cloud consulting and servicing for highly regulated industries extends more than a decade.

CoinCover

CoinCover

Blockchain technology is changing everything. However, it brings its own set of unique risks. Coincover ensures everyone is protected, enabling them to innovate freely, without constraints.