GDPR One Year On: What Have We Learned?
Saturday the 25th of May marked a year since the EU General Data Protection Regulations (GDPR) came into force in the EU. Most member states have adapted their national data protection laws to be GDPR equivalent (Portugal, Greece, and Slovenia are in the final stages) and the rules governing how data is collected, stored and used are now relatively well harmonised across the EU.
The publicity in the run-up to the GDPR introduction last year was hard to avoid, and many organisations and the public received lots of information. This had several effects. On the plus side, it shifted the focus of data management and security from the IT department to the C-suite. This was mainly due to the legal obligations on Directors and the headline-grabbing fines that are possible under GDPR in response to data breaches. Also, the discussions around GDPR implementation and compliance have provided a common reference point that data security professionals can use when discussing and championing data security within organisations and with third parties.
On the minus side, there is evidence that all the information sent in the months leading up to GDPR caused some people to screen out the message. Data from the EU from a survey of the general population shows that:
- 67% of EU citizens has heard of GDPR
- 57% know that is regulated at their national level
- 20% know their national regulator
Clearly more work informing the public is needed. The story isn't any better in SME businesses. A survey by Hiscox of 500 UK SME's showed that 39% don't know who GDPR effects, and 10% don't know that GDPR grants new data access rights to consumers.
Any business or organisation that does not have an accurate picture of their requirements under GDPR is at severe risk of reputational and financial damage if they have a data breach and do not report it correctly.
How was GDPR in the first year?
One year into GDPR it's clear that regulators across the EU have been taking an encouraging approach rather than the hefty fines based approach many feared in the run-up to the May 2018 go-live. Data from the EU survey already mentioned shows that in the first year of GDPR there have been:
- 89,271 data breach notifications to regulators. Notifications are required under the regulations.
- 144,376 complaints from individuals or groups to regulators about data handling.
Across the EU a total of €56M in fines were levied under GDPR, but this includes a single €50M fine given to Google by the French regulator. The remaining €6M in fines were spread, with the next largest of €220,000 levied on a Polish social media company for not informing users how their data would be processed. There have been no fines issued by the Irish regulators, although they have 65 ongoing investigations, including 19 into eight well known US based IT companies who have significant European presence in Ireland. Recent fines issued in the UK have not used the sanctions available under GDPR rules. For example, Facebook was levied with a £50,000 fine that was the maximum allowed under the UK data regulation laws that GDPR superseded.
Clear signals are coming from regulators across the EU that the approach taken in the first year to give time for compliance efforts to complete, and not use the stringent sanctions available is coming to an end. We can expect future fines to be much more significant than those issued so far, and for there to be more of them as ongoing investigations complete.
This makes it even more vital that organisations ensure that they are compliant with GDPR. It's not going to be forgotten by EU and National authorities, so it can't be ignored, or left as an IT issue by businesses and other organisations that collect and store people’s data.
We can help you stay on top of GDPR
Data is under attack on multiple fronts all the time. The increase in GDPR scrutiny means that successful cyber-attacks can be a lot more financially and reputationally damaging than they were in the past. There are likely to be more people reporting data breaches in future, due to the awareness of GDPR (or vindictiveness in some cases if a person takes a dislike to your organisation.)
At Renaissance, we specialise in IT security products. With our industry partners, we are focused on providing the best advice and delivering the best solutions to organisations of all sizes. Data security, integrity, and access control are core tools that we offer. Some areas we provide tools for are:
- Malware and Ransomware protection
- Device and endpoint protection
- DDoS attack protection
- Multi-factor authentication solutions
- Data encryption products
- Data leakage protection
- Email classification and encryption services
Conclusion
Having a good set of procedures and defences in place to guard against cyber-attacks is now a business differentiator when providing services to organisations that store user data. Being able to demonstrate that reasonable GDPR compliant procedures are in place is now a significant part of all IT procurement requests and bids. Renaissance can help you implement robust data security solutions, and make sure your GDPR compliance procedures are fit for purpose, and help your organisation operate and compete in the GDPR protected landscape.

