GDPR news: GDPR turns six months old

Experts say businesses still have a way to go before they reach compliance

GDPR at a glance

The General Data Protection Regulation (GDPR) came into force across the EU on 25 May 2018, forcing an update to the UK's existing Data Protection Act 1998 (now DPA 2018). Designed to give people more control over their data, GDPR represents a challenge to organisations, who must bring their data protection policies into line with the new regulations or face substantial penalties.

GDPR compels organisations to secure clearer consent for using people's information, and introduces tougher fines for failing to protect people's data.

This hub collates all the latest GDPR news as it happens, but please follow these links for more information on what the GDPR is, and how to prepare for it. Separate facts from the hype about GDPR with our article puncturing marketing hyperbole.

21/11/2018: GDPR turns six months old

This week marks the six-month anniversary of the implementation of the General Data Protection Regulations, but despite the regulations being in force for half a year, experts have warned that some businesses still have work to do before they're compliant with the rules.

The new regulations drew much attention for the heavy potential fines they introduced - up to 4% of a company's annual turnover or 20 million, whichever is higher - and left companies scrambling to implement new policies and procedures in order to bring their business in line with the updated laws.

Businesses have now had six months to meet the new standards, but in spite of this, industry experts have stated that many businesses still aren't prepared to cope with GDPR.

"Today, there is still a strong chance that a number of organisations could be struggling with issues around data sprawl, the volume of personal customer information and uncertainty around data ownership," said Citrix's chief security architect Chris Mayers, "as our research from around a year ago suggested."

"The poll also found the average large UK business was reliant on 24 systems to manage and store personal data, with one in five (21%) using over 40 systems to do so. Tackling such data sprawl wasn't easy then and won't be now if still the case."

Although the ICO has thus far failed to issue one of the dreaded maximum fines, some organisations have already been penalised under the new rules, including Brexit data analysis firm AggregateIQ and a Portuguese hospital.

"For those businesses still on the GDPR compliance journey, you cannot afford to rest on your laurels," Mayers said. "Public awareness of an organisation's responsibilities around data protection have never been higher -- with breach complaints to the Information Commissioner's Office on the increase. Reputations and revenues are on the line, and now is the time to ensure a long-term GDPR compliance strategy is in place, if it isn't already."

Featured Resources

Unlocking collaboration: Making software work better together

How to improve collaboration and agility with the right tech

Download now

Four steps to field service excellence

How to thrive in the experience economy

Download now

Six things a developer should know about Postgres

Why enterprises are choosing PostgreSQL

Download now

The path to CX excellence for B2B services

The four stages to thrive in the experience economy

Download now

Most Popular

Microsoft is submerging servers in boiling liquid to prevent Teams outages
data centres

Microsoft is submerging servers in boiling liquid to prevent Teams outages

7 Apr 2021
Hackers are using fake messages to break into WhatsApp accounts
instant messaging (IM)

Hackers are using fake messages to break into WhatsApp accounts

8 Apr 2021
How to find RAM speed, size and type
Laptops

How to find RAM speed, size and type

8 Apr 2021