Only 2% of "GDPR-ready" organizations are actually compliant

Study Only two percent of ‘GDPR-ready’ organizations are compliant
Only 2% of "GDPR-ready" organizations are actually compliant
Author

27 July, 2017

The location of data processing equipment is no longer a determining factor - i.e., worldwide businesses can not avoid the application of the GDPR by locating processing equipment outside the EU. In the category of "data protection by design", there is a general obligation to "implement technical and organisational measures to show that [a company] has considered and integrated data protection into processing activities". Individuals will be required to clearly give their affirmative consent - e.g., it is expected that website tick-boxes must be "opt-in" and must not be pre-ticked.

"These are the fundamentals of compliance and the findings today should be used to educate businesses about the mistaken beliefs that could put an organisation out of business". With the right tools and an organisation-wide commitment, even the largest company can gain control of its sensitive data and protect itself from hackers, spies, and government sanctions. This will particularly impact websites and apps targeted at children. In fact, research firm PWC states that 92% of USA businesses list GDPR as a priority because they are working internationally or have European Union students that visit. There is also a "right to erasure" that provides an individual a right to have personal data erased if it is "no longer necessary in relation to the objective for which it was originally collected/processed".

Processors - Data processors will be directly subject to the provisions of the GDPR.

In Singapore, a breach of its data protection law could result in a potential fine of S$1 million. Meaning that they aren't actually compliant. According to recent research cyber-attacks can cost businesses anywhere from $14.00 to $2.35million per incident and data breaches and attacks are growing all the time. The risk of not meeting GDPR requirement can be cost prohibitive in other ways. However, as most breaches could arguably result in a risk to an individual, further guidance is now being sought on this point.

The EU Commission may identify specific jurisdictions which are deemed to have adequate data protection laws in place and to permit data transfers to those jurisdictions. The EU and US have negotiated a new data transfer agreement (the Privacy Shield) to replace their previous transfer arrangements.

In the absence of a relevant decision by the European Commission, the transfer of data to a third country without the need for the data protection authority's consent may take place only if adequate safeguards are provided, such as the use of Binding Corporate Rules (BCR) approved by the competent authority for the protection of personal data (a solution particularly favorable for global corporations) or standard contractual clauses adopted by the European Commission (controller-controller or controller-processor clauses) or the use of an approved code of conduct or certification mechanism. Binding corporate rules must be approved by the Information Commissioner's Office.

Labour MEP and head of the committee Claude Moraes said: "Several key positions still need to be filled under the new United States administration in order to meet the conditions of the adequacy decision". Infringement on certain articles of GDPR carry fines of up to €20M or up to 4% of total global revenue of the preceding year, whichever is greater. The rules also broadly define "important data" to include information that relates to national security, economic development, or social or public interest. The maximum fine for breach of the UK's current data protection legislation is set at £500,000.

Those not compliant by next May could face eye-watering financial punishment for either themselves or their customers, and the event, taking place on 5 and 6 September in central London, will shed light on the challenges and requirements faced by the channel over the legislation in the coming eight months.

Understand the new regulatory framework and, where relevant, identity the jurisdiction that will act as the "lead supervisory authority" of the business. Our research showed that nine per cent of organisations have established a dedicated team for GDPR compliance, while 35 per cent are handling it through existing compliance teams.

Provide mechanism to easily satisfy a data subject's request for personal data in a commonly used format.


More news


  • Patients advised to take full course of antibiotics prescribed by doctor

    Patients advised to take full course of antibiotics prescribed by doctor

    Antibiotic resistance has become a growing problem in recent years, now serving as a threat to human health , Newsweek reports . Bacteria have developed multiple tactics to boost their resistance, depending on the infection and antibiotic involved.
    Jets claim Lucky Whitehead

    Jets claim Lucky Whitehead

    Despite denials from Whitehead, the Cowboys informed him he would be released hours later, and it became official Tuesday. Whitehead's agent said that his client was not in Virginia at the time of the incident.
    Duterte asked to retract threat

    Duterte asked to retract threat

    Regional offices in Mindanao also declined to release data on the list of schools that supposedly operate without a permit. Rights groups say they are concerned that Duterte's rhetoric may give tacit approval to the military to abuse civilians.
  • Tyson Fury announces retirement from boxing again

    Tyson Fury announces retirement from boxing again

    After recently hinting that his fighting days were done, Tyson Fury has seemingly arrived at a decision on his future. In addition, even if Fury wanted to box he faces a U.K.
    Ormond St angels: We will nurse Charlie in a hospice

    Ormond St angels: We will nurse Charlie in a hospice

    An alternative arrangement appears unlikely, given the total breakdown in relations between the parents and the hospital. Ms Yates and Mr Gard had initially said they wanted 11-month-old Charlie to spend days with them at home before dying.
    Lionel Richie, Luke Bryan, Charlie Puth Being Considered for 'American Idol' Judges

    Lionel Richie, Luke Bryan, Charlie Puth Being Considered for 'American Idol' Judges

    ABC's American Idol reboot is finally coming together now that it has secured Ryan Seacrest as host and Katy Perry as a judge. It was previously announced that superstar Katy Perry would be the first celebrity to join the updated judges panel.
  • Woman Breaks Into Ex-Hubby's House And Destroys 54 Violins

    The furious woman has destroyed 54 rare violins and bows 70, worth 105, 9 million yen ($950 700). The husband, who's about 30 years the suspects elder, made and sold violins in Nagoya.
    Senator John McCain to return to United States Senate

    Senator John McCain to return to United States Senate

    Arizona is one of 31 states that expanded Medicaid under President Barack Obama's health care law, and Republican Gov. But unlike what they do for every other senator, his colleagues turned in his direction and broke into applause.
    Blue Jays try to sweep A's

    Blue Jays try to sweep A's

    The home runs also marked just the second time the Jays have ever hit back-to-back home runs with the second one being a walk-off. It is a third gain in as many games for the Jays since the beginning of the four series against the Athletics.
  • Kansas Governor Sam Brownback nominated US Religious Freedom Ambassador

    Kansas Governor Sam Brownback nominated US Religious Freedom Ambassador

    Brownback to do". "Sam Brownback's commitment to Kansas is admirable and he has served our state and country honorably". He ushered into law new abortion restrictions, controversial welfare reforms and an aggressive tax-cutting strategy.
    Here's What Everyone Missed About Jon and Dany's 'GoT' Meeting

    Here's What Everyone Missed About Jon and Dany's 'GoT' Meeting

    Daenerys assumes-like Hillary Clinton-that she should be queen because of her family ties and her white privilege (the dragons). Could they be conspiring against Daenerys? The images also show Grey Worm in his battle armor, about to storm Casterly Rock.
    Rise in e-cigarette use 'linked to rise in smokers quitting'

    Rise in e-cigarette use 'linked to rise in smokers quitting'

    Surgeon General's report looked at the use of e-cigarettes among the youth and was the first of its kind. Pharmacotherapy has been shown to help some people to quit smoking, but not at the same rate as e-cigs.