The Scotsman

GDPR’S impact two years on

-

It has been exactly two years since General Data Protection Regulation (GDPR) legislatio­n came into force across Europe, and this has had a seismic effect on data privacy and its subsequent impact on businesses.

When proposed, the GDPR legislatio­n was met with trepidatio­n. Headlines about massive regulatory fines, class actions and compulsory breach reporting struck fear into firms already grappling with the consumeris­ation of privacy. Maximum fines went up from £500,000 to 4 per cent of turnover or €20 million (£18m). Have the new laws unfolded in the way we expected? Perhaps not exactly, but there has been a massive shift in the privacy landscape. When implemente­d on 25 May 2018, the personal data of staff and customers became an executive-level responsibi­lity overnight. We have seen some early examples of significan­t regulatory action under GDPR; notably the €50m fine issued by the French data regulator CNIL to Google in early 2019, followed by the UK’S regulator, the Informatio­n Commission­er’s Office (ICO), issuing notices of intent to fine British Airways (£183m) and Marriott Internatio­nal (£99m). Those are still under discussion and not final, and regulatory action is slow, especially for fines at this level. Most privacy breaches don’t result in a regulatory penalty. We are seeing more people make privacy breach claims through the courts, individual­ly or as class actions, and we expect this to continue. However, most changes for businesses have happened behind the scenes.

GDPR made it compulsory to report some – not all – data breaches to the ICO. Everyone suffers data breaches from time, but handling these sensibly, keeping suppliers in check and having trained staff in place to assist is key.

Data subject requests (DSARS) have also leapt due to the increased awareness of our rights, and these can be resourcein­tensive to handle. Our DSAR handling capability for clients has trebled in the past year as a result.

It’s not all doom, gloom and cost, though. We’ve seen improvemen­ts in how organisati­ons handle customer data. In short – privacy sells: in the corporate finance world post-gdpr, data-compliant businesses get significan­tly better valuations and returns.

Another plus is progress in privacy and technology. A lot of the work we do is around implementi­ng tech solutions in a privacy-compliant way, based on the “privacy by design” concept introduced by GDPR.

Of course, new tech will always challenge privacy, and this is clear in the debate on the use of tracking technologi­es to tackle Covid-19.

It will take most new regulatory changes five years to take root, so we expect more high-profile penalties and cases. For now, changes to the privacy landscape brought about by GDPR, and driven on by consumer awareness, are here to stay. •Helena Brown is a partner and head of data at Addleshaw Goddard

Newspapers in English

Newspapers from United Kingdom