Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Three Years of GDPR: Has it Delivered on Its Promise?
Articles

Three Years of GDPR: Has it Delivered on Its Promise?

Rob PriceBy Rob PriceJune 30, 2021Updated:May 2, 20255 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
data security
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In this data-driven world, culpability and legislation are crucial. More crucial, and not to be overlooked, however, is that they fulfill their purpose – improving overall data privacy and security. As of May 2021, three years have passed since the inception of GDPR, Europe’s data privacy, and security law. Despite the flurry of activity that preceded its launch, which left IT professionals clambering to ensure their organisations were compliant with the new regulations, millions of pounds’ worth of fines have been levied against businesses of all sizes. In fact, according to DLA Piper’s latest GDPR Data Breach Survey, there have been more than 281,000 data breach notifications since the legislation’s inception in 2018.

As a result, serious concerns have been raised over the legislation’s efficacy, and for many, this law has failed to deliver on its most basic premise. Gartner projected in 2018 that only 50% of organisations would be prepared for the impact of GDPR. Theoretically, this figure would have improved from then to now – after all, it has been three years. But with technology innovations and user behaviour in constant flux, threats evolve at a frightening speed, is this a fair – or accurate – yardstick to measure organisations against?

The digital landscape is different now compared to 2018. Heck, it’s different now to how it was in 2020. Apples and oranges, you might say. Both government regulation and business strategy must now adapt, pivoting accordingly. It is for this reason, that businesses must take the lead on the challenge of protecting their customers’ data, accepting and understanding the role they play within it as, evidently, state law isn’t enough. For this, the right tools will be critical.

Industries lagging behind

Driving the scepticism over GDPR’s effectiveness is the shift and evolution of people’s digital lifestyles. The rapid pace of tech innovation, increased reliance on data and the growing threat of cybersecurity have all been pinpointed as areas that have outgrown the blueprint launched in 2018. For IT leaders, the overwhelming feeling is that GDPR isn’t able to regulate the handling and protection of data in today’s updated and decentralised IT landscape.

Scoping the opinion of 1,000 IT leaders and 3,000 employees, a similar call for stronger rules and updated guidelines was also shared through Snow’s 2021 IT priorities report. This report found that 94% of IT leaders and 82% of employees believe more regulations are needed in the tech arena. Only 74% of the latter reported the same back in a 2019 global worker survey, highlighting how much has changed in a short space of time. More specifically, of those who do want to see more tech regulations introduced, the two leading areas brought to light were data protection and cybersecurity.

The doubtful advantage of market-expectation and compliance

It makes sense that data protection and cybersecurity would be high priorities for many individuals. Since the start of 2020 and the rise of the pandemic, a rapid and necessary shift to remote working took place. Not only that but consumers were forced to conduct vast portions of their day-to-day routines through digital channels. As a result, both individual and organisation’s digital footprints have expanded exponentially, and the end result is a stronger comprehension of the privacy pitfalls that come with such a strong digital presence.

Understandably, individuals are holding organisations that collect and store data responsible and accountable for their privacy. And a failure to either comply with regulation, or to ensure data protection in a more competitive marketplace, is a double-edged sword that businesses need to address. With consumers and employees now expecting a true hybrid proposition of both on-premises and cloud services, technology blind spots need to be mitigated as a matter of urgency.

A calculated, clever and connected ecosystem

To be truly disruptive and effective, businesses must be armed with the correct tools to manage compliance. And for this, the biggest asset will be visibility. Tools that provide visibility and manageability of an organisation’s entire IT ecosystem are vital. From that position of overarching insight, strategy and investment can be earmarked according to an informed roadmap, rather than adhering solely to a legislation that you already know isn’t completely effective at this time.

Considering the hybrid IT era that is upon us, this enhanced visibility can help to connect siloes within companies, to give a unified view when it comes to data analysis and use, and to enable actual transparency with consumers, so they are comforted by the privacy protocols that are in place. With this conjoined, intelligent, and strategic ecosystem in place, organisations can truly protect personal data and keep customers safe, no matter how quickly the business world continues to evolve.

Company concern has evolved from one of tick-box compliance to one that balances both compliance and the need for effective data protection as a differentiator. The general consensus is that existing tech regulations aren’t enough in such a consumer-centric world where privacy and security are every bit as important to people as the service being provided. Businesses now must adopt a two-pronged attack where they continue to urge greater assistance from GDPR while investing in their own levels of visibility to keep up their end of the data bargain.

Rob Price

Senior Specialist Solutions Consultant and Global Lead for Risk & Compliance

  • Rob Price
    Technology Blind Spots: Is Lack Of Visibility Leaving Your Business Exposed?

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}