{"id":1728,"date":"2018-08-03T16:39:00","date_gmt":"2018-08-03T13:39:00","guid":{"rendered":"https:\/\/www.endpointprotector.com\/blog\/?p=1728"},"modified":"2026-06-16T20:59:12","modified_gmt":"2026-06-16T17:59:12","slug":"two-months-later-living-in-a-post-gdpr-world","status":"publish","type":"post","link":"https:\/\/www.endpointprotector.com\/blog\/two-months-later-living-in-a-post-gdpr-world\/","title":{"rendered":"Two Months Later: Living in a Post-GDPR World"},"content":{"rendered":"<p>It\u2019s been over two months since the EU\u2019s <a href=\"https:\/\/www.endpointprotector.com\/epp\/gdpr-the-most-in-depth-guide-to-stay-compliant\" target=\"_blank\" rel=\"noopener noreferrer\">General Data Protection Regulation<\/a> (GDPR) has come into force on May 25<sup>th<\/sup> and, after a feverish rush for compliance overtook all businesses, a period of relative calm followed in the wake of its implementation. Whether this was because both organizations and users suffered from an oversaturation of GDPR-related content, updated privacy policies and consent requests or the new regulation has yet to shed its training wheels, the GDPR has effectively left the limelight.<\/p>\n<p>That being said, if it\u2019s not making headlines as it did a year ago, the GDPR is leaving its mark on the data protection field by being the first legislation of its kind to tackle present-day dangers to data security and companies\u2019 accountability to their customers and the law in the face of these threats.<\/p>\n<p>The post-GDPR world is one full of anxiety and opportunity. Many companies are struggling to put in place the infrastructure needed to respond to incidents and data requests as laid out in the GDPR, while entrepreneurs are profiting by building tools that enable companies to more easily manage visitor and customer consent.<\/p>\n<p>Noncompliant companies may hope to never incur the wrath of customers and <a href=\"https:\/\/www.endpointprotector.com\/blog\/data-protection-in-canada-pipeda\/\">data protection<\/a> agencies, but with data breaches continuing unperturbed through the ingenuity of perpetrators or the neglect of employees and customers having the right to request their data at any time, it won\u2019t be long before they will find themselves on the wrong side of the GDPR.<\/p>\n<h2>GDPR Compliance Rising<\/h2>\n<p>US-based security company TrustArc <a href=\"https:\/\/info.trustarc.com\/Web-Resource-2018-07-12-GDPR-ResearchReport_LP.html\" target=\"_blank\" rel=\"noopener noreferrer\">surveyed<\/a> 600 companies across the EU, UK and the US about their GDPR compliance and found that, while only 20% of the companies surveyed believed themselves to be GDPR compliant, 53% are now in the implementation phase and 27% have not yet started. This is a significant boost from their results in a similar survey conducted in August 2017: \u00a0the number of companies whose GDPR implementation is under way or completed increased from 38% to 66% in the US and from 37% to 73% in the UK. While there is still significant progress to be made, 74% of respondents expect to be compliant by the end of 2018 and 93% by the end of 2019.<\/p>\n<p>Another interesting finding of the report was that, when asked about their reasons for seeking GDPR compliance, most companies did not cite the GDPR\u2019s much talked of fines, but first and foremost mentioned customer expectations followed by company values and partner expectations. The GDPR\u2019s fines and potential law suits ranked only 4<sup>th<\/sup> on their list of reasons.<\/p>\n<h2>Unexpected Consequences<\/h2>\n<p>The GDPR has had a few surprising effects: in the UK for example, the<a href=\"https:\/\/www.theguardian.com\/business\/2018\/jul\/17\/royal-mail-letters-junk-mail-gdpr-data-privacy-law\" target=\"_blank\" rel=\"noopener noreferrer\"> Royal Mail<\/a> saw its revenues from addressed letters drop 7% as companies reduced unsolicited junk mail to meet GDPR requirements. With website visitors now able to opt out of third party elements such as ad servers, Google Analytics and plugins, reduced loading times and a better user experience have been registered on sites running in the EU.<\/p>\n<p>A consequence everyone expected on the other hand has also become a reality: the GDPR has inspired legislators around the world to push their own data protection regulations towards adoption. From China\u2019s Internet Security Law to the California Consumer Privacy Act of 2018 (CCPA) and Brazil\u2019s Data Protection Bill of Law, data protection is becoming increasingly legislated across the world and the GDPR, with its ground-breaking policies, its pro-user approach and harsh penalties, has set the tone.<\/p>\n<h2>A Waiting Game<\/h2>\n<p>The GDPR\u2019s most dreaded promise, the fines for violating its core principles which can go up to \u20ac20 million or 4% of a company\u2019s global annual turnover for the preceding financial year, whichever is greater, has yet to claim any victims. Many national protection authorities have advocated for a period of lenient enforcement that would allow companies to finalize their GDPR compliance without risking fines.<\/p>\n<p>However, with some companies outright ignoring the risks of non-compliance and others <a href=\"https:\/\/www.ft.com\/content\/31d9286a-7bac-11e8-8e67-1e1a0846c475\" target=\"_blank\" rel=\"noopener noreferrer\">failing to respond<\/a> to data requests within one month, momentum is building towards full blown litigation cases and the first fines under the GDPR.<\/p>\n<p><a href=\"http:\/\/www.itpro.co.uk\/general-data-protection-regulation-gdpr\/31438\/ticketmasters-data-breach-could-be-the-litmus-test-for\" target=\"_blank\" rel=\"noopener noreferrer\">Ticketmaster<\/a>, the giant ticket selling company that suffered a breach that affected 40,000 British and international customers between September 2017 and 23 June 2018, may the first to wind up on the GDPR\u2019s chopping block for both its failure to disclose the breach to the UK\u2019s Information Commissioner\u2019s Office (ICO) within 72 hours of learning of its existence and its failure to adequately protect its customers\u2019 data. Both the business and legal worlds are holding their breath in anticipation, as this case may set the standard for GDPR implementation across Europe.<\/p>\n<p>These first few cases, whether they address the consequences for data breaches that big companies like Ticketmaster will face in the age of GDPR compliance or the fines companies will be expected to pay for failing to reply to data requests or disclose breaches in a timely fashion, are likely to set the standard for all future applications of the new regulation.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>It\u2019s been over two months since the EU\u2019s General Data Protection Regulation (GDPR) has come into force on May 25th and, after a feverish rush for compliance overtook all businesses, a period of relative calm followed in the wake of its implementation. Whether this was because both organizations and users suffered from an oversaturation of &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.endpointprotector.com\/blog\/two-months-later-living-in-a-post-gdpr-world\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Two Months Later: Living in a Post-GDPR World&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":1729,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[115],"tags":[],"class_list":["post-1728","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance","entry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/1728","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/comments?post=1728"}],"version-history":[{"count":6,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/1728\/revisions"}],"predecessor-version":[{"id":8350,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/1728\/revisions\/8350"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media\/1729"}],"wp:attachment":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media?parent=1728"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/categories?post=1728"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/tags?post=1728"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}