{"id":2702,"date":"2019-12-27T11:58:46","date_gmt":"2019-12-27T08:58:46","guid":{"rendered":"https:\/\/www.endpointprotector.com\/blog\/?p=2702"},"modified":"2020-12-14T12:44:21","modified_gmt":"2020-12-14T09:44:21","slug":"the-2019-dlp-retrospective","status":"publish","type":"post","link":"https:\/\/www.endpointprotector.com\/blog\/the-2019-dlp-retrospective\/","title":{"rendered":"The 2019 DLP Retrospective"},"content":{"rendered":"<p>2019 was a dark one for data protection the world over. The number of data breaches spiked dramatically: the 5,183 that were reported exposed 7.9 billion records in the first nine months of 2019, with <a href=\"https:\/\/www.riskbasedsecurity.com\/2019\/11\/12\/number-of-records-exposed-up-112\/\" target=\"_blank\" rel=\"noopener noreferrer\">Risk Based Security<\/a> researchers estimating that the year-end figure will reach 8.5 billion. The total number of breaches has increased by 33.3% from 2018 while the number of records breached more than doubled.<\/p>\n<p>According to the Ponemon Institute and IBM Security\u2019s 2019\u00a0<a href=\"https:\/\/www.ibm.com\/security\/data-breach\" target=\"_blank\" rel=\"noopener noreferrer\">Cost of a Data Breach Report<\/a>, malicious attacks were the biggest root cause of data breaches, but only by a small margin. They accounted for 51% of data breaches, while the remaining 49% were due to human error and system glitches.<\/p>\n<p>Many of the big data breaches of 2019 were opportunistic attacks that took advantage of weak security practices to steal data. Unsecured databases were a particularly recurring theme in some of the year\u2019s biggest data thefts.<\/p>\n<h2>Data Breaches Got More Expensive<\/h2>\n<p>The cost of an individual data breach also <a href=\"https:\/\/www.endpointprotector.com\/blog\/the-cost-of-a-data-breach-at-the-end-of-2019\/\" target=\"_blank\" rel=\"noopener noreferrer\">increased this year<\/a>, reaching a global average of $3.92 million\/breach according to the 2019 Cost of a Data Breach Report. The United States had the highest average cost, with $8.19 million\/breach, while the Middle East had the highest average number of breached records, 38,800. The healthcare industry was hit the hardest, averaging $6.45 million\/breach, 65% more than the average cost of a data breach.<\/p>\n<p>While big organizations can weather the storm brought on by data breaches and recover in the long term in their aftermath, smaller companies are not so lucky. Reportedly, many of them fold <a href=\"https:\/\/www.inc.com\/joe-galvin\/60-percent-of-small-businesses-fold-within-6-months-of-a-cyber-attack-heres-how-to-protect-yourself.html\" target=\"_blank\" rel=\"noopener noreferrer\">within six months<\/a> of a major data breach. That\u2019s not surprising given the overall cost of a data breach\/employee: organizations with over 25,000 employees average data breach costs of $5.11 million or $204\/employee, while companies with 500 to 1000 employees average $2.65 million, or $3,533\/employee.<\/p>\n<h2>Data Protection Legislation Takes Over the Globe<\/h2>\n<p>In the wake of the EU\u2019s <a href=\"https:\/\/www.endpointprotector.com\/epp\/gdpr-the-most-in-depth-guide-to-stay-compliant\" target=\"_blank\" rel=\"noopener noreferrer\">General Data Protection Regulation<\/a> (GDPR), governments around the world have taken steps to update existing privacy laws or have successfully pushed forward new data protection bills to align themselves to the new international standards and ensure that cross-border data transfers with the European block continue unhindered.<\/p>\n<p>In 2019, the race for compliance switched continents, moving from Europe to the US as companies braced for the impact of the <a href=\"https:\/\/www.endpointprotector.com\/epp\/ccpa-compliance-the-most-in-depth-guide\" target=\"_blank\" rel=\"noopener noreferrer\">California Consumer Privacy Act <\/a>(CCPA), the most comprehensive privacy law in US history which will be enforced starting mid-2020. This year brought <a href=\"https:\/\/www.endpointprotector.com\/blog\/ccpa-update-latest-amendments-and-draft-regulations\/\" target=\"_blank\" rel=\"noopener noreferrer\">several amendments<\/a> to the CCPA that expanded mandatory data breach notifications to new categories of data as well as the first set of proposed regulations by California Attorney General Xavier Becerra.<\/p>\n<p>Meanwhile, as talks of a US-wide federal privacy law <a href=\"https:\/\/www.endpointprotector.com\/blog\/the-us-federal-privacy-law-picks-up-steam\/\">intensified<\/a>, Nevada quietly passed and enforced a <a href=\"https:\/\/www.endpointprotector.com\/blog\/all-you-need-to-know-about-nevadas-updated-privacy-law\/\" target=\"_blank\" rel=\"noopener noreferrer\">CCPA-inspired update<\/a> to its privacy law which granted its residents the right to opt-out of the sales of their personal information.<\/p>\n<p>Brazil passed its comprehensive general <a href=\"https:\/\/www.endpointprotector.com\/blog\/data-protection-in-canada-pipeda\/\">data protection<\/a> law, the <a href=\"https:\/\/www.endpointprotector.com\/blog\/about-brazils-new-data-protection-law\/\" target=\"_blank\" rel=\"noopener noreferrer\">Lei Geral de Prote\u00e7\u00e3o de Dados <\/a>(LGPD) on 14 August 2018, but doubts about it ever being enforced emerged when then-president Michel Temer vetoed several acts of the bill before its passing, most notably those needed to create Brazil\u2019s data protection authority, the Autoridade Nacional de Prote\u00e7\u00e3o de Dados (ANPD).<\/p>\n<p>2019 brought a much needed resolution: Brazil\u2019s new president, Jair Bolsonaro, promulgated <a href=\"http:\/\/www.planalto.gov.br\/ccivil_03\/_ato2019-2022\/2019\/lei\/L13853.htm\" target=\"_blank\" rel=\"noopener noreferrer\">Law No. 13.853\/2019<\/a> which amended some provisions of the LGPD and provided for the creation of the ANPD.<\/p>\n<p>This year, <a href=\"https:\/\/www.endpointprotector.com\/blog\/the-thailand-personal-data-protection-act-what-we-know-so-far\/\" target=\"_blank\" rel=\"noopener noreferrer\">Thailand\u2019s <\/a>National Legislative Assembly finally passed the Personal Data Protection Act (PDPA) on 28 February 2019, a law nearly twenty years in the making. After receiving a royal endorsement, the PDPA was published in the Government Gazette and passed into law. It is now set to come into force on 27 May 2020.<\/p>\n<p>Elsewhere in Asia, Singapore has <a href=\"https:\/\/www.endpointprotector.com\/blog\/about-singapores-pdpa\/\" target=\"_blank\" rel=\"noopener noreferrer\">taken steps<\/a> to update its Personal Data Protection Act (PDPA) in the wake of the disastrous SingHealth data breach, while both <a href=\"https:\/\/www.endpointprotector.com\/blog\/chinas-data-security-administrative-measures\/\" target=\"_blank\" rel=\"noopener noreferrer\">China <\/a>and <a href=\"https:\/\/www.endpointprotector.com\/blog\/indias-personal-data-protection-bill-what-we-know-so-far\/\" target=\"_blank\" rel=\"noopener noreferrer\">India <\/a>have new sweeping data protection legislation in the works.<\/p>\n<h2>GDPR Fines are Here<\/h2>\n<p>The training wheels came off the GDPR this year as data protection authorities (DPAs) across Europe began issuing fines. While no company has yet to attract the full wrath of GDPR penalties, 4% of its global annual turnover, British Airways came pretty close, with the UK\u2019s Information Commissioner\u2019s Office (ICO) <a href=\"https:\/\/ico.org.uk\/about-the-ico\/news-and-events\/news-and-blogs\/2019\/07\/ico-announces-intention-to-fine-british-airways\/\" target=\"_blank\" rel=\"noopener noreferrer\">proposing <\/a>a staggering \u20ac204 million fine amounting to 1.5% of the company\u2019s global annual turnover in July 2019, for security failures that led to a breach which affected 500,000 of their customers. Similar security failures <a href=\"https:\/\/ico.org.uk\/about-the-ico\/news-and-events\/news-and-blogs\/2019\/07\/statement-intention-to-fine-marriott-international-inc-more-than-99-million-under-gdpr-for-data-breach\/\" target=\"_blank\" rel=\"noopener noreferrer\">cost <\/a>Marriott International around \u20ac110.4 million.<\/p>\n<p>France\u2019s data protection authority, the Commission Nationale de l&#8217;Informatique et des Libert\u00e9s (CNIL), went after US tech giant Google, slapping the company with a \u20ac50 million <a href=\"https:\/\/www.cnil.fr\/en\/cnils-restricted-committee-imposes-financial-penalty-50-million-euros-against-google-llc\" target=\"_blank\" rel=\"noopener noreferrer\">fine <\/a>for lack of consent on ads.<\/p>\n<p>The end of 2019 brought with it the first multi-million euro GDPR fines to Germany. In November, the Berlin Commissioner for Data Protection and Freedom of Information (BfDI) announced <a href=\"https:\/\/edpb.europa.eu\/news\/national-news\/2019\/berlin-commissioner-data-protection-imposes-fine-real-estate-company_en\" target=\"_blank\" rel=\"noopener noreferrer\">it had fined<\/a> Deutsche Wohnen SE, a prominent real estate company, \u20ac14.5 million, its biggest fine to date, for retaining personal data for an unlimited period of time without checking whether the retention was legitimate or not.<\/p>\n<p>In December, the BfDI <a href=\"https:\/\/www.zdnet.com\/article\/data-privacy-germans-dish-out-one-of-biggest-gdpr-fines-yet-over-lax-call-centers\/\" target=\"_blank\" rel=\"noopener noreferrer\">issued <\/a>another major fine of \u20ac9.55 million, to mobile services provider 1&amp;1 Telecommunications for failing to take the appropriate technical and organizational measures to protect the processing of personal data.<\/p>\n<p>The Austrian Post was issued with a \u20ac18 million <a href=\"https:\/\/edpb.europa.eu\/news\/national-news\/2019\/administrative-criminal-proceedings-austrian-data-protection-authority_en\" target=\"_blank\" rel=\"noopener noreferrer\">fine<\/a> under the GDPR after the Austrian Data Protection Authority found evidence it had processed the political affiliation of data subjects as well as relocation and package frequency data for the purpose of direct marketing.<\/p>\n<p>Across the EU, there were 27 major fines issued, amounting to approximately \u20ac430 million, showing that data protection authorities now consider companies have had enough time to reach GDPR compliance. Any organization now found wanting will no longer have any excuses and DPAs have shown they are not shy about using the full extent of their powers to enforce the GDPR.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>2019 was a dark one for data protection the world over. The number of data breaches spiked dramatically: the 5,183 that were reported exposed 7.9 billion records in the first nine months of 2019, with Risk Based Security researchers estimating that the year-end figure will reach 8.5 billion. The total number of breaches has increased &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.endpointprotector.com\/blog\/the-2019-dlp-retrospective\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;The 2019 DLP Retrospective&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":2703,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2702","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-loss-prevention","entry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/2702","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/comments?post=2702"}],"version-history":[{"count":9,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/2702\/revisions"}],"predecessor-version":[{"id":3783,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/2702\/revisions\/3783"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media\/2703"}],"wp:attachment":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media?parent=2702"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/categories?post=2702"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/tags?post=2702"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}