Only 5% of Companies Claim to be Ready For GDPR
Research conducted by the BSI Group has underlined the growing concern that European businesses are simply not ready for the General Data Protection Regulation (GDPR). Even though 97 percent of companies admit that the implementation of the GDPR will affect their business, just 5 percent say they are fully prepared for the new data regulation, with 33 percent stating that they are just over half way to compliance.
The GDPR comes into effect on 25 May 2018 and will require all companies to comply with stricter rules concerning the data protection and privacy of data subjects (citizens) within the EU. Failure to comply could result in fines of up to €20 million or 4 percent of an organisation’s annual global turnover, with supervisory authorities expected to crack down hard to encourage greater compliance.
Just five weeks away from the deadline, the research from the Cybersecurity and Information Resilience division of the BSI Group has found that European businesses are aware of the looming deadline – but far from ready. Over half of organisations surveyed highlighted their concern regarding the role of their employees in GDPR compliance, with one in five businesses revealing that they had experienced a data compromising incident in the past 12 months. The Data Protection Commissioner reported *2,795 valid data security breaches in 2017, an increase of 26% from 2016.
The BSI Group research also revealed that:
- One in five senior managers are actively engaged with the GDPR on behalf of their organisation
- 36 percent are allocating a substantial level of resources to meet GDPR requirements
- 97 percent of companies admit that the GDPR will affect the way they conduct their business.
Data Protection Officer (DPO)
While specific sectors (e.g. public authorities) and companies engaged in high risk data processing are obliged to appoint a Data Protection Officer under the GDPR, the survey found that:
- Only 27 percent of companies have a DPO training programme in place
- More than half of companies do not provide data protection training to employees
- 63 percent of businesses have not assigned a DPO.
Privacy Impact Assessments (PIAs)
An additional key requirement of GDPR is Privacy Impact Assessments (PIAs) (a risk-based assessment used to ensure that the rights and freedoms of individuals are protected when any processing of their data is performed by an organisation), and alarmingly the research revealed that over 40 percent of companies surveyed weren’t aware that PIAs will be a mandatory requirement and only 12 percent claimed to have a good knowledge of PIAs.
Commenting on the research, Stephen O’Boyle, Head of Professional Services at the BSI Group, says: “There’s a lot of talk surrounding the GDPR but with less than two months to go our research shows that organisations are still unprepared and don’t fully understand what’s required of them. Becoming GDPR ready is less complicated, less expensive and less daunting than many companies think.”
“Data processing is an issue for everyone and awareness levels are increasing – the recently published Data Protection Commissioner annual report highlighted that complaints had increased by **79 percent compared to 2016 and this year it’s anticipated that this figure will be even higher. The new General Data Protection Regulation was set up to benefit everyone and having the right systems in place is not only good practice but will ensure that organisations build trust and transparency with their customers and minimise privacy and security risks for the future,” concludes Stephen O’Boyle.
The BSI Group Cybersecurity and Information Resilience division provides a range of solutions to help organisations become GDPR compliant including consulting, training, research, technical solutions and outsourced Data Protection Officer (DPO) services. For more information visit www.bsigroup.com/cyber-ie .