Only 20% of companies GDPR compliant

Only 20 per cent of companies surveyed believe they are compliant with the General Data Protection Regulation (GDPR), while 53 per cent are in the implementation phase and 27 per cent have not yet started their implementation.

This is according to a survey carried out by Dimensional Research on behalf of TrustArc in June among 600 IT and legal professionals with responsibility for privacy at companies required to meet GDPR compliance, split equally among the US, UK, and European Union.

EU (excluding UK) companies are further along, with 27 per cent reporting they are compliant, versus 12 per cent in the US and 21 per cent in the UK. While many companies have significant work to do, 74 per cent expect to be compliant by the end of 2018 and 93 per cent by the end of 2019.

“While the amount of effort was immense for the deadline of 25 May, there is substantive work yet to complete to achieve initial compliance as well as monitor and maintain compliance on a repeatable and efficient ongoing basis,” commented Chris Babel, chief executive of TrustArc.

While many companies still have a long way to go, a comparison to August 2017 research shows significant progress in the past 10 months. The number of companies whose GDPR implementation is under way or completed increased from 38 to 66 per cent in the US and from 37 to 73 per cent in the UK.

The research found that the cost of compliance is high, with 27 per cent of companies spending over half a million dollars each to become GDPR compliant, with 31 per cent planning to spend over half a million dollars each on GDPR compliance efforts between June and December 2018.

Despite difficulties in becoming GDPR compliant, 65 per cent view GDPR as having a positive impact on their business, with only 15 per cent viewing the GDPR as having a negative impact.

Meeting customer expectations (57 per cent) was the main driver to become compliant, significantly higher than concern over fines (39 per cent).

    Share Story:

Recent Stories


Safeguarding economies: DNFBPs' role in AML and CTF compliance explained
Join FStech editor Jonathan Easton, NICE Actimize's Adam McLaughlin and Graham Mackenzie of the Law Society of Scotland as they look at the role Designated Non-Financial Businesses and Professions (DNFBPs) play in the financial sector, and the challenges they face in complying with anti-money laundering and counter-terrorist financing regulations.

Ransomware and beyond: Enhancing cyber threat awareness in the financial sector
Join FStech editor Jonathan Easton and Proofpoint cybersecurity strategist Matt Cooke as they discuss the findings of the State of the Phish 2023 report, diving into key topics such as awareness of cyber threats, the sophisticated techniques being used by criminals to target the financial sector, and how financial institutions can take a proactive approach to educating both their employees and their customers.

Click here to read the 2023 State of the Phish report from Proofpoint.

Cracking down on fraud
In this webinar a panel of expert speakers explored the ways in which high-volume PSPs and FinTechs are preventing fraud while providing a seamless customer experience.

Future of Planning, Budgeting, Forecasting, and Reporting
Sage Intacct is excited to present FSN The Modern Finance Forum’s “Future of Planning, Budgeting, Forecasting, and Reporting Global Survey 2022” results. With participation from 450 companies around the globe, the survey results highlight how organisations are developing their core financial processes by 2030.