No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Data Privacy

How GDPR Enforcement is Shaping Up in Europe

by Anne Shannon Baxter
December 13, 2018
in Data Privacy, Featured
GDPR logo on map of europe

(And Why U.S. Companies Should Take Note)

The General Data Protection Regulation (GDPR), Europe’s sweeping data protection law, has been in effect for six months, and while fines have yet to be levied against U.S. companies for breach of the law, enforcement is beginning to take hold. Anne Shannon Baxter of Access Partnership discusses what organizations with cross-border operations should know.

The General Data Protection Regulation (GDPR) has been in effect for six months, and U.S. companies are still struggling to understand its ramifications. As readers of this publication are aware, the European Union law applies to any foreign companies processing the personal data of data subjects residing in the EU, regardless of the company’s location. This means that businesses in the U.S. that offer goods and services, monitor the behavior of individuals or have an establishment within the EU are liable.

There have not been any fines levied against U.S. companies for breach of the law at the time of writing, but this won’t be the case for long and, with fines of up to €20 million or 4 percent of annual global turnover (whichever is the higher), the risk can’t be brushed off.

Adding to the difficulty, enforcement of the GDPR so far has focused on big technology companies, making it harder for many businesses to ascertain whether or not they are sufficiently prepared. Because fines under the GDPR are retroactive, companies must ensure they do not get complacent about their compliance.

GDPR Enforcement in Europe Ramps Up

Here’s how GDPR is playing out in Europe. At the recent International Association of Privacy Professionals’ European Data Protection Congress, Andrea Jelinek, the European Data Protection Board Chair, noted that there are several cross-border enforcement cases making their way through the board. While some rulings have already been handed down by regulators across Europe, enforcement and fines will become more frequent throughout 2019 as the transition period for GDPR implementation comes to an end.

Throughout Europe, the GDPR has seen a rapid increase in the number of complaints and breach notifications. On November 21, the German data protection authority (DPA) issued its first fine under the GDPR against a social media company for violating data security obligations by storing passwords in plain text. The German DPA’s fine of €20,000 is, however, significantly lower than the maximum fine for this issue — 2 percent of the company’s annual revenue —  thanks to the company’s cooperation with authorities. Uncooperative companies may push their eventual fines higher.

Businesses must remain vigilant and adhere to best practices as we wait for the first GDPR enforcement test case in the U.S. As a result of the GDPR’s threat of fines and its effect on cross-border data flows, many countries, including the U.S., are considering altering their domestic privacy laws to fit within the GDPR’s framework.

The U.S. Plays Catch-Up

There is growing consensus in the U.S. among legislators and industry that there is a need for federal privacy legislation to replace the current U.S. privacy regime: an amalgamation of self-regulation and strict regulation on government access to or use of personal data. An essential component of policymaker considerations will be ways to ensure equivalency with the EU’s data protection standards, both in the legislative framework and how it is enforced.

The U.S. Senate Subcommittee on Consumer Protection, Product Safety, Insurance and Data Security held a hearing in November with the Federal Trade Commission (FTC), which highlighted the need for a federal privacy law. The FTC hopes this would provide more resources and increase their enforcement abilities within the U.S.

In parallel, the National Telecommunications and Information Administration (NTIA) recently called for comments on the Commerce Department’s approach to consumer privacy. Several groups, mostly representing the technology industry, submitted comments with suggestions ranging from having state attorneys general enforce privacy standards to self-regulatory programs.

With the newly-elected members of the U.S. House of Representatives taking office in January 2019, there is hope that a Democratic-led House will invigorate the push for a federal data privacy regime. But don’t hold your breath; it remains unlikely that legislation of this magnitude will have an easy path through Congress. Any federal legislation that develops will likely be shaped by a combination of the GDPR, California’s Consumer Privacy Act, and already proposed bills like the one proposed by Senator Ron Wyden (D-OR). There is hope among industry players that a federal law will provide a unified regulatory landscape, potentially similar to California’s, which is set to come into effect in 2020.

However, any U.S. privacy law is as likely to push back on the GDPR as to be inspired by it. Many lawmakers and industry leaders in the U.S. have criticized the GDPR for creating trade barriers in certain markets, and privacy reform in the U.S. would offer an opportunity to create a counterweight model to the GDPR. 

A key feature of a privacy law such as this would be the protection of cross-border data flows and promotion of world engagement. Any counterweight will also need to offer political benefits that allow lawmakers to claim they are protecting and empowering consumers. A major advantage here would be a law that’s coherent and easily understood, or at least easily presented, but it must also find a balance between supporting innovation and placing guardrails on the use of data.

The GDPR has already had an outsized effect on businesses and the way they interact with consumer data, but this is not the end. Additional privacy regulations will develop in the coming years focusing on IoT and electronic communications. If businesses in the U.S. are already struggling with the impact of the GDPR, they should monitor the EU closely as the ePrivacy Regulation and European Electronic Communications Code move toward becoming legislation over the next year.


Tags: California Consumer Privacy Act (CCPA)GDPR
Previous Post

TRACE: Measuring Corruption

Next Post

Panorays Recognized as a Strong Performer in Cybersecurity Risk-Rating Solutions Report

Anne Shannon Baxter

Anne Shannon Baxter

Anne Shannon Baxter is a Policy Analyst at Access Partnership, a global public policy consultancy for the tech sector. U.S.- born and London-based, she analyzes public policy in the U.S. and emerging markets and provides advocacy support to businesses and government groups. Her areas of expertise include privacy, cybersecurity, political risk and multilateral processes. She can be reached at Anne.Baxter@accesspartnership.com.

Related Posts

federal trade commission building

[Q&A] Big Tech & Free Speech Under the Microscope: FTC’s New Direction

by FTI Consulting
April 28, 2025

What compliance teams need to know about the changing approach to consumer protection and data privacy

data governance concept

The US Still Lacks Its Own GDPR, But That Doesn’t Mean Data Privacy Enforcement Isn’t Happening

by Brian McGinnis and Maddie San Jose
April 16, 2025

Despite the absence of comprehensive federal privacy legislation, American businesses face mounting regulatory pressure from multiple directions. Brian McGinnis and...

origami tiger

Paper Tigers Won’t Protect You: The Reality of Effective NIS2 Compliance

by Hans Kayaert
March 24, 2025

Why Belgium's early adoption model could prevent another round of ‘compliance theater’ across Europe

examining data on laptop screen

Privacy Rights Surge Forces Rethink of Data Management

by Gal Ringel
March 14, 2025

As global privacy regulations multiply, organizations face mounting pressure to efficiently respond to data subject requests amid complex data environments

Next Post
downward trending risk graph

Panorays Recognized as a Strong Performer in Cybersecurity Risk-Rating Solutions Report

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights