Symantec Corp. today revealed that 96% of businesses still do not fully understand the new European General Data Protection Regulation (GDPR), which will come into effect in May 2018, according to a survey it conducted.
The results of Symantec's European Data Privacy Survey , conducted through interviews with 900 businesses and IT managers in the UK, France and Germany, show that 91% of respondents have serious concerns about their ability to comply.
The survey also revealed that just 22% of businesses consider compliance to be a top priority for the next two years, while only 26% of respondents believe their business is fully prepared for the new European General Data Protection Regulation (GDPR).
“These findings show that businesses are not only unprepared for GDPR, they are not even getting started on the process,” said Kevin Isaac, vice president, Symantec. “There is a significant disconnect between how important privacy and security is to consumers and how important it is to businesses. The good news is that there is still time to fix this – if companies act now.”.
Lack of regulatory information
Of those surveyed, almost a quarter (23%) said their business would not be fully or only partially compliant by 2018. Of this percentage, only 20% believe it is likely that they will become fully compliant with the GDPR, while almost half of them (49%) believe that only some parts of the company will be able to comply, while others will not.
This lack of confidence in meeting the May 2018 start date puts businesses at risk of paying high fines upon the expiration of this date.
Lack of understanding of customer requirements
While businesses struggle to comply, they remain out of touch with consumer expectations for data protection and security. Nearly 74% of businesses do not consider data protection as one of the top three priorities of the consumers they do business with, despite the fact that 36% of businesses say customers often ask about the security of their data in their transactions.
Equally worrying is the result of the survey, where 35% of respondents do not believe that their business takes an ethical approach to securing and protecting their customers' data.
These results show that there is a significant gap in consumer priorities compared to those of businesses. Symantec research showed that 88% of European consumers see the security of their data as the most important factor in the process of choosing a company to do business with. In fact, 86% consider it to be a more important factor than product quality.
It is therefore not surprising that the survey results, which find that 55% of businesses are not convinced that they fully understand the expectations regarding the security of customers' personal data, are not surprising.
Lack of preparation
Symantec's study concluded that many businesses have not even started working on the organizational changes, aimed at compliance, that must be implemented by May 2018, when the new European General Data Protection Regulation (GDPR) will be activated.
- About one in ten (9%) claim that all employees have access to customers' personal information.
- 6% claim that all their staff can access details regarding customer payment data.
- Only 14% believe that everyone in an organization has a responsibility to guarantee that data is protected.
With so many people having access to personal information, companies have not understood the challenges they will face in managing their GDPR compliance.
- Less than half of respondents (47%) said that ethical data management is the most important priority for their company, and less than half also said they could increase security training.
- Only 27% of businesses plan to completely restructure their approach to GDPR requirements.
Technical readiness and the right to "be ignored"
- 91% of respondents have concerns about their business' ability to comply with GDPR, due to factors such as the complexity of properly processing data, in terms of time and cost.
- Only 28% of CIOs, or other departments, understand that the right to ignore is part of the new GDPR.
- 90% of businesses claim that customer demands to delete their personal data pose a challenge to their business.
- Only 9% of respondents have already received requests for disregard.
- 81% of respondents believe that their customers will exercise their right to have their personal data deleted.
- However, 60% of businesses do not have the appropriate system in place to be able to meet these requirements.
“Organizations must recognize that privacy, security and GDPR compliance are critical differentiators,” said Kevin Isaac, vice president, Symantec. “Organizations’ GDPR response should become a core part of their organizational design and culture. Taking a piecemeal approach will create more problems than it solves.”.
Peter Gooch , cyber risk partner, Deloitte , comments:
“Companies will need to lead with their will, successfully implementing the key pillars of the GDPR and embrace privacy by design. They must also understand that proper security and privacy of processes can provide significant competitive advantages that will lead to gaining consumer trust, while also being driven by regulatory requirements.”.
Prof. Dr. Udo Helmbrecht, Executive Director, European Union Agency for Network and Information Security (ENISA) comments:
“Given the fundamental importance of the General Data Protection Regulation in shaping tomorrow’s EU digital environment, the European Union Agency for Network and Information Security (ENISA) welcomes initiatives such as this one, which increase our understanding of the challenges of implementing the regulation in order to achieve the objectives we have set.”.
The European Regulation on the protection of individuals with regard to the processing of personal data and on the free movement of such data is due to enter into force in Spring 2018. The collection and exchange of personal data has increased significantly in recent years as technology allows both private companies and public authorities to use personal data on an unprecedented scale to pursue their activities. These developments led the European Union to establish a strong data protection framework with this regulation.
Labeling:
1 Symantec's 2015 State of Privacy Report:
https://www.symantec.com/content/en/us/about/presskits/b-state-of-privacy-report-2015.pdf
