Capgemini conducted a survey and found that only one in three companies has fully complied with the GDPR, despite the fact that privacy regulations have been mandatory across Europefor about a year and a half.
The company surveyed over 1,000 employees who work on compliance, privacy and data protection. Three-quarters of employees said they were fairly confident their company was compliant with the GDPR rules, which came into effect in May 2018. However, the researchers found that this is not true.
Now, only 28% of respondents believe they are fully compliant with the GDPR.
In the meantime, regulators are quite strict and willing to impose heavy fines on companies that do not comply.
UK regulators have fined British Airways £183 million after the airline failed to implement effective security practices, leading to the personal data of half a million customers being leaked in 2018.

Why don't all companies comply with GDPR?
Businesses often face some obstacles. The most basic of these is the use of old systems IT. 38% of participants stated that their companies' systems and IT infrastructure in general cannot keep up with the requirements and complexity of the GDPR.
36% of companies believe that GDPR requirements are too complex and require a lot of effort to implement. Finally, a large percentage claimed that there is a high financial cost to fully comply with the regulations and that they cannot manage it.
However, these companies are more likely to fall victim to a hacking attack. This could cause damage to their systems, leak customer data, and damage the company's reputation. In addition, there is the risk of being fined.
On the other hand, 92% of organizations operating in accordance with GDPR stated that they have a competitive advantage, as customer trust and satisfaction have been strengthened, resulting in good brand reputation and increased revenue.
Furthermore, a large percentage of these organizations stated that they have seen improvements in IT systems and security practices.
“Organizations must promote a culture of data protection and privacy and integrate advanced technologies to enhance security ,” the report said.
“Businesses that take these actions early and ensure data protection will secure a significant competitive advantage.”
Compliance with regulations is something that must be continuously examined. The fact that an organization operates correctly at a specific point in time does not mean it will do so continuously.
“The introduction of GDPR was the start of an ongoing process and much more needs to be done. We will not hesitate to defend the public interest when organisations intentionally or unintentionally break the law,” the regulators said.
