Two years after the entry into force of the General Data Protection Regulation (GDPR), data protection laws continue to face challenges throughout the European Union, especially regarding how member states implement the regulation.

A European Commission report broadly characterizes data protection laws as successful in providing citizens with more privacy, giving people a better understanding of their rights when handing over personal data, and encouraging organizations to take more precautions when handling information.
However, the implementation of the GDPR is not the same across Europe, which could potentially create problems.
Just over two years after the GDPR legislation, all EU member states have adopted it or adapted it into their national data protection laws. The only member country that has not implemented it is Slovenia.
However, the implementation of the GDPR across member states is inconsistent and creates inconsistency, which affects cross-border businesses, especially when it comes to new technological developments and cybersecurity products.
Among the reasons it is not universally applied is that Member States are responsible for managing the human, financial and technical resources of their national data.
While this has led to good adoption and understanding of the legislation in countries such as Iceland, the Netherlands, Finland, Ireland and Luxembourg – the latter two hosting some global technology – other countries are lagging behind.
“The situation remains uneven among member states and is not yet satisfactory overall”, the report said.
And while larger organizations have generally adapted to the GDPR, the report notes that even two years later, its understanding and compliance still pose a challenge for small and medium enterprises (SMEs).
Several data protection authorities have provided tools to help SMEs implement the GDPR and this is something the European Commission to “intensify and disseminate”.
However, despite the issues affecting small businesses, the Commission considers the GDPR a success, noting that 69% of people over 16 years old across Europe are aware of the legislation and what exactly it entails.
“GDPR has achieved its goals and has become a reference point worldwide for countries that want to provide their citizens with a high level of protection. However, we can do even better”, said Didier Reynders, European Commissioner for Justice.
