Companies still unprepared for GDPR rule changes and potential EU data breaches

A new survey finds many companies are still in the dark about GDPR compliance.
Enterprises across the world are still struggling to comply with the new rules enshrined in the GDPR that came into effect more than a year ago. The regulation had global implications, forcing companies in the US, China and Japan to comply with new, sometimes arcane, rules previously unseen on this scale.
A new study commissioned by international law firm McDermott Will & Emery and conducted by the Ponemon Institute found that almost 50% of respondents experienced at least one personal data breach that was required to be reported under GDPR in the last year.
Companies in both China and Japan had a very high number of respondents who said they were still “not familiar” with large parts of the regulation.
The study said Japanese respondents were increasingly using external cybersecurity companies to deal with any data breaches. Just 29% of Chinese respondents and 32% of Japanese ones reported being fully compliant with the GDPR, according to the survey.
“What we learned this year is that countries and regions are now very much at different points in their compliance awareness and execution journeys,” Ponemon said.
“With enforcement activity just beginning, it is more important than ever for companies to work hand in glove with external cybersecurity services and legal counsel and understand that these issues will continue well into the foreseeable future,” he said.
For many organizations, the biggest issue was the process around reporting data breaches.


