How Is the EU’s Data Privacy Regulation Doing So Far?

The EU’s General Data Protection Regulation went into effect on May 25, 2018, but online privacy experts are already scrutinizing the policy’s effects. Last week in London, the International Association of Privacy Professionals hosted a retrospective panel on the GDPR’s first year, which French regulator Mathias Moulin emphasized “should be considered a transition year.”
Transition year or not, early numbers for the GDPR make clear that the policy has been a success as a breach notification law, but largely a failure when it comes to imposing fines on companies that fail to adequately protect their customers’ data. At the panel discussion, Stephen Eckersley, the head of enforcement at the U.K. Information Commissioner’s Office, said the U.K. had seen a “massive increase” in reports of data breaches since the GDPR’s implementation. In June 2018, companies self-reported 1,700 data breaches, and Eckersley estimated that the total will be around 36,000 breaches reported in 2019, a significant increase from the previous annual reporting rate of between 18,000 and 20,000 breaches. Across Europe, nearly 60,000 breaches were reported during just the first eight months of the GDPR, according to a survey released last month by law firm DLA Piper.
Doubling the number of annually reported breaches is not an insignificant feat. That’s valuable information for consumers whose information may have been stolen, for regulators and technology designers trying to understand and mitigate the root causes underlying breaches, and for researchers working on examining the impacts and costs of these breaches. Europe’s success at ramping up breach notification is instructive for the United States and other countries that have struggled to implement a unified breach-notification policy framework.
Prior to the GDPR, there was no single breach-notification regulation for the European Union. Instead, the EU’s 1995 Data Protection Directive (which the GDPR replaced) allowed individual member nations to write and pass their own breach-notification laws. Some countries, such as Austria, Germany, and Norway, mandated breach notification. But their approaches differed: In Austria, for instance, companies were required to notify individuals whose data had been accessed, while in Norway only the data protection authority had to be notified; but in Germany, notification of both affected individuals and the state authority was required. There were differences, too, in what kind of data was considered “personal” and what types of information about the breach had to be reported. Other countries, including Ireland, Italy, and the U.K., put in place voluntary reporting schemes.
The GDPR swept away all these different statutes. It requires organizations to report data breaches to both the affected individuals and the appropriate regulatory authorities within 72 hours of being discovered. It also established a common, broader definition of personal data. The DPD defined personal data as names, photos, email addresses, phone numbers, addresses, and personal identification numbers, while the GDPR widened that category to include IP addresses, biometric data, mobile device identifiers, and other types of data that could potentially be used to identify an individual.


