A survey of UK GDPR decision-makers conducted on behalf of Egress, the leading provider of people-centric data security solutions, has revealed that 52% of businesses are not fully compliant with the regulation, more than a year after its implementation.

The survey found that 37% of respondents had reported an incident to the ICO in the past 12 months, with 17% having done so more than once. The results showed that over half (53%) of mid-size companies had reported data breaches to the ICO in the past 12 months, compared with 36% of small companies and only 23% of enterprise organisations. A notably lower percentage (39.5%) of mid-sized companies reported full GDPR compliance compared with 56% of large and 51% of small companies. There is obviously a gap in compliance performance among mid-size companies.

The survey also found that only half of decision-makers (48%) reported that their business was fully compliant; 42% rated their organisation as ‘mostly compliant’ and over one-third (35%) said GDPR has become less of a priority for their organisation in the last 12 months

Putting in place new processes around the handling of sensitive data has been the greatest area for compliance investment in the last 12 months (28%) and 7% said user education and training had been their biggest area of investment.

35% of GDPR decision-makers said that the majority of compliance activity had taken place in the lead up to the May 2018 deadline but had since dropped down the priority list. Only 6% said that the ICO’s recent high-profile announcements of its intention to fine British Airways and Marriott had subsequently shocked the business back towards greater awareness. While 70% of decision-makers surveyed said that their organisation felt very positively about GDPR, less than two thirds (62%) said their business had made GDPR a top priority over the past year.

Tony Pepper, CEO of Egress: “Since the rush to meet last May’s deadline, we now appear to be seeing an ‘almost compliant is close enough’ attitude towards GDPR, with a significant percentage of decision-makers indicating that focus has waned in the past 12 months. The wait of more than year between implementation and the first action taken by the ICO under GDPR seemed to lead to a perception outside the security industry that the regulation was ‘all bark and no bite’. Although the authority’s announcement that it intends to fine British Airways and Marriott such staggering sums sent shockwaves through the security community, it is concerning only 6% of organisations have taken action to avoid the full potential of the legislation. These announcements should definitely have acted as a clearer warning that organisations cannot risk compliance complacency.

“This is important for businesses in the small and mid-market segments, where our survey found lower compliance levels being reported. Although the ICO’s action to date has focused on two well-known enterprise organisations, GDPR demands compliance from businesses of all sizes and they need to take all necessary steps towards protecting data.”

When asked about their single greatest area of compliance investments, decision-makers chose:

  • Implementing new processes around the handling of sensitive data (28%)
  • Better auditing around what data we collect and for what reasons (18%)
  • Employment of a Data Protection Officer or other additional compliance staff (18%)
  • New technology (17%)
  • Implementing new procedures around incident reporting (8%)
  • End-user education and training (7%)

However, over one-third of respondents (37%) have reported at least one incident to the ICO in the last 12 months. According to analysis of ICO data, 60% of security-related personal data breach incidents in the first six months of 2019 were caused by human error.

Pepper adds: “The majority of respondents (96%) acknowledged their organisation has made investments in GDPR compliance in the last 12 months, with implementing new processes the most common top priority. Yet despite this, we continue to see data breach incidents being reported and we know from the ICO that the primary cause is human error – so clearly strategies need to shift if we are going to turn the tide against data breaches. Reliance on people to follow processes and protect data is only going to get organisations so far: people are always going to make mistakes or behave unexpectedly, and more must be done to provide a safety net that protects sensitive information.

“It’s positive to see that almost one-fifth (17%) of respondents are looking to technology as a way to mitigate breaches, but they must ensure these solutions tackle human error as the root causes of many of these incidents. They must look to the latest advances in security and DLP technology that can map a user’s behaviour to prevent the array of mistakes that put data at risk – from falling for phishing attacks that can lead to malware or stolen credentials, to misdirecting emails or attaching the wrong documents. GDPR is here to stay, and we’re only going to see more companies penalised for data breaches unless we’re able to overcome these issues.”

Our view

Essentially, the regulator has to step up more – this affects everyone and more education is needed and ultimately, business owners need to take ownership as compliance is about brand protection as much as anything else. Part of the legislation provides the facility for professional advice so businesses have no excuse to follow the path to compliance.

Membership bodies like Gassafe are needed so that they can show confirmation to the consumer but until the government resource GDPR compliance correctly, we believe businesses will still shirk responsibility. There is the perception that the ICO are all bark and no bite except when it comes to the headline grabbing major stories like Marriott and Facebook but when cases start to appear with smaller businesses it will be time to sit up and listen.

For example, a change in the law earlier this year made cold calls about pensions illegal in certain circumstances.

David Clancy, ICO Enforcement Group Manager, said: “The law now offers greater protection for people troubled by cold calls about their hard-earned pensions. This includes a ban on certain types of calls being made in relation to pensions.

“Today’s search and our investigation should serve as a warning to business owners that they must follow the law.”

At DLM, we have devised start-to-finish procedures so we will lobby the regulator re the above. Our immediate advice is that you undertake a health check and allow DLM to show you the gaps in your road to compliance.