The statistic comes from Macro 4, the software development company. They tasked research firm Vanson Bourne with surveying 100 UK IT leaders and decision-makers working in large enterprises about GDPR.
When IT leaders were asked if they were completely satisfied that the way they store, process, and use personal information is fully compliant with the GDPR, 18% of IT said they either didn’t agree or didn’t know.
On this, Jim Allum, Director of Macro 4’s Commercial and Technical department, said: “With five years to get their processes in place, you would expect that most technology leaders would feel confident that they are now fully compliant. But it’s obvious from the data that many are still struggling.”
The survey also revealed that 85% of respondents feel it’d be easier if the UK stayed with the data privacy requirements enshrined in the GDPR, rather than creating a separate set of post-Brexit regulations under the proposed Data Protection and Digital Information Bill (DPDIB).
“On the face of it, you would expect that business would welcome the DPDIB. It promises to simplify compliance, cut unnecessary red tape and promote innovation,” Allum commented.
“However, change brings uncertainty and this may explain why the IT leaders we questioned seem to want the status quo to prevail. There’s still a lot of complexity and also unanswered questions about what will happen in practical terms if the new bill comes into force.”
“Businesses that operate in both the UK and EU may fear that they’ll end up having to comply with two separate sets of compliance standards. They could be thinking, ‘It’s better the devil you know’.”
In addition to the already mentioned stats, 66% of IT leaders feel that the GDPR has made customers more aware of the need to protect their personal information — making them less willing to trust businesses with it.
“Most IT leaders seem to feel that the regulations have made people more suspicious about how their data is being used,” Allum said.
“This is possibly because people are better informed now about how their data could be compromised or misused. Media headlines about major data privacy breaches and huge GDPR non-compliance fines levelled at well-known brands will have reinforced the overall lack of trust. All this means that organisations need to work harder than ever to demonstrate that they’re managing data within the rules.”
Recommended
- Comment: Is Quiet Hiring the Solution to the Tech Skills Shortage?
- Crypto Watchdog Unveils Regulation Recommendations
- Smart Data Foundry Launch Open Banking Partnership and Tools
Earlier this week, DIGIT reported on law firm CMS’ GDPR Enforcement Tracker Report, which collated GDPR-related fines and trends over the past five years.
It found that insufficient technical and organisational measures are the leading causes of fines — not least non-compliance with general data processing principles.
By March 2023, over 1,500 GDPR-related fines were recorded in CMS’ Enforcement Tracker database, amounting to a sum of around €2.77.bn (£2.4bn~).





