Site navigation

GDPR Five Years on: Tracking the Trends

Elizabeth Greenberg

,

GDPR
CMS, the law firm, has published their GDPR Enforcement Tracker Report which collated fines and trends over the past five years.

GDPR was introduced five years ago in 2018, and since then, fines have stacked up against individuals and big tech companies alike for non-compliance issues.

The five-year anniversary edition of CMS’s Enforcement Tracker Report is based on around 1,672 entries surrounding fines and non-compliance of GDPR across the EU.

Though the UK is no longer under GDPR, the tracker provides an interesting plateau of context for the UK’s neighbouring market’s data protection legislation.

GDPR is once again in the news as Meta received a record £1 billion fine this week for transferring EU data to the US.

While GDPR has been enforced for five years, even large tech companies are continually under fire for breaches and non-compliance.

In many court cases, much of GDPR’s language can be left up to too much interpretation – the European Court of Justice is soon to decide a case on how strict liability will work for companies over data protection violations.

The Past Five Years 

Since 2018, the new enforcement authorities quickly made use of their power – the first GDPR fine was issued just two months after GDPR was put in place.

2019 and 2020 saw continuous growth, and then the previously highest fine was imposed in 2021, from the DPA in Luxembourg for £649 million.

By 2022, there was 1,000 publicly known GDPR cases, and the total amount of two billion euros in fines was exceeded in the autumn due to several fines against major tech corporations by the Irish DPC.


Recommended


But while this proves the fines are no vacant threats, to small and big tech alike, the past five years has revealed troubling differences between national regulators.

Each member state has their own national data protection board which is then supervised by the higher EU-wide authority, the European Data Protection Board (EUDPB) but these vary in their enforcement. The Irish DPC, for instance, has come under continuous fire for being too ‘soft’ on large tech companies based in their country.

Since the start of GDPR, the most common fine triggers, as found by the CMS tracker, have been either an insufficient legal basis for data processing or non-compliance with general data processing principles. Insufficient technical and organisational measures are leading causes of fines.

Further, violating the rights of data subjects can lead to fines, as well as further personal lawsuits. These rank fourth and fifth in the most common types of violations resulting in fines.

While fines are a continuous trend, emerging technologies have changed certain consequences. A recent AI charge in Italy imposed a limitation on processing data which could interrupt a company’s operations, perhaps more significantly impacting these organisations than a fine.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data