---
title: GDPR - 2 Years On
description: GDPR has changed the way data security and data privacy is viewed on a global scale. Cut through the confusion of GDPR with data-centric security
image: https://insights.comforte.com/hubfs/gdpr-3518254_1920_v1.4.jpg
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![GDPR](https://insights.comforte.com/hubfs/gdpr-3518254_1920_v1.4.jpg)](https://insights.comforte.com/gdpr-2-years-on)

[Thomas Stoesser](https://insights.comforte.com/author/thomas-stoesser) l May 26, 2020 l [GDPR](https://insights.comforte.com/tag/gdpr), [Compliance](https://insights.comforte.com/tag/compliance)

# GDPR - 2 Years On

GDPR. Four letters that have supposedly changed the way data security and privacy is viewed on a global scale. Now, two years on since the [European General Data Protection Regulation (GDPR)](https://gdpr-info.eu/)was introduced on the 25 May 2018, can we honestly say there has been an improvement in the way data privacy and security is handled?

GDPR is classified as being a European law that protects the data rights of European citizens but extends to any organisation that collects, stores or uses EU citizen data. Failure to appropriately meet the necessary compliance guidelines will result in fines that could range in the millions being issued by the independent regulatory bodies that enforce GDPR. Every nation has one: in the UK you have the ICO, in Germany you have the BfDI, in France there’s the CNIL, and Italy has the DPA Garante.

Truth be told, it is unacceptable today if an organisation is found to be non-compliant. From the time organisations were first pre-warned about GDPR back in 2016, it has now been four years. That’s four years to assure compliance, ensure systems that store, use and collect data are secure, and have the necessary processes and policies in place to meet the GDPR standard. Yet, the constant barrage of data breaches being reported act as a perfect reminder that there is much work to be done to drill home the message.

## GDPR Got Teeth

Since its inception, there has been an increase in the number of [data breaches](https://insights.comforte.com/almost-60-of-uk-consumers-affected-by-data-breaches-in-2019?hsLang=en), but this is likely due to the fact that organisations are now reporting more to the authorities – it helps that there is a 72-hour deadline for this to happen.

Yet, in the UK, it took over a year for the ICO to charge its first GDPR violator. A local [London pharmacy was fined £275,000 (](https://bateswells.co.uk/2020/01/first-gdpr-fine-from-the-ico/)[€](https://www.techradar.com/uk/news/1and1-hit-with-million-euro-gdpr-fine)[307,762)](https://bateswells.co.uk/2020/01/first-gdpr-fine-from-the-ico/) in December 2019. The first fine to range in the millions was issued by Germany’s BfDI to one of the country’s largest internet and mobile providers, 1&1 Ionos. [The penalty here was €9,550,000](https://www.techradar.com/uk/news/1and1-hit-with-million-euro-gdpr-fine) after the company lacked sufficient protection for personal data and violated Article 32 of GDPR.

But the unwanted title of having the largest fine imposed under GDPR in Europe to date goes to Google, with French regulators CNIL enforcing [a fine of €50m](https://www.theverge.com/2019/1/21/18191591/google-gdpr-fine-50-million-euros-data-consent-cnil) on the tech giant after it was found to have provided inadequate information to its users about data consent policies and restricting control on how data was used.

These are all substantial fines in their own rights and should be heeded as a warning by other businesses that are taking a nonchalance stance to GDPR compliance. Furthermore, there are a variety of ways companies have been [found to be non-compliant](https://insights.comforte.com/4-gdpr-violations-that-multiple-companies-have-been-fined-for?hsLang=en). For organisations outside of the EU’s remit that are struggling to fulfil data security obligations, GDPR can also be used as a helpful guideline.

Aside from the obvious [benefit of data security and privacy](https://insights.comforte.com/4-reasons-why-the-gdpr-is-an-opportunity-and-not-a-threat?hsLang=en), GDPR has also allowed organisations to be more open and bridge communication with users as to how data is being leveraged to create a better customer experience. This is where trust between a brand and a customer can blossom. However, if a company suffers a breach and is found to have failed in meeting GDPR compliance, damage both financially and reputationally, can be almost irreparable. 

Even though we are only two years into life with GDPR, the regulation has certainly highlighted the importance of the privacy and security of data today, and in this position, it can never be cast aside. 

---

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/gdpr-2-years-on&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/gdpr-2-years-on&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/gdpr-2-years-on&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/gdpr-2-years-on&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/gdpr-2-years-on&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## The Choice is Yours: Adopt Data-centric Security or Risk GDPR and PCI Non-Compliance

Are you considering data-centric security for protecting personal data but need help convincing others at your organisation?   
Click the button below to get a white paper from the cybersecurity experts at CyberEdge that explains in depth   
how data-centric security reduces [compliance](https://www.comforte.com/enterprise-data-protection/compliance/) scope and minimizes the risks of a data breach.

[![Download White Paper](https://no-cache.hubspot.com/cta/default/4026697/42e934f9-22e2-46a9-8cce-b57f766662d1.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/42e934f9-22e2-46a9-8cce-b57f766662d1)

### Related posts

![OpenAI’s GDPR Travails Demonstrate Need for Data Security-by-Design](https://insights.comforte.com/hubfs/comforte%20AG_blog%20post_AI.png)

 Apr 6, 2023 l [GDPR](https://insights.comforte.com/tag/gdpr) , [Data Protection](https://insights.comforte.com/tag/data-protection) , [Compliance](https://insights.comforte.com/tag/compliance) , [Big Data Analytics](https://insights.comforte.com/tag/big-data-analytics) , [AI](https://insights.comforte.com/tag/ai)

### [OpenAI’s GDPR Travails Demonstrate Need for Data Security-by-Design](https://insights.comforte.com/openais-gdpr-travails-demonstrate-need-for-data-security-by-design?hsLang=en)

After several weeks of incredible growth, OpenAI has come in for a bumpy ride of late. First it revealed details of a data breach exposing a significant number of ChatGPT subscribers. Then the Italian data protection regulator (GPDP) became the...

[Read more](https://insights.comforte.com/openais-gdpr-travails-demonstrate-need-for-data-security-by-design?hsLang=en)

![How to Stay Agile and Compliant with Format-preserving Protection for Analytics](https://insights.comforte.com/hubfs/Analytics%20on%20Red%20Button%20Enter%20on%20Black%20Computer%20Keyboard..jpeg)

 Aug 4, 2022 l [GDPR](https://insights.comforte.com/tag/gdpr) , [PCI DSS](https://insights.comforte.com/tag/pci-dss) , [Compliance](https://insights.comforte.com/tag/compliance) , [Big Data Analytics](https://insights.comforte.com/tag/big-data-analytics) , [CCPA](https://insights.comforte.com/tag/ccpa)

### [How to Stay Agile and Compliant with Format-preserving Protection for Analytics](https://insights.comforte.com/how-to-stay-agile-and-compliant-with-format-preserving-protection-for-analytics?hsLang=en)

Cloud-based analytics offer a truly transformative opportunity for global organizations. By extracting insights from data, they are already helping companies better serve their customers, improve operational efficiencies and make better business...

[Read more](https://insights.comforte.com/how-to-stay-agile-and-compliant-with-format-preserving-protection-for-analytics?hsLang=en)

![17 Countries with GDPR-like Data Privacy Laws](https://insights.comforte.com/hubfs/Int_Datenschutz_Strategie_1.png)

 Jan 13, 2022 l [GDPR](https://insights.comforte.com/tag/gdpr) , [Data Protection](https://insights.comforte.com/tag/data-protection) , [Compliance](https://insights.comforte.com/tag/compliance) , [CCPA](https://insights.comforte.com/tag/ccpa)

### [17 Countries with GDPR-like Data Privacy Laws](https://insights.comforte.com/countries-with-gdpr-like-data-privacy-laws?hsLang=en)

GDPR wasn't the beginning and it certainly won't be the end. Strict data privacy legislation with extraterritorial applicability is appearing in more and more economies across the globe, meaning the list of “GDPR-free” havens is growing shorter by...

[Read more](https://insights.comforte.com/countries-with-gdpr-like-data-privacy-laws?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>