Warnings over GDPR compliance and penalty regime

Image

The General Data Protection Regulation (GDPR) comes into effect from today, 25 May, introducing the biggest changes to the processing of personal data for 20 years, with warnings that low levels of compliance in some areas could see some companies paying large fines

FTI Consulting’s poll of over 500 managers in large UK companies found 42% claim their organisation will not be fully GDPR compliant by the deadline, while 37% expect to achieve this within the next six months.

Two thirds (67%) consider their company to be vulnerable to a GDPR-related crisis event, and nearly half (45%) declare themselves worried that their organisation is unprepared to deal with such a crisis.

In contrast, software supplier IRIS Accountancy Solutions’s poll of its users found 99% of respondents were aware of their responsibilities compared to 80% previously.

Its research showed nearly three quarters (69%) of accountancy practices feel their employees can apply the principles of personal data protection, up from two fifths (40%) in September 2017. Two thirds (66%) can demonstrate they have the necessary basis to hold client data, an increase from 42%.

Stewart Room, lead partner for GDPR and data protection at PwC, said: ‘Findings from our GDPR readiness assessments, which we’ve run with over 220 clients globally over the last two years, show that, in general, highly regulated sectors such as healthcare and financial services, which are used to dealing with regulatory change, tend to have a slight margin over others in terms of preparedness.’

In the event of the worst happening, 79% of large UK companies in the FTI survey believe this would damage their company’s reputation,  and a similar proportion anticipate a financial loss. FTI Consulting says the companies surveyed had a mean annual turnover of £15bn and would expect their turnover to lose on average 5% as a direct consequence of GDPR, making this a mean loss of £750m per company. 

Fines

The introduction of GDPR is accompanied by greater powers for the UK Information Commissioner’s Office (ICO). GDPR regulations require the reporting of any breach of the rules within 72 hours and there are substantial fines, up to 4% of turnover, for failure to meet the requirements.

Up until now, the ICO’s limit for monetary penalties has been £500,000. PwC says its analysis of ICO data protection enforcement actions over the past four years found that in 2017, 14 of the 54 fines issued (26%) were of more than £100,000.

Of the 91 enforcement actions for breaches of the previous data protection laws taken by the ICO last year, 54 monetary penalties were issued to UK organisations, totalling £4,207,500 - an increase of nearly £1m over the previous year (35 fines with a total of £3,245,500).

PwC says almost half of last year’s UK data protection enforcement actions were due to marketing infringements, but security breaches and misusing data for profiling purposes also continued to appear as substantial causes of failure and if these persist nto the GDPR regime, would result in penalties.

Sion Lewis, CEO of IRIS Accountancy, said: ‘GDPR compliance is a journey not a destination. Although GDPR is effective from today, it should not be viewed as a one-off activity. Protecting personal data is central to every client relationship and needs to be frequently monitored. By continuing training and process checks, practices not only ensure they are compliant but also build client loyalty and trust.’

Report by Pat Sweet

Pat Sweet | Reporter, Accountancy Daily [2010-2021]

Pat Sweet was the former online reporter at Accountancy Daily and contributor to the monthly Accountancy magazine, pub...

View profile and articles

4
Average: 4 (1 vote)

Rate this article

Related Articles
Subscribe