Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
Security Newswire

Companies Still Not Prepared to Comply with GDPR and Potential EU Data Breaches

privacy
October 7, 2019

A GDPR survey reveals that businesses across the globe continue to face challenges understanding and responding to EU data breaches, despite making investments in new personnel and changing business practices.

The McDermott-Ponemon study conducted by Ponemon Institute surveyed companies in the US and EU, and for the first time in China and Japan, as they assessed progress and challenges after one year under the GDPR requirements.

Key findings:

  • Nearly 50% of respondents experienced at least one personal data breach that was required to be reported under GDPR
  • One-quarter of respondents on average in all countries say their readiness and confidence to respond to a GDPR data breach is very low
  • Only 18% of organizations were highly confident in their ability to communicate a reportable data breach to the relevant regulator(s) within 72 hours of awareness
  • Nearly half (49%) of Chinese respondents and more than a third (36%) of Japanese respondents subject to GDPR are still not familiar with this regulation.

"The number of data breaches occurring under GDPR should give pause," said Mark Schreiber, partner and co-leader of McDermott's Global Privacy and Cybersecurity Practice. "Companies would benefit from conducting risk assessments and engaging forensic professionals who can identify vulnerabilities and recommend improved processes and remediation. If done under litigation or attorney privilege, organizations can further safeguard themselves."

"The reporting requirement is one of the most difficult aspects for companies to get right.  Over-reporting and under-reporting to regulators are both disadvantageous, and mandatory reporting to data subjects can increase the likelihood of class action litigation," said Ashley Winton. A partner at McDermott, Ashley is also a Ponemon Institute fellow and Chairman of the UK Data Protection Forum.

Although companies report making significant investments in compliance, there are still risks around their ability to prevent – and then also respond to – data breaches. Almost half of the respondents experienced at least one personal data breach that was required to be reported under the GDPR. Less than that (39% of US companies and 45% of EU companies) reported a personal data breach to a Regulator.

Approximately one third of companies obtained cyber risk insurance; 43% of those respondents said their insurance policy covers GDPR fines or penalties. Ten percent were unsure of what their organization's cyber policy covered.

Looking beyond the US and EU, Chinese and Japanese respondents lag in their GDPR efforts. Only 29% of the Chinese respondents and 32% of Japanese ones stated that they were fully compliant with the GDPR, more than 10% lower than Western companies. Although Japanese respondents rely heavily on external cybersecurity services to investigate data breaches, significantly fewer Chinese respondents did so and only 41% of these are conducted through litigation or under the protection of lawyer-client privilege.

"As revealed in our first study one year ago, The Race to GDPR, GDPR compliance is a challenge, particularly with information and the companies that possess it so frequently crisscrossing national borders and an uptick in varying local regulations – whether that's China's Cybersecurity Law or the new California Privacy Act," said Dr. Larry Ponemon, chairman and founder of the Ponemon Institute.

"What we learned this year is that countries and regions are now very much at different points in their compliance awareness and execution journeys. With enforcement activity just beginning, it is more important than ever for companies to work hand in glove with external cybersecurity services and legal counsel and understand that these issues will continue well into the foreseeable future," he added.

Additional findings include:

  • A surprisingly high percentage of respondents (85%) reported appointing a GDPR Data Protection Officer and 54% of non-EU respondents appointed an EU Representative. Most of these appointments were internal rather than an external individual or company. At play are complex GDPR provisions that mandate this position in some, but not all, situations.
  • More than half of the US company respondents apply GDPR data subject rights to both US and EU employees. Fifty-one percent of US companies surveyed say they give their US and EU employees the same rights under GDPR. Only 43% of EU companies apply GDPR data rights to both US and EU employees.
KEYWORDS: data breach GDPR privacy regularly scheduled shredding

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

Popular Stories

Tree shaped as dollar sign

The Salary of a Chief Security Officer

Classroom with rows of desks facing a chalkboard

The AI Powered Classroom Network of the Future: Because Hackers Never Take Recess

Jaguar logo

New Update on Jaguar Land Rover Cyberattack: Q3 Wholesales Down 43%

Cloud icon

Google Cloud Service Exploited in New Phishing Campaign

Person holding phone to smart lock

Why it’s Time to Move on From Legacy Access Control Systems

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

February 26, 2026

Zero Incidents vs. Zero Tolerance – Workplace Violence Prevention Best Practices that Work

Workplace violence remains one of the most complex challenges facing healthcare organizations today. For executive security professionals, the stakes have never been higher: protecting staff, patients, and visitors while preserving a culture of compassion, dignity, and service.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • You’re Not Ready for GDPR, but Don't Panic

    See More
  • Companies are Failing to Get Ahead of the GDPR

    Companies are Failing to Get Ahead of the GDPR

    See More
  • Gaps in Cybersecurity Programs

    60% of Enterprises Not Equipped to Respond to Data Breaches

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • A Leaders Guide Book Cover_Nicholson_29Sept2023.jpg

    A Leader’s Guide to Evaluating an Executive Protection Program

  • The Complete Guide to Physical Security

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing