29 datasets found
  1. Challenges to adapt privacy compliance changes for companies in the EU and...

    • statista.com
    Updated Jul 15, 2023
    Share
    FacebookFacebook
    TwitterTwitter
    Email
    Click to copy link
    Link copied
    Close
    Cite
    Statista (2023). Challenges to adapt privacy compliance changes for companies in the EU and UK 2023 [Dataset]. https://www.statista.com/statistics/1403394/eu-uk-firms-challenge-consumer-data-privacy-law/
    Explore at:
    Dataset updated
    Jul 15, 2023
    Dataset authored and provided by
    Statistahttp://statista.com/
    Time period covered
    Apr 2023 - May 2023
    Area covered
    European Union, United Kingdom
    Description

    A survey conducted in April and May 2023 revealed that around ** percent of the companies that do business in the European Union (EU) and the United Kingdom (UK) found it challenging to adapt to new or changing requirements of the General Data Protection Regulation (GDPR) or Data Protection Act 2018 (DPA). A further ** percent of the survey respondents said it was challenging to increase the budget because of the changes in the data privacy laws.

  2. Cyber Security Breaches Survey 2018: Preparations for the new Data...

    • gov.uk
    Updated Jan 24, 2018
    Share
    FacebookFacebook
    TwitterTwitter
    Email
    Click to copy link
    Link copied
    Close
    Cite
    Department for Digital, Culture, Media & Sport (2018). Cyber Security Breaches Survey 2018: Preparations for the new Data Protection Act [Dataset]. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2018-preparations-for-the-new-data-protection-act
    Explore at:
    Dataset updated
    Jan 24, 2018
    Dataset provided by
    GOV.UKhttp://gov.uk/
    Authors
    Department for Digital, Culture, Media & Sport
    Description

    The Government has surveyed UK businesses and charities to find out how they approach cyber security and help them learn more about the cyber security issues faced by industry. The research informs Government policy on cyber security and how Government works with industry to make Britain one of the most secure places to do business online.

    This specific release is being in published in advance of the full report of the 2018 Cyber Security Breaches Survey, to provide insight into how aware and prepared businesses and charities are for the General Data Protection Regulation (or GDPR), the foundation of the new Data Protection Act which is due to be introduced in May 2018.

    Released

    24 January 2018

    Period covered

    The findings are taken from survey telephone interviews, which took place between October and December 2017.

    Geographic coverage

    UK

    Further Information

    The survey is part of the Government’s National Cyber Security Programme.

    Cyber security guidance and information for businesses, including details of free training and support, can be found on the National Cyber Security Centre website and GOV.UK at: http://www.ncsc.gov.uk/guidance">www.ncsc.gov.uk/guidance and www.gov.uk.

    The survey was carried out by Ipsos MORI and its partner, the Institute of Criminal Justice Studies (ICJS) at the University of Portsmouth.

    The UK Statistics Authority

    This release is published in accordance with the Code of Practice for Official Statistics (2009), as produced by the UK Statistics Authority. The UKSA has the overall objective of promoting and safeguarding the production and publication of official statistics that serve the public good. It monitors and reports on all official statistics, and promotes good practice in this area.

    Pre-release access

    The document above contains a list of ministers and officials who have received privileged early access to this release. In line with best practice, the list has been kept to a minimum and those given access for briefing purposes had a maximum of 24 hours.

    Contact

    The responsible statistician for this release is Rishi Vaidya. For any queries please contact 020 7211 2320 or evidence@culture.gov.uk.

  3. f

    Data_Sheet_1_Implementation of data protection laws in the European Union...

    • frontiersin.figshare.com
    docx
    Updated Jun 21, 2023
    Share
    FacebookFacebook
    TwitterTwitter
    Email
    Click to copy link
    Link copied
    Close
    Cite
    Elad Yom-Tov; Yishai Ofran (2023). Data_Sheet_1_Implementation of data protection laws in the European Union and in California is associated with a move of clinical trials to countries with fewer data protections.docx [Dataset]. http://doi.org/10.3389/fmed.2022.1051025.s001
    Explore at:
    docxAvailable download formats
    Dataset updated
    Jun 21, 2023
    Dataset provided by
    Frontiers
    Authors
    Elad Yom-Tov; Yishai Ofran
    License

    Attribution 4.0 (CC BY 4.0)https://creativecommons.org/licenses/by/4.0/
    License information was derived automatically

    Area covered
    European Union
    Description

    The European Union implemented data privacy laws in mid-2018 and the state of California enacted a similar law several weeks later. These regulations affect medical data collection and analysis. It is unclear if they achieve this goal in the realm of clinical trials. Here we investigate the effect of these laws on clinical trials through analysis of clinical trials recorded on the US's ClinicalTrials.gov, the World Health Organization's International Clinical Trials Registry Platform and scientific papers describing clinical trials. Our findings show that the number of phase 1 and 2 trials in countries not adhering to these data privacy laws rose significantly after implementation of these laws. The largest rise occurred in countries which are less free, as indicated by the negative correlation (−0.48, p = 0.008) between the civil liberties freedom score of countries and the increase in the number of trials. This trend was not observed in countries adhering to data privacy laws nor in the paper publication record. The rise was larger (and statistically significant) among industry funded trials and interventional trials. Thus, the implementation of data privacy laws is associated a change in the location of clinical trials, which are currently executed more often in countries where people have fewer protections for their data.

  4. EU online privacy laws 2025

    • statista.com
    Updated Feb 4, 2025
    Share
    FacebookFacebook
    TwitterTwitter
    Email
    Click to copy link
    Link copied
    Close
    Cite
    Statista (2025). EU online privacy laws 2025 [Dataset]. https://www.statista.com/statistics/1446279/privacy-law-eu/
    Explore at:
    Dataset updated
    Feb 4, 2025
    Dataset authored and provided by
    Statistahttp://statista.com/
    Time period covered
    Jan 2025
    Area covered
    European Union
    Description

    As of January 2025, The European Union (EU) had three fully operating and one upcoming law regarding online privacy and the usage of digital technologies. The first one, the General Data Protection Regulation (GDPR), was enacted in May 2018. The second law became effective on February 17, 2024, and is called the Digital Services Act (DSA). In March 2024, another law protecting consumer privacy, the Digital Markets Act, was enacted. The latest regulation adopted by the European Union (EU) is called the Cyber Resilience Act (CRA), which became active in December 2024.

  5. Medicines and Healthcare products Regulatory Agency Privacy Notice

    • gov.uk
    Updated Feb 11, 2022
    Share
    FacebookFacebook
    TwitterTwitter
    Email
    Click to copy link
    Link copied
    Close
    Cite
    Medicines and Healthcare products Regulatory Agency (2022). Medicines and Healthcare products Regulatory Agency Privacy Notice [Dataset]. https://www.gov.uk/government/publications/mhra-privacy-notice
    Explore at:
    Dataset updated
    Feb 11, 2022
    Dataset provided by
    GOV.UKhttp://gov.uk/
    Authors
    Medicines and Healthcare products Regulatory Agency
    Description

    At the Medicines and Healthcare products Regulatory Agency (the Agency) we are committed to protecting and respecting your privacy.

    This privacy notice describes how we collect and use your personal information, in accordance with the Data Protection Act 2018 and the UK General Data Protection Regulation (GDPR) 2016/279.

    This Privacy Notice applies to anyone (except staff) whose personal data we might process, for example, members of the public, manufacturers, wholesalers, and other authorities.

    If you work for the Agency, please refer to our intranet for details of how we process your personal data – ex-members of staff should contact: dataprotection@mhra.gov.uk.

    Contact our Data Protection Officer

    If you have queries about how the Agency protects and uses your personal data, please contact dataprotection@mhra.gov.uk in the first instance. You may also contact the DHSC Data Protection Officer at data_protection@dhsc.gov.uk.

    Alternatively, you can contact us in writing:

    Data Protection Officer
    MHRA
    10 South Colonnade
    London
    E14 4PU

    Or

    Data Protection Officer
    DHSC
    1st Floor North
    39 Victoria Street
    London
    SW1H 0EU

  6. Data Protection Impact Assessments - Dataset - data.gov.uk

    • ckan.publishing.service.gov.uk
    Updated Nov 28, 2023
    Share
    FacebookFacebook
    TwitterTwitter
    Email
    Click to copy link
    Link copied
    Close
    Cite
    ckan.publishing.service.gov.uk (2023). Data Protection Impact Assessments - Dataset - data.gov.uk [Dataset]. https://ckan.publishing.service.gov.uk/dataset/data-protection-impact-assessments1
    Explore at:
    Dataset updated
    Nov 28, 2023
    Dataset provided by
    CKANhttps://ckan.org/
    Description

    A Data Protection Impact Assessment (DPIA) is one of the ways to find out what privacy risks people face when information is collected, used, stored, or shared about them. This helps the London Borough of Barnet find issues so that risks can be taken away or lowered to a level that is acceptable. It also cuts down on privacy breaches and complaints that could hurt the Council's reputation or lead to action by the Information Commissioner (the government watchdog). The London Borough of Barnet makes DPIAs public in with its Data Charter and the 2018 Data Protection Act and UK GDPR.

  7. UK largest fines issued for violations of GDPR 2025

    • statista.com
    Updated Feb 19, 2025
    Share
    FacebookFacebook
    TwitterTwitter
    Email
    Click to copy link
    Link copied
    Close
    Cite
    Statista (2025). UK largest fines issued for violations of GDPR 2025 [Dataset]. https://www.statista.com/statistics/1385746/largest-fines-issued-gdpr-uk/
    Explore at:
    Dataset updated
    Feb 19, 2025
    Dataset authored and provided by
    Statistahttp://statista.com/
    Time period covered
    Feb 2025
    Area covered
    United Kingdom
    Description

    As of February 2025, the largest fine issued for violation of the General Data Protection Regulation (GDPR) in the United Kingdom (UK) was more than 22 million euros, received by British Airways in October 2020. Another fine received by Marriott International Inc. in the same month was the second-highest in the UK and amounted to over 20 million euros.

  8. e

    Protection of personal data

    • data.europa.eu
    html
    Share
    FacebookFacebook
    TwitterTwitter
    Email
    Click to copy link
    Link copied
    Close
    Cite
    LESY Slovenskej republiky, štátny podnik, Protection of personal data [Dataset]. https://data.europa.eu/data/datasets/4ab21feb-63c7-4b81-bbd7-ee1ffda9a768/
    Explore at:
    htmlAvailable download formats
    Dataset authored and provided by
    LESY Slovenskej republiky, štátny podnik
    Description

    Contracts concluded between the Controller and the Processor pursuant to Act No. 18/2018 Coll. and General Data Protection Regulation — GDPR

  9. DPIA (Data Privacy Impact Assessments) - Dataset - data.gov.uk

    • ckan.publishing.service.gov.uk
    Updated Mar 4, 2022
    Share
    FacebookFacebook
    TwitterTwitter
    Email
    Click to copy link
    Link copied
    Close
    Cite
    ckan.publishing.service.gov.uk (2022). DPIA (Data Privacy Impact Assessments) - Dataset - data.gov.uk [Dataset]. https://ckan.publishing.service.gov.uk/dataset/dpia-data-privacy-impact-assessments
    Explore at:
    Dataset updated
    Mar 4, 2022
    Dataset provided by
    CKANhttps://ckan.org/
    Description

    A data protection impact assessment (DPIA) is a process to identify privacy risks to individuals in the collection, use, storing, and disclosure of information. This allows Camden to identify problems so that risks can be removed or reduced to acceptable levels. It also reduces privacy breaches and complaints which can damage the Council’s reputation or enforcement action against it by the Information Commissioner (the regulator). We publish these as a dataset in accordance with the Council's Data Charter and also the GDPR/Data Protection Act 2018.

  10. Steps taken by U.S. companies to comply with GDPR 2018

    • statista.com
    Updated Jul 10, 2025
    Share
    FacebookFacebook
    TwitterTwitter
    Email
    Click to copy link
    Link copied
    Close
    Cite
    Statista (2025). Steps taken by U.S. companies to comply with GDPR 2018 [Dataset]. https://www.statista.com/statistics/946800/steps-taken-companies-taken-comply-gdpr-usa/
    Explore at:
    Dataset updated
    Jul 10, 2025
    Dataset authored and provided by
    Statistahttp://statista.com/
    Time period covered
    Jul 2018 - Aug 2018
    Area covered
    United States
    Description

    This statistic presents the steps taken by companies in the United States to comply with the European Union's General Data Protection Regulation Act as of ***********. According to the findings, ** percent of respondents reported that their company had conducted a GDPR gap assessment, while ** percent stated that they have increased their data privacy budget as a measure towards complying with the GDPR.

  11. e

    Complaints received by the CNIL

    • data.europa.eu
    csv, excel xlsx
    + more versions
    Share
    FacebookFacebook
    TwitterTwitter
    Email
    Click to copy link
    Link copied
    Close
    Cite
    Complaints received by the CNIL [Dataset]. https://data.europa.eu/data/datasets/555b616ec751df4bb2190c78?locale=en
    Explore at:
    csv(465), excel xlsx(9261)Available download formats
    License

    Licence Ouverte / Open Licence 1.0https://www.etalab.gouv.fr/wp-content/uploads/2014/05/Open_Licence.pdf
    License information was derived automatically

    Description

    Any person or association can submit a complaint to the CNIL for non-compliance with the Data Protection Act and, since May 25, 2018, for non-compliance with the General Data Protection Regulation (GDPR).

    The CNIL can then contact the person in charge of the file to check its compliance with the law and request corrective actions if necessary. At the end, the complainant is informed of the actions taken.

    This dataset presents the number of complaints received since 1981.

    Disclaimer: for any questions about the operation of a file and the help that the CNIL can provide you, please do not use the "Discussions" below, which are visible to all and reserved for exchanges on published datasets; use the Need help service (https://www.cnil.fr/en/cnil-direct) or contact the CNIL on 01 53 73 22 22.

  12. COVID-19: Pandemic and Health Emergency Response Services

    • s3.amazonaws.com
    Updated Mar 9, 2021
    + more versions
    Share
    FacebookFacebook
    TwitterTwitter
    Email
    Click to copy link
    Link copied
    Close
    Cite
    Public Health England (2021). COVID-19: Pandemic and Health Emergency Response Services [Dataset]. https://s3.amazonaws.com/thegovernmentsays-files/content/170/1704858.html
    Explore at:
    Dataset updated
    Mar 9, 2021
    Dataset provided by
    GOV.UKhttp://gov.uk/
    Authors
    Public Health England
    Description

    The Secretary of State for Health and Social Care, acting through the executive agency of the Department of Health and Social Care, Public Health England, has commissioned the provision of various services to support members of the public during the coronavirus (COVID-19) pandemic.

    These services are part of the Pandemic and Health Emergency Response Services (PHERS) which supplements the response provided by primary care during pandemics and other health-related emergencies.

    These documents explain how personal data is used, in line with the UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018. It includes information on the purpose and categories of data processed, and your rights if information about you is included.

  13. Sanctions pronounced by the CNIL

    • data.europa.eu
    csv, excel xlsx
    Updated Aug 26, 2025
    + more versions
    Share
    FacebookFacebook
    TwitterTwitter
    Email
    Click to copy link
    Link copied
    Close
    Cite
    CNIL (2025). Sanctions pronounced by the CNIL [Dataset]. https://data.europa.eu/data/datasets/591af43d88ee3826b379093a?locale=en
    Explore at:
    excel xlsx(11522), csv(848), excel xlsx(10266), excel xlsx(10813), csv(247), csv(403)Available download formats
    Dataset updated
    Aug 26, 2025
    Dataset provided by
    National Commission on Informatics and Liberty
    Authors
    CNIL
    License

    Licence Ouverte / Open Licence 1.0https://www.etalab.gouv.fr/wp-content/uploads/2014/05/Open_Licence.pdf
    License information was derived automatically

    Description

    The CNIL may sanction a data controller who has not taken the necessary measures to comply with the Data Protection Act and, from 25 May 2018, the General Data Protection Regulation (GDPR).

    The datasets presented concern the number of sanctions, pronounced by the restricted formation of the CNIL, notified each year since 2014 (and their breakdown by type of decision, which has evolved hence the publication of data with the new typology of sanctions as of 2019).

    In addition to the distribution of this game, the content of the public sanctions is available on Legifrance.

    Disclaimer: for any questions about the operation of a file and the help that the CNIL can provide you, please do not use the "Discussions" below, which are visible to all and reserved for exchanges on published datasets; use the Need help service (https://www.cnil.fr/en/cnil-direct) or contact the CNIL on 01 53 73 22 22.

  14. g

    Controls carried out by the CNIL | gimi9.com

    • gimi9.com
    Share
    FacebookFacebook
    TwitterTwitter
    Email
    Click to copy link
    Link copied
    Close
    Cite
    Controls carried out by the CNIL | gimi9.com [Dataset]. https://gimi9.com/dataset/eu_555c431bc751df5800190c78
    Explore at:
    License

    Licence Ouverte / Open Licence 1.0https://www.etalab.gouv.fr/wp-content/uploads/2014/05/Open_Licence.pdf
    License information was derived automatically

    Description

    To verify compliance with the Data Protection Act (and the GDPR since 25 May 2018), the CNIL has the option of controlling files recording personal data. This control may be exercised: - on site (on the premises of the person responsible for the file); - on convocation (on CNIL premises); - on documents (request for documents); - and, since 2014, online (website monitoring). Eight datasets are published: 1. number and types of checks carried out each year since 1990 (csv and xls); 2. lists of checks carried out, by year, from 2014 to 2022 (csv and xls).

  15. Largest fines issued for violations of GDPR 2025

    • statista.com
    • abripper.com
    Updated Nov 28, 2025
    Share
    FacebookFacebook
    TwitterTwitter
    Email
    Click to copy link
    Link copied
    Close
    Cite
    Statista (2025). Largest fines issued for violations of GDPR 2025 [Dataset]. https://www.statista.com/statistics/1133337/largest-fines-issued-gdpr/
    Explore at:
    Dataset updated
    Nov 28, 2025
    Dataset authored and provided by
    Statistahttp://statista.com/
    Area covered
    Europe
    Description

    Since the European Union's implementation of the General Data Protection Regulation (GDPR) in May 2018, numerous fines have been issued for violations or non-compliance. Of these, the fine of 1.2 billion euros received by Meta Platforms, Inc. in May 2023 has been by far the greatest. The company was issued such a penalty for personal data transfers to the United States without sufficiently complying with the EU regulation.

  16. g

    Letters of formal notice issued by the CNIL | gimi9.com

    • gimi9.com
    Share
    FacebookFacebook
    TwitterTwitter
    Email
    Click to copy link
    Link copied
    Close
    Cite
    Letters of formal notice issued by the CNIL | gimi9.com [Dataset]. https://gimi9.com/dataset/eu_591acfbb88ee387bd5a92ab7/
    Explore at:
    License

    Licence Ouverte / Open Licence 1.0https://www.etalab.gouv.fr/wp-content/uploads/2014/05/Open_Licence.pdf
    License information was derived automatically

    Description

    The President of the CNIL has the possibility to formal notice a data controller to take the necessary measures, within a period that it sets, to comply with the amended Data Protection Act and, from 25 May 2018, the General Data Protection Regulation (GDPR). The dataset presented concerns the number of formal notices notified each year since 2014 (and their public/non-public breakdown). In addition to the distribution of this game, the content of the public notices is available on Legifrance. Disclaimer: for any questions about the operation of a file and the help that the CNIL can provide you, please do not use the "Discussions" below, which are visible to all and reserved for exchanges on published datasets; use the Need help service (https://www.cnil.fr/en/cnil-direct) or contact the CNIL on 01 53 73 22 22.

  17. HMO Register - Dataset - data.gov.uk

    • ckan.publishing.service.gov.uk
    Updated Mar 6, 2023
    Share
    FacebookFacebook
    TwitterTwitter
    Email
    Click to copy link
    Link copied
    Close
    Cite
    ckan.publishing.service.gov.uk (2023). HMO Register - Dataset - data.gov.uk [Dataset]. https://ckan.publishing.service.gov.uk/dataset/hmo-register5
    Explore at:
    Dataset updated
    Mar 6, 2023
    Dataset provided by
    CKANhttps://ckan.org/
    Description

    List of properties licensed under the Council’s HMO Licensing Scheme. This list is updated on a monthly basis. Under section 232 of The Housing Act 2004 the London Borough of Barnet is required to maintain and make available a public register of licensed Houses in Multiple Occupations. An extract of the register is published on the Council’s website here. The dataset is not intended for marketing purposes and none of the individuals or organisations mentioned within this register have given their consent for such use. Companies wishing to use this data for commercial purposes, and marketing in particular, are advised to consider whether their use of this data complies with the UK General Data Protection Regulations (GDPR), Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003. Information Rights are upheld by the Information Commissioners Office, for further information, see the Information Commissioner’s Office website at ww.ico.org.uk. More information on Houses in Multiple Occupancy can be found on our website as well as on the council's Planning portal. You will need to select "Houses in Multiple Occupation" from the drop-down menu and click "Search":

  18. GDPR Fines Repository

    • kaggle.com
    zip
    Updated Dec 31, 2022
    Share
    FacebookFacebook
    TwitterTwitter
    Email
    Click to copy link
    Link copied
    Close
    Cite
    vdwow (2022). GDPR Fines Repository [Dataset]. https://www.kaggle.com/datasets/valentindefour/gdpr-fines-referential/discussion
    Explore at:
    zip(44996 bytes)Available download formats
    Dataset updated
    Dec 31, 2022
    Authors
    vdwow
    License

    https://creativecommons.org/publicdomain/zero/1.0/https://creativecommons.org/publicdomain/zero/1.0/

    Description

    Context

    In May 2018, GDPR went into effect. Since then, the local european authorities (such as CNIL for France) issued fines to companies for non respect of the GDPR principles.

    Content

    A data referential of all known GDPR fines issued by european local authorities regarding GDPR reglementation.

  19. C

    WaH informed consent and image rights forms

    • dataverse.csuc.cat
    pdf, txt
    Updated Jul 12, 2023
    Share
    FacebookFacebook
    TwitterTwitter
    Email
    Click to copy link
    Link copied
    Close
    Cite
    Carme Montserrat; Carme Montserrat; Marta Garcia Molsosa; Marta Garcia Molsosa (2023). WaH informed consent and image rights forms [Dataset]. http://doi.org/10.34810/data506
    Explore at:
    txt(6449), pdf(801115), pdf(257580), pdf(190399), pdf(1087773), pdf(188251), pdf(737114), pdf(1087535), pdf(737011), pdf(1104027), pdf(1104399)Available download formats
    Dataset updated
    Jul 12, 2023
    Dataset provided by
    CORA.Repositori de Dades de Recerca
    Authors
    Carme Montserrat; Carme Montserrat; Marta Garcia Molsosa; Marta Garcia Molsosa
    License

    Attribution 4.0 (CC BY 4.0)https://creativecommons.org/licenses/by/4.0/
    License information was derived automatically

    Dataset funded by
    https://ror.org/03zhx9h04
    Description

    This dataset includes the informed consent forms template used in the research projecte "WeAreHere!"(WaH) ["SomAquí!"] for children's questionnaire, for teachers' questionnaire and for advisory groups. Children under 14 years old doing the questionnaire or participating in the advisory groups needed also the consent of their parents (informed consent forms also included in this dataset). It also includes the image rights forms template for children under 14 years old and 14 and over. All the documents are in Catalan language, except the informed consent forms for parents, that have a Catalan and Spanish version. The informed consent forms have been designed according to the Organic Law 3/2018 on Data Protection and Guarantee of Digital Rights and the General Data Protection Regulation (GDPR) 2016/679 of the European Parliament and of the Council and have been approved by the Ethical Committee of the University of Girona (CEBRU0009-21).

  20. Penalties issued to Meta for EU GDPR violations 2024

    • statista.com
    Updated Nov 15, 2024
    Share
    FacebookFacebook
    TwitterTwitter
    Email
    Click to copy link
    Link copied
    Close
    Cite
    Statista (2024). Penalties issued to Meta for EU GDPR violations 2024 [Dataset]. https://www.statista.com/statistics/1192794/meta-fines-from-eu-and-dpc/
    Explore at:
    Dataset updated
    Nov 15, 2024
    Dataset authored and provided by
    Statistahttp://statista.com/
    Time period covered
    Mar 2022 - Sep 2024
    Area covered
    Europe
    Description

    In September 2024, the Irish Data Protection Commission fined Meta Ireland 91 million euros after passwords of social media users were stored in 'plaintext' on Meta's internal systems rather than with cryptographic protection or encryption. In May 2023, the EU fined Meta 1.2 billion euros for violating laws on digital privacy and putting the data of EU citizens at risk through Facebook's EU-U.S. data transfers. European privacy legislation is seen as being far stricter than American privacy law, and the sending of EU citizens’ data to the United States resulted in the record breaking penalty being issued to the tech giant. In January 2023, after it was discovered that Meta Platforms had improperly required that users of Facebook, Instagram, and WhatsApp accept personalized adverts to use the platforms, the company was issued a 390 million euro fine by the European Commission. EU regulators claim that the social media giant broke the General Data Protection Regulation (GDPR) by including the demand in its terms of service. In addition, Meta was fined 405 million euros by the Irish Data Protection Commission (DPC) in September 2022 for violating Instagram's children's privacy settings. In November 2022, the DPC fined Meta a further 265 million euros for failing to protect their users from data scraping. GDPR violations in 2022 Social media sites and companies are not the only types of online services upon which users' data can potentially be compromised. In 2022, the online service with the biggest fine for violating GDPR was e-commerce and digital powerhouse Amazon, which was issued a 746 million euro fine. Furthermore, in December 2021, Google was penalized 90 million euros for GDPR violations. What are the most common GDPR violations? Since GDPR went into effect in May 2018, fines have been imposed for a variety of reasons. As of June 2022, companies' non-compliance with general data processing principles accounted for the largest share of fines, resulting in over 845 million euros worth of penalties. Insufficient legal basis for data processing was the second most common violation, amounting to 447 million euros in fines.

Share
FacebookFacebook
TwitterTwitter
Email
Click to copy link
Link copied
Close
Cite
Statista (2023). Challenges to adapt privacy compliance changes for companies in the EU and UK 2023 [Dataset]. https://www.statista.com/statistics/1403394/eu-uk-firms-challenge-consumer-data-privacy-law/
Organization logo

Challenges to adapt privacy compliance changes for companies in the EU and UK 2023

Explore at:
Dataset updated
Jul 15, 2023
Dataset authored and provided by
Statistahttp://statista.com/
Time period covered
Apr 2023 - May 2023
Area covered
European Union, United Kingdom
Description

A survey conducted in April and May 2023 revealed that around ** percent of the companies that do business in the European Union (EU) and the United Kingdom (UK) found it challenging to adapt to new or changing requirements of the General Data Protection Regulation (GDPR) or Data Protection Act 2018 (DPA). A further ** percent of the survey respondents said it was challenging to increase the budget because of the changes in the data privacy laws.

Search
Clear search
Close search
Google apps
Main menu