Facebook
TwitterAs of February 2025, the largest fine issued for violation of the General Data Protection Regulation (GDPR) in the United Kingdom (UK) was more than 22 million euros, received by British Airways in October 2020. Another fine received by Marriott International Inc. in the same month was the second-highest in the UK and amounted to over 20 million euros.
Facebook
TwitterA survey conducted in April and May 2023 revealed that around ** percent of the companies that do business in the European Union (EU) and the United Kingdom (UK) found it challenging to adapt to new or changing requirements of the General Data Protection Regulation (GDPR) or Data Protection Act 2018 (DPA). A further ** percent of the survey respondents said it was challenging to increase the budget because of the changes in the data privacy laws.
Facebook
TwitterAttribution 4.0 (CC BY 4.0)https://creativecommons.org/licenses/by/4.0/
License information was derived automatically
BackgroundThe COVID-19 pandemic brought global disruption to health, society and economy, including to the conduct of clinical research. In the European Union (EU), the legal and ethical framework for research is complex and divergent. Many challenges exist in relation to the interplay of the various applicable rules, particularly with respect to compliance with the General Data Protection Regulation (GDPR). This study aimed to gain insights into the experience of key clinical research stakeholders [investigators, ethics committees (ECs), and data protection officers (DPOs)/legal experts working with clinical research sponsors] across the EU and the UK on the main challenges related to data protection in clinical research before and during the pandemic.Materials and methodsThe study consisted of an online survey and follow-up semi-structured interviews. Data collection occurred between April and December 2021. Survey data was analyzed descriptively, and the interviews underwent a framework analysis.Results and conclusionIn total, 191 respondents filled in the survey, of whom fourteen participated in the follow-up interviews. Out of the targeted 28 countries (EU and UK), 25 were represented in the survey. The majority of stakeholders were based in Western Europe. This study empirically elucidated numerous key legal and ethical issues related to GDPR compliance in the context of (cross-border) clinical research. It showed that the lack of legal harmonization remains the biggest challenge in the field, and that it is present not only at the level of the interplay of key EU legislative acts and national implementation of the GDPR, but also when it comes to interpretation at local, regional and institutional levels. Moreover, the role of ECs in data protection was further explored and possible ways forward for its normative delineation were discussed. According to the participants, the pandemic did not bring additional legal challenges. Although practical challenges (for instance, mainly related to the provision of information to patients) were high due to the globally enacted crisis measures, the key problematic issues on (cross-border) health research, interpretations of the legal texts and compliance strategies remained largely the same.
Facebook
TwitterThis statistic shows the results of a survey on the share of respondents that agreed with selected statements on the EU General Data Protection Regulations (GDPR) legislation in the United Kingdom (UK) in 2017. During the survey, ** percent of IT decision makers either strongly agreed or agreed that they faced some serious challenges in being compliant with the EU GDPR by ************.
Facebook
TwitterThis statistic shows the results of a survey on how aware consumers were of their rights regarding data protection under the upcoming GDPR legislation in the United Kingdom (UK) as of December 2017. The survey, that looked into consumer attitudes towards sharing their personal data with businesses, found that ** percent of respondents stated to never have heard of the new data protection regulations that will apply from ********** onwards.
Facebook
TwitterSince the enforcement of the General Data Protection Regulation (GDPR) in May 2018, fines have been issued for several types of violations. As of February 2025, the most significant share of penalties was due to companies' non-compliance with general data processing principles. This violation has led to over 2.4 billion euros worth of fines.
Facebook
TwitterIn September 2024, the Irish Data Protection Commission fined Meta Ireland 91 million euros after passwords of social media users were stored in 'plaintext' on Meta's internal systems rather than with cryptographic protection or encryption. In May 2023, the EU fined Meta 1.2 billion euros for violating laws on digital privacy and putting the data of EU citizens at risk through Facebook's EU-U.S. data transfers. European privacy legislation is seen as being far stricter than American privacy law, and the sending of EU citizens’ data to the United States resulted in the record breaking penalty being issued to the tech giant. In January 2023, after it was discovered that Meta Platforms had improperly required that users of Facebook, Instagram, and WhatsApp accept personalized adverts to use the platforms, the company was issued a 390 million euro fine by the European Commission. EU regulators claim that the social media giant broke the General Data Protection Regulation (GDPR) by including the demand in its terms of service. In addition, Meta was fined 405 million euros by the Irish Data Protection Commission (DPC) in September 2022 for violating Instagram's children's privacy settings. In November 2022, the DPC fined Meta a further 265 million euros for failing to protect their users from data scraping. GDPR violations in 2022 Social media sites and companies are not the only types of online services upon which users' data can potentially be compromised. In 2022, the online service with the biggest fine for violating GDPR was e-commerce and digital powerhouse Amazon, which was issued a 746 million euro fine. Furthermore, in December 2021, Google was penalized 90 million euros for GDPR violations. What are the most common GDPR violations? Since GDPR went into effect in May 2018, fines have been imposed for a variety of reasons. As of June 2022, companies' non-compliance with general data processing principles accounted for the largest share of fines, resulting in over 845 million euros worth of penalties. Insufficient legal basis for data processing was the second most common violation, amounting to 447 million euros in fines.
Facebook
TwitterThe global market research industry reached a record high market size of approximately ** billion U.S. dollars in 2023. Over the last decade, the global market research industry has performed contrary to broader economic trends as the industry has continued to grow. Figures for 2023 signaled an increase of about *** billion U.S. dollars compared to the previous year. Market research industryMarket research is the activity of gathering information about markets in which an organization sells their produces and/or services. This often includes detailed qualitative understandings of consumer attitudes and preferences through tools such interviews, surveys, and increasingly, big-data analytics. The leading market research company worldwide was U.S.-based Gartner in 2022. Slow growth in EuropeWhile growth in the United States has been significant, the revenue of the market research industry in Europe grew just slightly since 2014. Some analysts expect this poor performance to continue into the near future for *** reasons. First is the short- and mid-term uncertainty created by Brexit, impacting the reliability of any market research conducted prior to the issue being resolved. Second is the implementation of the EU General Data Protection Regulation (GDPR) laws in May 2018, which limit what companies are able to do with personal data. A majority of IT professionals in France, Germany and the UK agree the GDPR laws will prevent personal data being passed on to third parties, reducing the amount of data available to researchers in Europe compared to other regions.
Not seeing a result you expected?
Learn how you can add new datasets to our index.
Facebook
TwitterAs of February 2025, the largest fine issued for violation of the General Data Protection Regulation (GDPR) in the United Kingdom (UK) was more than 22 million euros, received by British Airways in October 2020. Another fine received by Marriott International Inc. in the same month was the second-highest in the UK and amounted to over 20 million euros.