# Three Years Later: GDPR is All Talk and No Action
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-07-09
Category: BUSINESS
Category URL: https://financedigest.com/category/business
Meta Title: The Truth About GDPR Compliance: Is Self-Regulation Enough?
Meta Description: Discover why three years post-GDPR, the regulation is struggling to meet its objectives and how a GDPR kitemark could provide consumers with the reassurance
URL: https://financedigest.com/three-years-later-gdpr-is-all-talk-and-no-actionhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/technology-and-innovation-1736838200219-compressed.jpg)

**_The General Data Protection Regulation (GDPR) was introduced on May 25th 2018. This legislation focuses on data protection and privacy across the European Union (EU) and European Economic Area (EEA), while addressing the transfer of personal data outside of the EU and EEA, and aims to provide citizens with more control over their information._**

However, three years into a post-GDPR world, the regulation remains all talk, no action – and isn’t quite meeting its objective effectively. Although we have witnessed the likes of British Airways, H&M and the Marriott hotel chain suffer heavy fines of up to £32.1m for their data protection failings, even the latest [_potential_](https://www.reuters.com/technology/amazon-likely-see-425-million-eu-privacy-fine-wsj-2021-06-10/) fine on Amazon cannot mask that GDPR still lacks the necessary funding and structure to make it more than an incipient – supposedly hard-hitting – concept.

A big part of the problem is due to the self-regulative – ‘honesty-policy’ – nature of the legislation. It is typically up to individual organisations to record and communicate their own offences and infringements to the Information Commissioner’s Office (ICO), who then enforce the regulation.

Which entity is responsible for inspecting whether a [business is actually still GDPR compliant three years](https://www.financedigest.com/why-the-new-year-is-the-best-time-to-start-your-dream-tech-business.html "Why the New Year is the best time to start your dream tech business") later? Who is in charge of validating [GDPR compliance](https://www.financedigest.com/clarity-structure-key-gdpr-compliance-finance.html "Clarity and structure: the key to GDPR compliance in finance")? Further, how [effective  – as well as  official – is self-regulation in ensuring organisations](https://www.financedigest.com/organisational-effectiveness-establishing-competitive-difference.html "Organisational Effectiveness: establishing competitive difference") are co-operating? Russell Loarridge, Director UK, ReachFive argues that Martech and retail technology providers have a greater [role to play](https://www.financedigest.com/why-the-bank-branch-still-has-a-role-to-play-for-consumers.html "Why the bank branch still has a role to play for consumers") in GDPR compliance.

**Consumers crave reassurance that data is GDPR compliant** Where is the GDPR equivalent standard that proves that organisations are certified as “compliant”?

A GDPR kitemark would [solve this problem](https://www.financedigest.com/british-start-up-reveals-the-secret-to-solving-the-problem-of-identity-fraud.html "British start up reveals the secret to solving the problem of identity fraud") and offer customers reassurance from brands, and retailers, that their data is being stored and used in a way that is genuinely GDPR-compliant and ethical.

Typically, important legislation, similar to GDPR, comes with a [need to meet](https://www.financedigest.com/institutions-need-to-consider-spreadsheet-management-to-meet-the-pras-latest-stress-testingexpectations.html "Institutions Need to Consider Spreadsheet Management to Meet the PRA’s Latest Stress Testing Expectations") specific prerequisites in order to certify standards are met. Once it has been proven that these are adhered to, certification usually results in the option for organisations to use a kitemark of sorts as a way of demonstrating compliance has been achieved. Good examples of this in action can be seen from the likes of the [BSI](https://www.bsigroup.com/en-GB/kitemark/services/) or the various [ISO](https://www.iso.org/standards.html) standards.

**Cookie request immunity – click ‘Accept All’** Is anyone else bored with accepting cookies on every site and every click through on mobile, whilst still not knowing why the site needs that information?

As a ‘form’ of GDPR consent, many [businesses often encourage the public to accept cookies when using apps and visiting websites](https://www.financedigest.com/reasons-to-hire-a-web-developer-for-your-business-website.html "Reasons to Hire a Web Developer for Your Business Website"). Is this really acceptable in the eyes of today’s consumer? To the majority of people, cookie requests have become the norm, a boring overhead to using the web.  Users find themselves clicking ‘Accept All’ for convenience in order to reach the online content they were looking for as quickly as they can.

In addition to this, through the pandemic, we witnessed an [accelerated change in consumer behaviour](https://www.financedigest.com/2021-predictions-less-fraud-shifting-consumer-behaviour-and-accelerating-pace-of-innovation.html "2021 predictions: less fraud, shifting consumer behaviour and accelerating pace of innovation"). [Lockdown restrictions forced people to stay at home](https://www.financedigest.com/keeping-your-team-connected-and-beating-work-from-home-fatigue-in-lockdown.html "Keeping your team connected and beating work from home fatigue in lockdown") and consume media online. This included an influx of film and game consumption, as well as an increase in e-commerce. A new study by [Ofcom](https://www.ofcom.org.uk/about-ofcom/latest/media/media-releases/2020/uk-internet-use-surges) found that UK adults are now spending more than a quarter of their waking day online – the highest on record. This [digital transition demonstrates how more and more data](https://www.financedigest.com/why-data-is-the-best-weapon-in-the-war-for-digital-talent.html "Why data is the best weapon in the war for digital talent") continues to shift online at pace.  This drives a heightened risk for [data privacy breaches](https://www.financedigest.com/10-steps-to-stop-lateral-movement-in-data-breaches.html "10 Steps to Stop Lateral Movement in Data Breaches") to take place.

As people [spend more time online and share](https://www.financedigest.com/spending-drive-knocks-spotify-shares-after-q1-beat.html "Spending drive knocks Spotify shares after Q1 beat") data, this is where a GDPR kitemark could help reassure consumers about where to spend their time or money safely. Furthermore,  the industry could benefit from defining the status of compliance achievement, in a similar way to how [PCI DSS](https://www.financedigest.com/the-pci-dss-comes-of-age-with-v3-2.html "The PCI DSS comes of age with v3.2") compliance is defined. What if organisations could confirm whether they are Bronze, Silver, or Gold GDPR compliant? This will help relieve [worries experienced by some consumers](https://www.financedigest.com/autonation-gets-a-bumpy-ride-as-investors-worry-about-u-s-consumers.html "AutoNation gets a bumpy ride as investors worry about U.S. consumers") and, indeed, help  organisations demonstrate that they are treating customer data with the privacy it deserves.

**Consumer demand drives more to be done by tech firms though** Not long after GDPR’s three-year anniversary, at Apple’s recent developer conference, it [announced](https://www.apple.com/newsroom/2021/06/apple-advances-its-privacy-leadership-with-ios-15-ipados-15-macos-monterey-and-watchos-8/) new features that will help users control and monitor apps’ use of their data.

Driven by consumer demand, this is a good move by Apple – we expect the idea of ‘privacy’ to become a [competitive differentiator](https://www.financedigest.com/how-music-sound-can-help-financial-brands-differentiate-in-a-competitive-world.html "How Music & Sound Can Help Financial Brands Differentiate in a Competitive World") for the tech giant and other ‘copycat’ firms down the line. We anticipate more [brands to follow](https://www.financedigest.com/10-million-to-be-whipped-into-ice-cream-brand-four-winters-following-acquisition.html " Million To Be Whipped Into Ice Cream Brand Four Winters Following Acquisition ") suit as they strive to demonstrate data privacy and GDPR compliance. Within today’s data-driven landscape, people will start to take more of an interest in how their [personal data](https://www.financedigest.com/five-ways-to-keep-your-personal-data-safe-from-hackers.html "Five ways to keep your personal data safe from hackers") is used too. This is where Martech and retail [technology vendors have a critical leading role](https://www.financedigest.com/the-role-of-technology-in-post-pandemic-recovery.html "The role of technology in post-pandemic recovery") to play.

As [organisations seek to achieve GDPR compliance and data](https://www.financedigest.com/tackling-the-complexity-of-data-within-financial-organisations.html "Tackling the complexity of data within financial organisations") privacy best practice, they need to assess whether they are collecting and storing customer data ethically. For some, this might [mean completely re-engineering how they engage](https://www.financedigest.com/the-pandemic-means-that-its-time-to-double-down-on-our-commitment-wellbeing-and-employee-engagement.html "The pandemic means that it’s time to double down on our commitment wellbeing and employee engagement") with customers at an ‘identity’ level. This is where [customer identity and access management](https://www.financedigest.com/allianz-benelux-taps-into-modern-data-management-to-combat-fraud-and-foster-a-positive-customer-experience.html "Allianz Benelux Taps into Modern Data Management to Combat Fraud and Foster a Positive Customer Experience") (CIAM) technology can help. For ecommerce brands, this is especially crucial to review too – many mistakenly think that their e-commerce engines provide some form of identity management; when, in fact, they don’t.  Further, since there is no kitemark for GDPR yet, a combination of tools, like CIAM, can help firms manage customer identity (and data) effectively and transparently, and support their growing [business under the best practice](https://www.financedigest.com/6-practical-tips-for-starting-an-online-business.html "6 Practical Tips for Starting an Online Business") outlined by GDPR.

All of this can help [build trust with consumers that personal](https://www.financedigest.com/best-guide-to-build-a-personal-financial-plan.html "Best Guide to Build a Personal Financial Plan") data is not abused – but, equally, that it will be used to drive relevant and personalised marketing that truly benefits consumers.

**Conclusion** What has GDPR taught us over the past three years? Arguably, not a lot.

The current state of GDPR in 2021 consists of self-regulation, a lack of an industry kitemark, as well as an absence in enforcement. For a legislation as important as one that [protects the public’s data](https://www.financedigest.com/4-steps-you-should-be-taking-to-protect-data.html "4 Steps You Should Be Taking To Protect Data"), more needs to be done to provide confidence to consumers that their information is being respected by the rules set out by GDPR’s regulatory requirements – but, equally, that brands, or retailers, don’t just superficially try to meet these requirements. Instead, ethical [data management](https://www.financedigest.com/use-case-centric-data-management-why-it-is-the-future-of-data-management-for-financial-institutions.html "Use Case centric data management – Why it is the future of data management for financial institutions") and privacy should ideally underpin their character, customer relationships and GDPR efforts long-term.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

