Stock Groups

Fines for breaches of EU GDPR privacy law spike sevenfold

[ad_1]

Getty Images| iStock | Getty Images

According to research, fines for violating the landmark EU privacy law have nearly trebled in the last year.

In a Tuesday report, DLA Piper reported that the EU’s data protection authorities handed out $1.25 Billion in penalties for breaches of its General Data Protection Regulation. It’s an increase from the $180million collected a year prior.

However, notifications of data breaches by firms to regulators rose more slowly at 8% to 356 daily on average.

The GDPR was in place since 2018. GDPR has been in force since 2018. sweeping changes to EU’s data rulesThese are designed to give consumers more control over their data in Europe.

Before processing any user’s data, companies must obtain their explicit consent. Companies must immediately notify the authorities of data breaches within 72 hours.

Failure to comply can result in potentially hefty fines — namely, up to 4% of a company’s annual global revenues or 20 million euros ($22.8 million), whichever is the bigger amount.

Ross McKean (chair of DLA Piper’s U.K data protection and security team) stated that “GDPR certainly has been effective in getting everyone to sit up and pay attention to data protection laws and data enforcement.”

“Prior the GDPR fines were much less severe than if they had been imposed and you were one the larger processors. This would have barely covered the costs of Christmas. You now have fines of close to one billion euros.

Record fines

EU regulators issued record GDPR fines last year, with Big Tech driving the bulk of these penalties.

Luxembourg’s privacy watchdog fined Amazon 746 million euros($850 million), while Irish authorities slapped Meta’s WhatsApp with an a 225 million euro penalty. Both companies are currently appealing respective fines.

McKean explained that regulators take a long time when imposing large, frightening fines. It’s because it takes time for investigations to complete. There are still many open questions in the law.

There are many open questions about cross-border data transfers from the EU to the U.S.

2020 saw a landmark ruling by the European Court of Justice invalidating the use of the Privacy Shield frameworkThe legal framework to move data across the Atlantic. After Max Schrems (an Austrian privacy activist), the ruling was called “Schrems II”.

Although the Privacy Shield was disqualified, the ECJ retained the legality of standard contractual clauses. These are another means to guarantee that EU-U.S. data flows remain legally sound. Firms are trying to understand the consequences of this ruling.

The decision’s core argument states that the U.S. system for data protection is not comparable to the EU.

Legal uncertainty

McKean states that legal uncertainties surrounding EU-U.S data transfers are a significant “headache” for companies moving forward.

McKean explained that SCCs, the most common method to legally process such transfers are currently on “life support”, as McKean spoke for officials from the EU and the U.S. hash out plans for a new data pact to replace Privacy Shield.

Meta, the parent company of Facebook has been involved in an intense dispute with the Irish Data Protection CommissionOver the matter. Meta was ordered by the DPC to cease using SCCs as a means of sending user data from Europe into the U.S. while it examines its data transfer practices.

Meta obtained a temporary freeze of the order but this was thrown out by the High Court in Ireland, which gave the watchdog permission to continue with its investigation.

Recent news highlights include: Austria’s data protection watchdog saidGoogle Analytics is a violation of GDPR because it could expose users’ data to U.S. intelligence agents. The decision applies to website publishers who use Google Analytics, and not Google.

Google is a US tech company like Meta, which relies heavily on SCCs in order to handle EU-U.S. data transfer requests. At that time, Google saidGoogle Analytics is used by companies that “control the data collected and how it’s used” and provides an “ensemble of safeguards controls, resources, and control for compliance.”

“Every organization — with some limited exceptions — has an international supply chain and international data transfers,” McKean said, adding the Schrems II ruling has had a “profound” impact on businesses of all shapes and sizes.

McKean said that, in addition to the increased uncertainty legality, he expected to see more appeals for GDPR fines emerging in 2022.

[ad_2]