One key finding is that privacy is increasingly a stand-alone issue of corporate significance, not tied as integrally to data breach as in previous years. Here are some other key results:
- 76 percent of all respondents believe their firm falls under the scope of the GDPR.
- Acquiring and maintaining business relationships is a key driver of GDPR compliance; B2B-focused businesses are far more likely than B2C and even than blended firms to have full-time privacy professionals working in their privacy programs.
- 25 percent of respondents have changed vendors in response to GDPR and 30 percent say they are considering future vendor changes.
- The most popular cross-border data transfer mechanism — by far — is Standard Contractual Clauses.
- More than half the respondents subject to GDPR (56 percent) say they are far from compliance or will never comply.
One of other important stories coming out of this year’s report is a portrait of the role of the data protection officer. This position has exploded on to the scene, with 75 percent of respondent firms reporting they have appointed a DPO. Among those that haven’t, most believe the GPDR simply doesn’t apply to them.