A lot has happened since the European General Data Protection Regulation (GDPR) came into force in 2018 - and not just in terms of data protection awareness. Sanctioning practices have also increased noticeably: According to the latest report by law firm CMS, fines totalling over 5.5 billion euros have already been imposed across Europe. The report not only highlights the total amount, but also the most common causes.
It is particularly expensive when companies cannot provide a legally sound basis for the processing of personal data - according to the analysis, this affects most cases. Inadequate protective measures for IT security or breaches of basic data protection principles are also among the mistakes frequently penalised. The supervisory authorities are also increasingly focussing on the rights of data subjects, such as information or transparency.
The media, telecommunications and broadcasting industries are the most targeted sectors. Around 70 per cent of all fines are imposed here. However, the handling of employee data also results in severe penalties - particularly in Germany and the Netherlands.
Source: www.behoerden-spiegel.de