In July of this year, the UK Information Commissioner's Office (ICO)quietly issued the first General Data Protection Regulation (GDPR) violation notice to a Canadian analytics company

Last week, the German data protection authority (DPA) issued the country's first GDPR fine, imposing a penalty of nearly $23,000 (about €20,000) on the chat platform Knuddels.de,according to Bleeping Computer. The company suffered a data breach in July involving 1.8 million usernames and more than 808,000 email addresses.

But beyond that, the regulatory landscape has been largely quiet—too quiet, some would say.

Although GDPR has forced companies to rethink their relationship with consumer data, many are still dragging their feet on compliance or treating it as a one-time task. Heading into 2019, all eyes will be on European regulators, waiting to see when they will issue the first major fines or penalties against non-compliant companies.

In the US, comprehensive data privacy and protection rules remain lagging. A federal data privacy law may still be years away, but state-level legislation with GDPR principles is gradually shaping data handling and operational practices.

Expert Perspectives

The implementation of GDPR has not been without its critics.

TrustArc CEO Chris Babel told CIO Dive that people and processes were put in place to meet the first deadline, but compliance was not viewed from a sustainability perspective.

eBay CEO Devin Wenig said at The Washington Post's "Technology 202 Live" event in Washington in October that GDPR, while a "good idea," was pushed from the bottom up rather than the top down, resulting in poor implementation. He mentioned that the problems should have been figured out first before wiring things up. "You know, we plastered cookie banners all over our websites before answering, 'What problem are we actually trying to solve?'"

When assessing the impact of GDPR, geographic factors must be considered.

Box Chief Compliance Officer Crispen Maung told CIO Dive that US industries are still lagging in GDPR compliance. Europeans have been discussing GDPR for longer and are more directly subject to it, so their compliance levels are higher. He also said the chaos surrounding Brexit has given many companies breathing room—not an exemption, but extra time to get their internal affairs in order.

GDPR is driving more businesses and professionals into the information security field, not only to understand the appropriate use of data but also its ethical use.

Sumo Logic Data Protection Officer Jen Brown told CIO Dive that GDPR has also increased discussions about how companies approach "privacy by design." As privacy and design become increasingly integrated into the early stages of business, privacy engineering is emerging as a new career track in the industry.

Improving data-related processes and controls and embedding these protections across all areas of the enterprise will become an ongoing responsibility for organizations.

Babel noted that one area not receiving enough attention is GDPR's impact on B2B relationships. Contract negotiations between companies are seeing more disputes over which party controls or is responsible for what, indicating that companies are holding each other strongly accountable.

What to Watch in 2019

Many experts expect fines and more notices to emerge over the coming year.

John Visneski, Chief Information Security Officer and DPO at The Pokémon Company International, told CIO Dive that there are signs regulators are preparing to take action against companies that do not take GDPR seriously. For now, in terms of regulatory and enforcement capability, GDPR remains the highest standard companies need to meet.

Maung predicts that regulators will continue to issue notices quietly until they have accumulated enough precedent before raising their voices. The coming year may be relatively calm as data protection authorities continue to define and redefine their processes.

Every European can file a complaint against a company, and regulators are currently processing thousands of requests. This process becomes complex when it crosses geographic boundaries. Maung said that if a French citizen files a complaint against a German company, they would go to the French DPA, which must then contact the DPA in the corresponding region of Germany. This process currently lacks sufficient "muscle memory" to operate efficiently, but it will improve as the regulation matures.

Matt Radolec, Security Architecture Manager at Varonis, told CIO Dive that looking at precedents from major regulations like the Sarbanes-Oxley Act, HIPAA, and PCI, these regulations often take years and multiple fines before organizations truly take them seriously.

But when it comes to compliance, it's important not to view deadlines as endpoints, but rather as a step toward the ultimate goal of more responsible, secure data use and customer protection.

The quiet six months have raised concerns: if major regulatory action doesn't come soon, people will stop caring about the regulation.

Radolec said that a regulation without teeth is just a piece of paper, and unless regulators start imposing real penalties, many companies that haven't taken it seriously will remain unmotivated. Whether it's 2019, 2020, or 2025, it will take a sensational headline-grabbing case involving hundreds of millions of dollars to truly get people's attention.

He said that in 2019, organizations need to continue on the path of compliance. Ensuring that data maps, processing systems, and data subject request processes are adequate will help companies demonstrate that they have fulfilled their due diligence obligations.

Brown said they also need to continue thinking about privacy holistically, because "the flashlight has been turned on and won't be turned off." Focusing solely on GDPR or the California Consumer Privacy Act is not enough.

Is a US Version of GDPR on the Horizon?

Some of America's top executives and businesses havecalled for a US data privacy law. After several high-profile data breaches in the past few years, consumer calls for more protection are also rising.

Wenig said that if the US passes its own version, it could be "very, very different and done better." The US needs to start from the question, "What privacy problem are we trying to solve?" and figure out how to achieve those goals without "screwing up" companies that serve as beacons of innovation.

When asked whether the White House is considering privacy legislation, Abigail Slater, Special Assistant to the President for Technology, Telecommunications, and Cyber Policy at the White House Economic Council, said at the Technology 202 event that the White House is willing to work with Congress on privacy legislation. She said agencies such as the National Telecommunications and Information Administration, the National Institute of Standards and Technology, and the Department of Commerce provide people with a "deliberative policy-making process" to participate in.

Big tech companies have called on Congress to enact privacy regulations, particularly hoping tooverturn certain provisions in the California privacy law, including where information is stored, how quickly data requests must be responded to, and the scale of fines. Many industry associations are pushing for voluntary standards to replace legal mandates, which critics argue are insufficient to bring about meaningful change.

Radolec said there is considerable business pressure to block federal policy. The current administration is very pro-business, and data privacy regulation is not a cost-cutting measure. He said that given the administration hasn't issued much comprehensive regulation so far, the White House is more likely to choose executive action. Privacy legislation is also unlikely to pass in an election year.

If a US version eventually emerges, Brown advocates for including provisions on youth privacy education. "We've become such a networked society," she said, and privacy and security need to be taught from a young age so people don't think data is free.

States Still Leading the Way

For now, California continues to lead in the US with theCalifornia Consumer Privacy Act, which goes into effect in early 2019. As the center of the US tech industry, California's economy is unavoidable for many businesses nationwide.

Colorado also enacted theColorado Consumer Data Privacy Protection Actin September—a strategic move for companies looking to attract more tech firms to their state.

These pioneers are expected to shape policy in other US states. New York is likely to be the next to follow suit, and other parts of the Northeast, especially Massachusetts, Connecticut, and New Jersey, may follow closely behind.

State-level regulations still lack the "teeth" of GDPR, making it harder to get organizations to demonstrate compliance. They are also not as prescriptive as European standards.

Companies already compliant with GDPR and now focusing on CCPA can breathe a sigh of relief. "If you've already done GDPR, and you look at what needs to be done for CCPA, you're already 87% done," Babel said. There are some differences and adjustments, but at a foundational level, one helps the other.

Some companies chose to isolate European users and implement GDPR compliance only for that subset, rather than for the entire business. With CCPA approaching, many companies now have to repeat many of the same processes for the rest of their business—which is time-consuming and resource-intensive, Babel said. If they had implemented compliance for the entire business from the start, it would have been much easier.