GDPR Takes Effect Soon: The Road to Compliance Remains Long
The EU GDPR will officially take effect on May 25, and corporate compliance processes have entered the final sprint phase. Platforms such as Microsoft, Google, Twitter, and Facebook have released related tools and policy updates, but surveys estimate that a large number of companies will still fail to meet the deadline. The intensity of regulatory enforcement remains unclear, and the ambiguity of the compliance path poses challenges while also offering companies opportunities to demonstrate a sustained sense of responsibility.

Update Notes (May 23, 2018):This article has been supplemented and revised based on the latest information.
As the European Union's General Data Protection Regulation (GDPR) officially takes effect this Friday, many companies are making final refinements and deployments to their compliance measures, while others are feeling the pressure due to lagging compliance progress.
Companies had two years to prepare for GDPR compliance, but multiple estimates indicate that before the deadline, between one-third and 60% of companies will fail to meet compliance requirements.
Recently,Microsoft、Google、TwitterandFacebookhave successively launched GDPR-related tools and processes in a high-profile manner. After all, if a company's value depends on the health of its partner ecosystem, ensuring supplier and platform compliance is crucial.
The road to compliance is winding, full of detours, alternative routes, and dead ends. However, the ambiguity regarding the means to achieve GDPR goals is not necessarily a bad thing.
"You have to understand that tech companies will obviously continue to evolve," Ashley Slavik, senior legal counsel and global data protection officer at Veeva, said in an interview with CIO Dive. "The beauty of these requirements is that there aren't many black-and-white lines. If you can demonstrate accountability over time and show how you embed it into your products and processes, I think you'll be fine."
For example, some companies are implementing differentiated data practices in Europe, while others are extending updated data protection protocols to users globally.
Organizations want to make better use of data, and establishing processes for managing and storing data while maintaining accountability to users will help all companies in the long run. "When I think about GDPR, it's about putting individuals in the driver's seat," Slavik said.
What exactly will happen after May 25 is something no one can know for certain. As regulators figure out how to enforce GDPR, they may set a grace period, understanding that compliance is a long and arduous process. But the EU may also act immediately, making an example of companies that ignore the new rules or fail to give them due priority.
Whether trying todefine GDPR, clarify next steps, or assess overall industry progress, here is a summary of major news and trends related to this upcoming EU regulation:
-
Leadership and Long-Term Thinking: Keys to GDPR Compliance
On the path to compliance, some clear lessons and trends are emerging: companies need strong leadership and a long-term perspective.Read more >>
-
Where Does GDPR Apply? The Answer Isn't Simple
Lawyers point out that the Civil Rights Act of 1964 and provisions prohibiting discrimination based on national origin could be a potential source of controversy for GDPR in the United States.Read more >>
-
Enforcers Themselves Unprepared: How Will GDPR Be Enforced?
A survey of 24 GDPR regulatory authorities found that 17 of them admitted to having insufficient funding and limited powers to fulfill their regulatory obligations.Read more >>
-
GDPR Focuses on Key Compliance Role: Data Protection Officer
Jen Brown and Raymond Umerley are both fully dedicated to data protection and compliance work, but for many organizations, the role of Data Protection Officer (DPO) "may just be one hat among many responsibilities for someone."Read more >>
-
GDPR Countdown 100 Days: How Box Is Preparing
Box's Vice President of Compliance, Crispen Maung, led the company's compliance efforts, working with regulators to develop binding corporate rules and drawing inspiration from industry-specific data protection protocols.Read more >>
-
Is Facebook's Phased GDPR Strategy Sufficient?
Regulatory or punitive responses from global and domestic regulators to the social media company's recent data scandals will have ripple effects across the corporate and tech sectors.Read more >>
-
Talend CIO: GDPR Is About Change Management, Not Data Use
According to Eric Johnson, GDPR is forcing U.S. companies to re-examine previously accepted standards, and organizations are starting to look to Europe as the 'high-water mark' for privacy protection.Read more >>
-
Six Weeks Before GDPR Takes Effect, One-Third of Companies May Struggle to Comply
Although companies generally recognize the costs of non-compliance, only 40% of companies globally know the location of their service providers' data centers and where data is stored.Read more >>
-
GDPR: Compliance Costs Money, Non-Compliance Also Costs Money
If nearly one-third of European Google users choose to opt out of data sharing after GDPR takes effect in May, it could impact the company's advertising revenue by approximately 2%.Read more >>