On the 25th of May 2018, the General Data Protection Regulation (GDPR) emerged, legally preventing marketers and companies from collecting and storing EU customer data without "explicit" consent.
GDPR presented a significant challenge to many organisations who were unprepared to transform their entire data strategy in time for the deadline. According to research by Dimensional Research and TrustArc, a few weeks after the legislation went into effect, only 20% of companies believed that they were "fully compliant," though a little over 50% were implementing new strategies.
So, if so many people are bewildered by GDPR, where's the evidence that businesses are taking it seriously, and why haven't we seen more fines being handed out? Well, the simple answer is that the storms are coming. Litigation has already begun with larger companies like Google and Facebook - businesses potentially facing fines worth billions of dollars. At the same time, various crowdsourcing initiatives are creating their own privacy class actions. It seems that GDPR could be as serious as we thought after all.
How Is the World Responding to GDPR?
Though GDPR was created explicitly for the EU market, many companies have decided to apply the rules on a global basis. Some world-wide companies feel that GDPR standards are a great way to boost their reputation from a PR perspective, while others are simply concerned about protecting conversations with EU customers.
From a general perspective, the main thing that's changing right now is the world's knowledge of privacy and security. Even in the lead-up to GDPR, many companies had very little knowledge of what they were preparing for, and how the regulations would affect them. Consumers were even less informed, with studies suggesting that 91% of Americans would consent to conditions without reading them first.
By forcing people to re-think about the way information is shared and stored online, GDPR has had at least one positive impact on the digital world.
How Are People Dealing with GDPR?
The biggest impact that GDPR has had is on the unprecedented levels of awareness and transparency in the industry. The purpose of the regulation was to ensure that people had more control over their data, and in that regard, it's been successful. More people than ever before are making complaints regarding privacy according to the latest reports.
The CNIL agency in France recently reported a 64% increase in complaints, which it believes shows how much the EU customers have seized management of their rights with GDPR. Additionally, the UK Information Commissioner Office reported that complaints had doubled since the new legislation had arrived.
So, what are businesses doing about this change? Not much. Recently, studies found that one in four companies have yet to fully implement a GDPR strategy, months after the deadline passed.
How are Comms Companies Responding to GDPR?
The biggest issue that most businesses have with GDPR is that they don't fully understand how, where, and how much user data is being stored. Usually, information gets stored and siloed in systems that don't connect, leaving businesses to search endlessly for the right information.
The good news is that some leading communication companies are taking the initiative with new campaigns and data protection programmes. RingCentral recently updated their data protection strategy with new protection standards, third-party audits and certifications. Similarly, companies like Avaya are looking for ways to help their channel partners meet their legal obligations regarding GDPR.
One of the Comms companies most prepared to help organisations adapt to GDPR is Tollring. Not only has the company's strategy for preserving private data been a strong part of their product portfolio for years, but the organisation also has various certifications in place to ensure security. Tollring even provides call analytics and call recording solutions that are intended to give businesses more control over the information that they're storing, so that they can adhere to the rules and regulations of GDPR, including explicit consent and right to be forgotten.




