SlideShare uma empresa Scribd logo
1 de 11
Baixar para ler offline
TALEND GDPR
COMPLIANCE
BENCHMARK
SEPTEMBER 2018
33
GDRP BENCHMARK PARAMETERS
103
Companies
In the panel
Rights for Data
Access &
Portability
Worldwide study
Financial
Services
24%
Travel,
Transport,
Hospitability
24%
Retail &
consumer
goods
24%
Media,
Telco,
Utilities
28%
Europe
70%
APAC 11%
NORAM 19%
Regions Sectors
44
GDPR BENCHMARK - BACKGROUND
GDPR: The General Data Protection Regulation is a regulation in EU law on data protection and privacy for all individuals
within the European Union. The regulation, which sets a new standard for consumer rights regarding their data, came into
effect on May 25, 2018. The governing body is expected to levy significant fines to companies that do not comply with the
new regulations.
Market Compliance Research: Talend, a leader in data integration and management software, conducted market research
to assess companies’ ability to comply with the new GDPR regulation. The analysis involved the following:
• Assessing whether or not companies had updated their privacy policies to account for GDPR
• Researching whether or not companies had dedicated ways for consumers to request GDPR data (i.e., the personal
information the company has on them)
• Requesting GDPR data and assessing how quickly and thoroughly companies comply
• Requesting GDPR data in a way that may be directly accessed and reused by the individual (data portability)
The research involved 103 GDPR-relevant companies across the globe (EU companies or companies based in the U.S. or
APAC that conduct business in Europe) from a range of industries (Retail, High-Tech, Media, Transport/Travel/Hospitality,
Utilities/Telco, Public Sector, Finance)
55
SURVEY HIGHLIGHTS
Policies are defined…
98%HAVE UPDATED THEIR
PRIVACY POLICIES FOR
GDPR
70%FAILED TO PROVIDE THE
DATA REQUESTED
IN 30 DAYS !
21 days
AVG TIME IT TOOK
COMPLIANT COMPANIES
TO RESPOND
But are not enforced… or poorly delivered
66
GDPR COMPLIANCE - REGIONAL BREAKDOWN
Almost
90%
FRENCH AND SOUTHERN
EUROPEAN COMPANIES
HAD THE HIGHEST FAILURE
RATE OF ANY REGION
35%
OF EUROPEAN
COMPANIES PASSED
50%OF NON-EUROPEAN
COMPANIES PASSED
EU-based companies were less likely to comply
to GDPR than companies outside the EU
Vs
77
GDPR COMPLIANCE - INDUSTRY BREAKDOWN
47% TRAVEL/TRANSPORTATION HOSPITALITY
24% RETAILERS
50% FINANCIAL SERVICES
COMPLIANCE
FAILURE
WHILE MOST INDUSTRIES ARE DOING A POOR
JOB OF COMPLYING TO GDPR, RETAILERS ARE BY
FAR THE WORST OFFENDERS
40% MEDIA/TELCO/UTILITIES
88
GDPR COMPLIANCE – COMPLIANT COMPANIES
30%PROVIDED GDPR
DATA UPON
REQUEST
WITHIN 30 DAYS
21THE AVG NUMBER OF DAYS
IT TOOK COMPLIANT
COMPANIES TO RESPOND
6%THE PERCENTAGE OF
COMPLIANT COMPANIES
THAT ASKED FOR AN
EXTENSION* TO COMPLY
*Allowed under article 12.3 of GDPR
22%THE PERCENTAGE OF
COMPANIES THAT
RESPONDED IN A 24HRS
65%THE PERCENTAGE OF
COMPANIES THAT
ANSWERED IN 10+ DAYS
99
ADDITIONAL
EXPERIENCES
• 7% of companies mistakenly assumed we were asking
to be forgotten (half of them were hospitality leaders)
• 4 companies actually deleted our account and data
without notice
• Some companies asked for a range of personal data
before beginning our request (ID, loyalty number,
birthday, data of transactions…) and then still didn’t
comply
• Virtually every company failed to fulfill our request for
data portability
• 4 companies asked “what do you mean by personal
data”?
• A leading global firm in the financial sector fulfilled our
request by sharing the data they held on us through
printed pages that they physically delivered through a
secure mail courier.
• Only a few delivered a 1-click memorable customer
experience, including Spotify (Sweden), N26 (Germany),
Garmin (US), and Next (Germany). They offered a clear
explanation of their usage of our personal data, direct
access to our data via a portal, and data portability.
1010
THE ROAD TO
COMPLIANCE:
WHY DO
COMPANIES FAIL?
• The majority of companies do not
adequately track personal information
• Lack accountability
• Absence of Data Privacy Owner (DPO)
• No department clearly appointed to answer
requests
• Lack data control and visibility
• Can’t identify customers: some companies
have requested personal data in order to start
processing the requests
• Can’t locate data or deleted data
• Provided incomplete data sets (siloed data)
• Lack proper processes or tools
• Need for human data integrators
• Companies are overwhelmed: fail to deliver
after the extension with article 12.3
1111
OUR KEY TAKE AWAYS
GDPR is seen as a
legal project and not
as a driver for better
customer experience,
Engagement, and
trust
LEGAL VS
CUSTOMER
How organizations
empower data
workers towards
GDPR and the
importance of having
a data owner or
controller
DATA CULTURE/
DATA OWNERSHIP
Customers data is
siloed and the
majority of
companies do not
know their customers
CUSTOMER
360°
Organizations do not
have automated
processes: GDPR is
not a one-click
process (human data
integrator)
AUTOMATION
GDPR Benhmark: 70%  of companies failing on their own GDPR compliance claims

Mais conteúdo relacionado

Mais procurados

Delivering data you can trust for data privacy
Delivering data you can trust for data privacy Delivering data you can trust for data privacy
Delivering data you can trust for data privacy
Jean-Michel Franco
 
Delivering data you can trust with Talend 2019
Delivering data you can trust with Talend 2019 Delivering data you can trust with Talend 2019
Delivering data you can trust with Talend 2019
Jean-Michel Franco
 
Evtm 281 07_bi2015_infographic_r2h
Evtm 281 07_bi2015_infographic_r2hEvtm 281 07_bi2015_infographic_r2h
Evtm 281 07_bi2015_infographic_r2h
Nadia Smith
 

Mais procurados (20)

Delivering data you can trust for data privacy
Delivering data you can trust for data privacy Delivering data you can trust for data privacy
Delivering data you can trust for data privacy
 
Delivering data governance with a Yes
Delivering data governance with a YesDelivering data governance with a Yes
Delivering data governance with a Yes
 
Big Data LDN 2017: Disruption in Data
Big Data LDN 2017: Disruption in DataBig Data LDN 2017: Disruption in Data
Big Data LDN 2017: Disruption in Data
 
Data strategy demistifying data
Data strategy demistifying dataData strategy demistifying data
Data strategy demistifying data
 
Big data engineering slideshare - v0.4
Big data engineering   slideshare - v0.4Big data engineering   slideshare - v0.4
Big data engineering slideshare - v0.4
 
Understanding the Data You Have Before Applying a Governance Strategy
Understanding the Data You Have Before Applying a Governance StrategyUnderstanding the Data You Have Before Applying a Governance Strategy
Understanding the Data You Have Before Applying a Governance Strategy
 
Slides: Achieving a “Single Source of Truth” with BI in Your Enterprise
Slides: Achieving a “Single Source of Truth” with BI in Your EnterpriseSlides: Achieving a “Single Source of Truth” with BI in Your Enterprise
Slides: Achieving a “Single Source of Truth” with BI in Your Enterprise
 
Big Data Strategy
Big Data StrategyBig Data Strategy
Big Data Strategy
 
Big Data LDN 2017: Data Governance Reimagined
Big Data LDN 2017: Data Governance ReimaginedBig Data LDN 2017: Data Governance Reimagined
Big Data LDN 2017: Data Governance Reimagined
 
Slides: Applying Artificial Intelligence (AI) in All the Right Places in the ...
Slides: Applying Artificial Intelligence (AI) in All the Right Places in the ...Slides: Applying Artificial Intelligence (AI) in All the Right Places in the ...
Slides: Applying Artificial Intelligence (AI) in All the Right Places in the ...
 
Delivering data you can trust with Talend 2019
Delivering data you can trust with Talend 2019 Delivering data you can trust with Talend 2019
Delivering data you can trust with Talend 2019
 
Big Data SurVey - IOUG - 2013 - 594292
Big Data SurVey - IOUG - 2013 - 594292Big Data SurVey - IOUG - 2013 - 594292
Big Data SurVey - IOUG - 2013 - 594292
 
Big Data Strategies
Big Data StrategiesBig Data Strategies
Big Data Strategies
 
You Can’t Have Best in Class Governance Without Best in Class Data Lineage
You Can’t Have Best in Class Governance Without Best in Class Data LineageYou Can’t Have Best in Class Governance Without Best in Class Data Lineage
You Can’t Have Best in Class Governance Without Best in Class Data Lineage
 
Slides: Data Governance Reality Check
Slides: Data Governance Reality CheckSlides: Data Governance Reality Check
Slides: Data Governance Reality Check
 
Data Catalog as the Platform for Data Intelligence
Data Catalog as the Platform for Data IntelligenceData Catalog as the Platform for Data Intelligence
Data Catalog as the Platform for Data Intelligence
 
Predictive vs Prescriptive Analytics
Predictive vs Prescriptive AnalyticsPredictive vs Prescriptive Analytics
Predictive vs Prescriptive Analytics
 
Evtm 281 07_bi2015_infographic_r2h
Evtm 281 07_bi2015_infographic_r2hEvtm 281 07_bi2015_infographic_r2h
Evtm 281 07_bi2015_infographic_r2h
 
Navigating the Complex World of Compliance Guidelines
Navigating the Complex World of Compliance GuidelinesNavigating the Complex World of Compliance Guidelines
Navigating the Complex World of Compliance Guidelines
 
New Strategies for More Effective Remote/Branch Office Data Protection
New Strategies for More Effective Remote/Branch Office Data ProtectionNew Strategies for More Effective Remote/Branch Office Data Protection
New Strategies for More Effective Remote/Branch Office Data Protection
 

Semelhante a GDPR Benhmark: 70% of companies failing on their own GDPR compliance claims

Running Head THE IMPACT OF GDPR ON GLOBAL IT POLICIES1THE IMPA.docx
Running Head THE IMPACT OF GDPR ON GLOBAL IT POLICIES1THE IMPA.docxRunning Head THE IMPACT OF GDPR ON GLOBAL IT POLICIES1THE IMPA.docx
Running Head THE IMPACT OF GDPR ON GLOBAL IT POLICIES1THE IMPA.docx
jeanettehully
 

Semelhante a GDPR Benhmark: 70% of companies failing on their own GDPR compliance claims (20)

GDPR & Data Privacy Guide - Free Download
GDPR & Data Privacy Guide - Free DownloadGDPR & Data Privacy Guide - Free Download
GDPR & Data Privacy Guide - Free Download
 
Pwc gdpr survey 2018
Pwc gdpr survey 2018Pwc gdpr survey 2018
Pwc gdpr survey 2018
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
 
GDPR: A Threat or Opportunity? www.normanbroadbent.
GDPR: A Threat or Opportunity? www.normanbroadbent.GDPR: A Threat or Opportunity? www.normanbroadbent.
GDPR: A Threat or Opportunity? www.normanbroadbent.
 
Janrain Identity Cloud GDPR Assessment Kit
Janrain Identity Cloud GDPR Assessment Kit Janrain Identity Cloud GDPR Assessment Kit
Janrain Identity Cloud GDPR Assessment Kit
 
Data opportunities mini whitepaper
Data opportunities mini whitepaperData opportunities mini whitepaper
Data opportunities mini whitepaper
 
Security, GDRP, and IT outsourcing: How to get it right
Security, GDRP, and IT outsourcing: How to get it rightSecurity, GDRP, and IT outsourcing: How to get it right
Security, GDRP, and IT outsourcing: How to get it right
 
GDPR: Data Privacy in the New
GDPR: Data Privacy in the NewGDPR: Data Privacy in the New
GDPR: Data Privacy in the New
 
Global Threats| Cybersecurity|
Global Threats| Cybersecurity| Global Threats| Cybersecurity|
Global Threats| Cybersecurity|
 
GDPR for dummies
GDPR for dummies  GDPR for dummies
GDPR for dummies
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and Privacy
 
Privacy 2020: Recap & Predictions
Privacy 2020: Recap & PredictionsPrivacy 2020: Recap & Predictions
Privacy 2020: Recap & Predictions
 
How Insurers Fueled Transformation During a Pandemic
How Insurers Fueled Transformation During a PandemicHow Insurers Fueled Transformation During a Pandemic
How Insurers Fueled Transformation During a Pandemic
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
U.S. Data Privacy Report - Patchy preparation for GDPR shows U.S. businesses ...
U.S. Data Privacy Report - Patchy preparation for GDPR shows U.S. businesses ...U.S. Data Privacy Report - Patchy preparation for GDPR shows U.S. businesses ...
U.S. Data Privacy Report - Patchy preparation for GDPR shows U.S. businesses ...
 
GDPR (En) JM Tyszka
GDPR (En)  JM TyszkaGDPR (En)  JM Tyszka
GDPR (En) JM Tyszka
 
Snow SAM presentation March 2018
Snow SAM presentation March 2018Snow SAM presentation March 2018
Snow SAM presentation March 2018
 
EU GDPR: What You Really Need to Know
EU GDPR: What You Really Need to Know EU GDPR: What You Really Need to Know
EU GDPR: What You Really Need to Know
 
Top 10 GDPR solution providers 2020
Top 10 GDPR solution providers 2020Top 10 GDPR solution providers 2020
Top 10 GDPR solution providers 2020
 
Running Head THE IMPACT OF GDPR ON GLOBAL IT POLICIES1THE IMPA.docx
Running Head THE IMPACT OF GDPR ON GLOBAL IT POLICIES1THE IMPA.docxRunning Head THE IMPACT OF GDPR ON GLOBAL IT POLICIES1THE IMPA.docx
Running Head THE IMPACT OF GDPR ON GLOBAL IT POLICIES1THE IMPA.docx
 

Mais de Jean-Michel Franco

Mais de Jean-Michel Franco (20)

A commonsense approach to data
A commonsense approach to dataA commonsense approach to data
A commonsense approach to data
 
Prendre la data par le bon sens
Prendre la data par le bon sensPrendre la data par le bon sens
Prendre la data par le bon sens
 
Reveal the Intelligence in your Data with Talend Data Fabric
Reveal the Intelligence in your Data with Talend Data FabricReveal the Intelligence in your Data with Talend Data Fabric
Reveal the Intelligence in your Data with Talend Data Fabric
 
Dévoilez l'essentiel de vos données avec Talend
Dévoilez l'essentiel de vos données avec TalendDévoilez l'essentiel de vos données avec Talend
Dévoilez l'essentiel de vos données avec Talend
 
Libérez vos données avec un catalogue de données
Libérez vos données avec un catalogue de donnéesLibérez vos données avec un catalogue de données
Libérez vos données avec un catalogue de données
 
Make Data Better Together
Make Data Better Together Make Data Better Together
Make Data Better Together
 
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
 
Créer la vue 360° des employés
Créer la vue 360° des employés Créer la vue 360° des employés
Créer la vue 360° des employés
 
Are Your Data Ready for GDPR? (with MAPR and Talend)
Are Your Data Ready for GDPR? (with MAPR and Talend)Are Your Data Ready for GDPR? (with MAPR and Talend)
Are Your Data Ready for GDPR? (with MAPR and Talend)
 
Etapes Pratiques Pour La Mise En Conformité Au GDPR avec Talend
Etapes Pratiques Pour La Mise En Conformité Au GDPR avec TalendEtapes Pratiques Pour La Mise En Conformité Au GDPR avec Talend
Etapes Pratiques Pour La Mise En Conformité Au GDPR avec Talend
 
Practical steps to GDPR compliance
Practical steps to GDPR compliance Practical steps to GDPR compliance
Practical steps to GDPR compliance
 
Présentation de Talend Winter 2017
Présentation de Talend Winter 2017 Présentation de Talend Winter 2017
Présentation de Talend Winter 2017
 
Talend winter 2017 overview webinar
Talend winter 2017 overview webinarTalend winter 2017 overview webinar
Talend winter 2017 overview webinar
 
Self-service data and data governance: friends or foes?
Self-service data and data governance: friends or foes?Self-service data and data governance: friends or foes?
Self-service data and data governance: friends or foes?
 
Etablir une collaboration durable entre les équipes informatiques et les méti...
Etablir une collaboration durable entre les équipes informatiques et les méti...Etablir une collaboration durable entre les équipes informatiques et les méti...
Etablir une collaboration durable entre les équipes informatiques et les méti...
 
Big Data : au delà du proof of concept et de l'expérimentation (Matinale busi...
Big Data : au delà du proof of concept et de l'expérimentation (Matinale busi...Big Data : au delà du proof of concept et de l'expérimentation (Matinale busi...
Big Data : au delà du proof of concept et de l'expérimentation (Matinale busi...
 
Piloter l'entreprise par ses données (présentation Talend pour la matinale ED...
Piloter l'entreprise par ses données (présentation Talend pour la matinale ED...Piloter l'entreprise par ses données (présentation Talend pour la matinale ED...
Piloter l'entreprise par ses données (présentation Talend pour la matinale ED...
 
Talend Summer 16 (version française) : la Préparation des Données à la Portée...
Talend Summer 16 (version française) : la Préparation des Données à la Portée...Talend Summer 16 (version française) : la Préparation des Données à la Portée...
Talend Summer 16 (version française) : la Préparation des Données à la Portée...
 
Talend Summer 16 launch présentation: Open Data Preparation for Everyone
Talend Summer 16 launch présentation: Open Data Preparation for Everyone Talend Summer 16 launch présentation: Open Data Preparation for Everyone
Talend Summer 16 launch présentation: Open Data Preparation for Everyone
 
Bi et partage des données financières en libre -service
Bi et partage des données financières en libre -serviceBi et partage des données financières en libre -service
Bi et partage des données financières en libre -service
 

Último

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Victor Rentea
 

Último (20)

TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
Vector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxVector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptx
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering Developers
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 

GDPR Benhmark: 70% of companies failing on their own GDPR compliance claims

  • 2. 33 GDRP BENCHMARK PARAMETERS 103 Companies In the panel Rights for Data Access & Portability Worldwide study Financial Services 24% Travel, Transport, Hospitability 24% Retail & consumer goods 24% Media, Telco, Utilities 28% Europe 70% APAC 11% NORAM 19% Regions Sectors
  • 3. 44 GDPR BENCHMARK - BACKGROUND GDPR: The General Data Protection Regulation is a regulation in EU law on data protection and privacy for all individuals within the European Union. The regulation, which sets a new standard for consumer rights regarding their data, came into effect on May 25, 2018. The governing body is expected to levy significant fines to companies that do not comply with the new regulations. Market Compliance Research: Talend, a leader in data integration and management software, conducted market research to assess companies’ ability to comply with the new GDPR regulation. The analysis involved the following: • Assessing whether or not companies had updated their privacy policies to account for GDPR • Researching whether or not companies had dedicated ways for consumers to request GDPR data (i.e., the personal information the company has on them) • Requesting GDPR data and assessing how quickly and thoroughly companies comply • Requesting GDPR data in a way that may be directly accessed and reused by the individual (data portability) The research involved 103 GDPR-relevant companies across the globe (EU companies or companies based in the U.S. or APAC that conduct business in Europe) from a range of industries (Retail, High-Tech, Media, Transport/Travel/Hospitality, Utilities/Telco, Public Sector, Finance)
  • 4. 55 SURVEY HIGHLIGHTS Policies are defined… 98%HAVE UPDATED THEIR PRIVACY POLICIES FOR GDPR 70%FAILED TO PROVIDE THE DATA REQUESTED IN 30 DAYS ! 21 days AVG TIME IT TOOK COMPLIANT COMPANIES TO RESPOND But are not enforced… or poorly delivered
  • 5. 66 GDPR COMPLIANCE - REGIONAL BREAKDOWN Almost 90% FRENCH AND SOUTHERN EUROPEAN COMPANIES HAD THE HIGHEST FAILURE RATE OF ANY REGION 35% OF EUROPEAN COMPANIES PASSED 50%OF NON-EUROPEAN COMPANIES PASSED EU-based companies were less likely to comply to GDPR than companies outside the EU Vs
  • 6. 77 GDPR COMPLIANCE - INDUSTRY BREAKDOWN 47% TRAVEL/TRANSPORTATION HOSPITALITY 24% RETAILERS 50% FINANCIAL SERVICES COMPLIANCE FAILURE WHILE MOST INDUSTRIES ARE DOING A POOR JOB OF COMPLYING TO GDPR, RETAILERS ARE BY FAR THE WORST OFFENDERS 40% MEDIA/TELCO/UTILITIES
  • 7. 88 GDPR COMPLIANCE – COMPLIANT COMPANIES 30%PROVIDED GDPR DATA UPON REQUEST WITHIN 30 DAYS 21THE AVG NUMBER OF DAYS IT TOOK COMPLIANT COMPANIES TO RESPOND 6%THE PERCENTAGE OF COMPLIANT COMPANIES THAT ASKED FOR AN EXTENSION* TO COMPLY *Allowed under article 12.3 of GDPR 22%THE PERCENTAGE OF COMPANIES THAT RESPONDED IN A 24HRS 65%THE PERCENTAGE OF COMPANIES THAT ANSWERED IN 10+ DAYS
  • 8. 99 ADDITIONAL EXPERIENCES • 7% of companies mistakenly assumed we were asking to be forgotten (half of them were hospitality leaders) • 4 companies actually deleted our account and data without notice • Some companies asked for a range of personal data before beginning our request (ID, loyalty number, birthday, data of transactions…) and then still didn’t comply • Virtually every company failed to fulfill our request for data portability • 4 companies asked “what do you mean by personal data”? • A leading global firm in the financial sector fulfilled our request by sharing the data they held on us through printed pages that they physically delivered through a secure mail courier. • Only a few delivered a 1-click memorable customer experience, including Spotify (Sweden), N26 (Germany), Garmin (US), and Next (Germany). They offered a clear explanation of their usage of our personal data, direct access to our data via a portal, and data portability.
  • 9. 1010 THE ROAD TO COMPLIANCE: WHY DO COMPANIES FAIL? • The majority of companies do not adequately track personal information • Lack accountability • Absence of Data Privacy Owner (DPO) • No department clearly appointed to answer requests • Lack data control and visibility • Can’t identify customers: some companies have requested personal data in order to start processing the requests • Can’t locate data or deleted data • Provided incomplete data sets (siloed data) • Lack proper processes or tools • Need for human data integrators • Companies are overwhelmed: fail to deliver after the extension with article 12.3
  • 10. 1111 OUR KEY TAKE AWAYS GDPR is seen as a legal project and not as a driver for better customer experience, Engagement, and trust LEGAL VS CUSTOMER How organizations empower data workers towards GDPR and the importance of having a data owner or controller DATA CULTURE/ DATA OWNERSHIP Customers data is siloed and the majority of companies do not know their customers CUSTOMER 360° Organizations do not have automated processes: GDPR is not a one-click process (human data integrator) AUTOMATION