Two thirds of companies fail to meet GDPR response deadlines

Six months on from the introduction of the General Data Protection Regulation (GDPR), more than two thirds of organisations are responding to customer data requests late, according to research by Deloitte which warns that the volume of data enquiries is set to increase

The survey of 1,100 organisations found that customer data requests, such as opting out of direct marketing and the right to erasure, are typically dealt with beyond the set timeframe of one month.

Since May, 70% of those polled have seen an increase in staff who are either partly or fully focussed on GDPR compliance. For many, this included the recruitment of a dedicated data protection officer (DPO). Of the countries surveyed, the UK leads in this respect, with 92% of respondents assigning a DPO.

A third (33%) continue to invest in their privacy practices, including in technology and talent.

Peter Gooch, cyber risk partner at Deloitte, said: ‘Six months in, what is clear is that some organisations are still grappling with the implementation of their GDPR compliance. Given the complexities of such programmes and increased consumer awareness of such requests, we would expect some bedding-in time.

‘However, our research found that a fifth of organisations only aimed for bare minimum compliance back in May, which may be indicative of the delays some customers are currently experiencing.’

Deloitte’s research found that overall 92% of organisations felt confident in demonstrating their ability to conform in the long-term.

‘In the immediate term, though, many will need to address today’s pressure to respond to data requests. This is particularly the case as online tools, enabling consumers to make mass data requests, increase in popularity,’ Gooch warned.

Report by Pat Sweet

Average: 4 (1 vote)