Skip to main content

On-demand webinar coming soon...

Blog

How 4 years of GDPR has changed the privacy landscape

GDPR turns four this year. What has this landmark legislation taught us, and what does the future look like?

Alexis Kateifides, Senior Center of Excellence Counsel
May 25, 2022

 

A blue and purple gradient background image.

The introduction of the GDPR marked the dawning of a new age in privacy and data protection legislation, opening the door to a growing global regulatory landscape.  

The GDPR forced organizations to start their data protection journeys to keep up with the evolving world of data privacy. With enforcement actions, new guidelines, international data transfers, and global development of privacy laws and regulations, organizations had to develop data policies that could keep up with the rapid pace of these changes.

So, what have we learned over the last four years, and what’s on the horizon?

Data transfers in the spotlight

Like the EU Data Protection Directive before it, one of the goals of the GDPR is to ensure the protection of EU citizens’ data when it’s transferred outside of the EU. And like Schrems I, the CJEU’s decision in Schrems II brought with it new considerations for organizations. It’s been almost two years since that decision but in the last year the European Data Protection Board (EDPB) also issued its final version of recommendations of supplementary measures, and the European Commission adopted and released its new Standard Contractual Clauses.  

With the release of these documents, organizations have been continuing to prioritize the steps laid out by the EDPB, working both internally and with customers, partners, and vendors to ensure compliance. 

The work is against an ever evolving backdrop. Data protection authorities (DPAs) are highlighting their Schrems II compliance expectations through investigations and enforcement actions. And the recent announcement of an agreement in principle for a new Trans-Atlantic Data Privacy Framework may provide further certainty for privacy professionals on EU-US data transfers. What is certain is that EU data transfers will continue to rank highly on companies’ and regulators’ lists of priorities for the year to come.  

Operationalizing GDPR through guidance

The GDPR’s requirements are laid out across 11 chapters and 99 articles. To help organizations comply, the EDPB and national DPAs release guidance on key compliance areas.  

In the last year, the EDPB has updated its former guidance on the concepts of controllers and processors, to take account of the dynamic relationships and roles in today’s modern world. It also adopted new guidance to help businesses handle data breaches, and the types of factors to consider during risk assessments. National DPAs weighed in on issues like Privacy by Design and artificial intelligence.

Down the road, we can expect to see finalized guidance on data subject rights as well as other topics, like legitimate interests as a legal basis. 

GDPR in a global context

Since agreement on the GDPR was reached in 2016, there has been a proliferation of new privacy laws around the world. The influence of the GDPR is seen within these laws, with many taking a similar approach to regulating data protection and privacy. 

In the US, Utah and Connecticut recently became the fourth and fifth states respectively to pass comprehensive privacy laws in the absence of a federal law. Quebec modernized its law through Bill 64. In Brazil, the LGPD’s enforcement provisions took effect. China’s PIPL and DSL were finalized and entered into force, as did Japan’s APPI amendments. Federal laws were also passed in Saudi Arabia and the UAE, whilst South Africa, Rwanda, and Botswana all had laws take effect. The list can go on and on!  

The commonalities in requirements are many. However, as they say, the devil is in the detail, and mapping between these requirements remains an important task for organizations. 

And there are no signs of slowing down either. The UK announced a new Data Reform Bill. Israel is looking to amend its four-decade-old law. Thailand’s first Data Protection Act comes into force next month, while India’s debate on its own law continues. For businesses operating globally, staying agile is important as ever. 

More data laws are coming

The EU’s Digital and Data Strategy is on the move. The AI Act, the Data Act, the DMA, the DSA, the DGA. Running alongside is an increased desire to enhance regulation of cybersecurity, and that’s where we see proposals for NIS2 and Digital Operational Resilience Act (DORA). And though initially proposed in 2017, agreement on the proposed ePrivacy Regulation seems to also be edging closer.  

These are some of the new abbreviations privacy professionals are including when speaking on issues of data protection and privacy. As more laws regulate both the use of personal and non-personal data, as technology continues to evolve, and with data being an increasingly valuable resource, organizations are thinking holistically about their data governance programs, to not only comply with these laws, but drive business value. 

Industry experts reflect on 4 years of GDPR

Take a look at what privacy leaders across industries have to say about the past four years of GDPR and where the future of data privacy looks to go.

 

 

On-demand webinar coming soon...

 

Looking back on the past 4 years of GDPR

Learn more about what GDPR has brought about for Europe and the rest of the world at the webinar “4 Years of GDPR: Birthday reflections and wishes”. A panel of industry experts and privacy leaders will reflect on how the privacy and data protection landscape has changed since 2018, and look to what the future holds in store. Register for the webinar here.

 


You may also like

eBook

Privacy Management

Understanding data transfers under the GDPR ebook

In the ebook, we delve into the fallout from Schrems II and explore how organizations based in Europe can best navigate international data transfers under the GDPR.

June 05, 2024

Learn more

Webinar

Privacy Management

Navigating data privacy in 2024: Global regulatory updates & compliance strategies

Join our webinar for a comprehensive overview of the latest global data privacy regulations and updates impacting businesses in 2024 and how to prepare.

March 20, 2024

Learn more

Infographic

Privacy Management

OneTrust announces partnership with Europrivacy

Learn how OneTrust and Europrivacy's partnership can help your organization achieve GDPR compliance and build trust with your customers.

December 06, 2023

Learn more

Webinar

Technology Risk & Compliance

Demonstrating GDPR compliance with Europrivacy criteria: The European Data Protection Seal

Join our webinar to learn more about the European Data Protection Seal and to find out what the key advantages of getting certified.

November 30, 2023

Learn more

Webinar

Privacy Management

Revisiting the ICO Data Protection Practitioner's Conference: Addressing your top challenges

Join OneTrust and KPMG UK to discuss the challenges of employee SARs, managing your breach response with third parties, and incident management.

October 25, 2023

Learn more

Infographic

Privacy & Data Governance

Understanding the EU Data Boundary

Download our free infographic and get the information you need to understand the EU Data Boundary and how to properly handle data in the European Union.

September 22, 2023

Learn more

Webinar

Privacy Management

Privacy in practice: PIA & DPIA with PA Consulting

Join OneTrust and PA Consulting as we discuss what makes an effective PIA, best practices, and the benefits of automation.

September 21, 2023

Learn more

Webinar

Privacy & Data Governance

Privacy in practice for data mapping: With PA Consulting and Syngenta

Join OneTrust and panelists from PA Consulting and Syngenta as we explore practical ways to build an effective data mapping program, best practices, and the need for automation.

September 14, 2023

Learn more

Webinar

Governance & Policy Management

EU-US DPF: What next for UK businesses?

Join our expert webinar as we discuss the upcoming UK-US DPF Extension and what UK businesses need to prepare to become DPF-certified.

September 06, 2023

Learn more

Webinar

Privacy Management

Unpacking the EU-US DPF

In this webinar, we cover the new EU-US Data Privacy Framework (EU-US DPF) and what privacy program managers need to know for post-Schrems II data transfers.

June 28, 2023

Learn more

Infographic

Privacy & Data Governance

The 3 priorities of the French DPO: Gain visibility, take action, automate

Download our infographic and learn about the 3 priorities of the French DPO.

May 30, 2023

Learn more

Webinar

Privacy Management

GDPR turns 5: Celebrating data protection

Northern Europe panel - Join our panel of experts as they recap the GDPR, its key concepts, and what it means for organizations and compliance. 

May 25, 2023

Learn more

Webinar

Privacy Management

Global Panel — GDPR & Tech: Key considerations of Privacy by Design and AI in tech

Join our panel of experts as we discuss the impact GDPR had on the tech industry during the past five years, the importance of privacy by design, and what to expect with AI and regulation.

May 25, 2023

Learn more

Webinar

Privacy Management

5 years of GDPR: Milestones, challenges, and opportunities

Eastern European panel - Watch our webinar as we look back on 5 years of the GDPR, AI, and their impact on Europe, the world, and your organization.

May 24, 2023

Learn more

Webinar

Privacy & Data Governance

Global Panel — GDPR & Healthcare: current regulatory guidance and enforcement

In this live webinar, our expert panel examines the first five years of the GDPR, how it changed the healthcare industry, and the changing global regulatory landscape.

May 24, 2023

Learn more

Webinar

Privacy Management

Global Panel — GDPR & Retail: building customer loyalty and trust with consent and privacy

Join us for a live panel as we discuss GDPR's impact on the retail and eCommerce industry and how companies evolved to meet the global regulatory landscape.

May 23, 2023

Learn more

eBook

Privacy Management

Getting started with GDPR compliance

This eBook covers the fundamental information you need to know in order to get your GDPR compliance program started and how OneTrust helps. 

May 23, 2023

Learn more

Infographic

Privacy Management

Comparing the FADP, Revised FADP, and the GDPR

Download our infographic to see how the Revised FADP compares with its original version and the GDPR.

May 23, 2023

Learn more

Webinar

Privacy Management

Global Panel — GDPR & Finance: Staying ahead of the regulatory and cyber landscape

How has the GDPR affected the financial industry? Join our live panel as we examine how it companies evolved to meet the regulatory challenges and what can be done to stay ahead of the curve.

May 22, 2023

Learn more

Webinar

Privacy Automation

OneTrust and Deloitte UK - Data transfers: Assessments & safeguards

OneTrust's Center of Excellence and Deloitte UK will discuss data transfers and GDPR compliance, covering the UK stance, ICO/EDBP guidance, and more.

April 04, 2023 1 min read

Learn more

eBook

Privacy Management

The 3 Priorities for DPOs in France: Gain Visibility, Take Action, Automate eBook | Resources | OneTrust

French DPOs should take three priorities into account when building their data protection and compliance programs and processes in 2023.

February 21, 2023

Learn more

Webinar

Privacy & Data Governance

Data Protection in Financial Services Week: Government keynote and international transfers

This session will examine some key issues and recent developments on international data transfers with contributions from key EU, UK, and US regulators.

February 07, 2023

Learn more

Webinar

Consent & Preferences

Belgian DPA approves TCF action plan: Where we go from here

Belgian DPA approves IAB Europe’s action plan to correct its Transparency & Consent Framework (TCF) violations of the GDPR.

January 12, 2023

Learn more

Webinar

Privacy & Data Governance

Keeping pace with the changing regulatory landscape: UK And EU updates webinar

Learn more about the privacy updates for the UK and the EU, what to expect in the coming year, and how to manage regulatory change.

August 15, 2022

Learn more

Webinar

Ethics & Compliance

GDPR and the EU Whistleblower Protection Directive webinar

Join this webinar to learn how to review your whistleblowing processes to comply with the EU Whistleblower Protection Directive, the GDPR and others.

July 06, 2022

Learn more

Webinar

Privacy & Data Governance

4 years of GDPR

Watch our webinar on the last 4 years of GDPR compliance and trends for the future.

May 05, 2022

Learn more

Webinar

Privacy Management

Privacy rights poland: Enhance Your DSAR process with automation, discovery & redaction

As part of our Privacy Automation webinar series, we discuss why it's important to automate DSAR fulfillment and the latest regulatory trends. 

April 03, 2022

Learn more

Webinar

Privacy & Data Governance

Know your laws: Comparing CCPA & CPRA vs. GDPR

Watch this free webinar and see how the CCPA and CPRA compare with the GDPR.

January 04, 2022

Learn more

Checklist

Privacy & Data Governance

Transfer Impact Assessment (TIA) checklist

This Transfer Impact Assessment checklist provides an overview of the key steps you can take as you perform a TIA.

December 01, 2021

Learn more

Infographic

GDPR's 8 fundamental data subject rights

Download our GDPR's 8 Fundamental Data Subject Rights infographic and learn more about the individual rights guaranteed under the EU's major privacy law. 

August 27, 2021

Learn more

eBook

Privacy & Data Governance

The ultimate guide to GDPR compliance

Download this eBook to get an ultimate guide to understanding the GDPR and implementing steps towards compliance.

August 26, 2021

Learn more

eBook

Privacy & Data Governance

The Ultimate PIA and DPIA eBook

Download The Ultimate PIA and DPIA eBook to understand, develop, and implement an efficient PIA and DPIA process for your privacy program.

July 22, 2021

Learn more

eBook

Privacy & Data Governance

10 steps to meeting the GDPR Article 30 requirement

Download this eBook and learn how to leverage data mapping for your GDPR Article 30 compliance program. 

July 22, 2021

Learn more

Checklist

Privacy & Data Governance

GDPR compliance checklist

Download our GDPR compliance checklist for recommendations on improving your organization's privacy program. 

June 11, 2021

Learn more