Why multinationals prefer to take GDPR as baseline for global compliance?


Rolling out General Data Protection Regulation (GDPR) compliance framework as a standard can be operationally simpler for global organisations and may also help to reduce the level of privacy risk, including in non-EU countries, said an industry expert.
“The GDPR’s strict requirements on data breach handling are well known, in particular, the requirement to report personal data breaches to regulators within 72 hours of becoming aware (unless the breach is unlikely to result in a risk). Depending on the level of risk, breaches may also need to be notified to individuals,” Joanna de Fonseka, Senior Associate for Technology/Commercial at Baker McKenzie Habib Al Mulla, told TechRadar Middle East.
GDPR was introduced in May 2018 and it has had a significant impact on personal data protection.
According to law firm DLA Piper, GDPR has led to over 160,000 data breach notifications across Europe and has imposed about $126 million in fines under the GDPR regime till January for a wide range of GDPR infringements, not just for data breaches.
France, Germany and Austria top the rankings for the total value of GDPR fines imposed with just over $5m, $26.80m and $19.7m respectively.
The Netherlands, Germany and the UK topped the table for the number of data breaches notified to regulators with 40,647, 37,636 and 22,181 respectively.
The biggest penalty under GDPR to date was a fine of $55m imposed on Google.
Moreover, Fonseka said that many multinational companies are increasingly choosing to follow stricter data protection standards, such as the GDPR, globally.
From a UAE perspective, she said that there is currently no equivalent requirement but companies may still need to comply with the GDPR breach reporting obligations if their data processing activities are subject to the GDPR, due to its broad territorial scope.
UAE data protection law soon
UAE’s regulatory authorities are expected to announce more details about its Personal Data Protection Law soon.
“Part of the strategy is that data privacy is crucial to the cyber and the UAE is regulating and drafting a data protection law. We will look at the best performing practices performed worldwide; GDPR will be one of the inputs to it. We want to make sure that whatever regulations are put, are easy to be implemented across different sectors,” Mohammad Al Zarooni, Director of Policies and Programs Department at Telecommunications Regulatory Authority (TRA) of the UAE, told TechRadar Middle East, recently.
However, Fonseka said that UAE companies who work with EU customers will still need to comply in practice even if they themselves are not directly subject to the GDPR. An EU customer will normally seek to flow down certain GDPR obligations contractually to its non-EU service providers, including in relation to breach reporting.
“There are still significant reputational advantages of responsible information handling. That might include implementing staff training programmes, negotiating robust data processing terms with vendors, and following good information security practices, including breach reporting where appropriate.
“Handling personal data responsibly can help promote trust and confidence in a company’s brand – particularly for consumer-facing organisations,” she said.
However, she said that the GDPR has extra-territorial application and companies outside the EU will still need to comply if they offer goods or services to individuals in the EU or monitor the behaviour of individuals in the EU (for example, if they sell their products to EU consumers through a website targeted at the EU market).
“A UAE company could therefore still be subject to GDPR fines if its activities are caught by the GDPR and it does not comply,” she said.
When asked whether a common global data privacy policy is better or individual country-wise, she said and added that there is no doubt that global compliance is a challenge – new privacy laws continue to emerge around the world and their requirements do not always align.
“GDPR is still one of the strictest standards globally; we often find that multinationals prefer to take the GDPR as their baseline for global compliance. Operationally, this is often the simplest approach and there is likely to be a reputational advantage as well,” she said.
Rolling out General Data Protection Regulation (GDPR) compliance framework as a standard can be operationally simpler for global organisations and may also help to reduce the level of privacy risk, including in non-EU countries, said an industry expert. “The GDPR’s strict requirements on data breach handling are well known, in…
Recent Posts
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010