Skip to content
Law Society of Scotland
Search
Find a Solicitor
Contact us
About us
Sign in
Search
Find a Solicitor
Contact us
About us
Sign in
  • For members

    • For members

    • CPD & Training

    • Membership and fees

    • Rules and guidance

    • Regulation and compliance

    • Journal

    • Business support

    • Career growth

    • Member benefits

    • Professional support

    • Lawscot Wellbeing

    • Lawscot Sustainability

  • News and events

    • News and events

    • Law Society news

    • Blogs & opinions

    • CPD & Training

    • Events

  • Qualifying and education

    • Qualifying and education

    • Qualifying as a Scottish solicitor

    • Career support and advice

    • Our work with schools

    • Lawscot Foundation

    • Funding your education

    • Social mobility

  • Research and policy

    • Research and policy

    • Research

    • Influencing the law and policy

    • Equality and diversity

    • Our international work

    • Legal Services Review

    • Meet the Policy team

  • For the public

    • For the public

    • What solicitors can do for you

    • Making a complaint

    • Client protection

    • Find a Solicitor

    • Frequently asked questions

    • Your Scottish solicitor

  • About us

    • About us

    • Contact us

    • Who we are

    • Our strategy, reports and plans

    • Help and advice

    • Our standards

    • Work with us

    • Our logo and branding

    • Equality and diversity

Platinum blog series Deborah Dillon

  1. Home
  2. News and events
  3. Blogs & opinions
  4. GDPR...one year on
4th June 2019 | Law Society news

GDPR... one year on

Deborah Dillon is Lead Auditor, Business & Platform Solution for Atos UK&I. She specialises in information governance, including the application and implementation of data protection processes and procedures across a wide range of organisational areas. Deborah is a member of our Privacy Committee.

The arrival of the General Data Protection Regulation on 25 May 25  2018 was highlighted in the media with a high-profile public awareness campaign that informed people of their new rights around their personal information and warned businesses of their responsibility about how they used this information. For me personally, as a Data Protection professional of many years, this meant that now friends and family finally understood the principles that I had been ‘banging on about’ for years previously! data protection is newsworthy, with people now understanding what I actually do for a living.  

 The UK Information Commissioner, Elizabeth Denham, gave a speech to the International Privacy Forum on 4 December 2018 in which she said that the Information Commissioner’s Office (the ICO) had received over 8,000 notifications of data breaches since the end of May 2018. That is compared with just 3,311 notifications between 1 April 2017 and 31 March 2018, and 2,565 between 1 April 2016 and 31 March 2017.

So far, the evidence of any significant enforcement activity is pretty slim; the European Data Protection Authorities (DPAs) continue to wade through very high work volumes, not least in dealing with over 50,000 data breach notifications since the GDPR came into force last year. However, we are now starting to see examples of the type of business behaviour that is likely to jump the data enforcement queue as well as grab media attention. This does not mean that investigations are not being undertaken behind the scenes by the UK and EU Data Protection Authorities and it is highly likely that we will start to hear again about some of the headline-grabbing breaches that we have seen in recent months and organisations being hit with large fines over the next year.

Some European regulators have already imposed fines. According to the Brussels-based board, there were 11 imposed under GDPR as of the end of March, totalling €55 million in penalties.

The biggest was against Google which was slapped with a €50 million fine by the French regulator CNIL (Commission nationale de l'informatique et des libertés). One of the key themes arising from these complaints is the level of detail that is expected to be included in the transparency information provided to data subjects. For example, in its statement on the Google fine, the CNIL said that Google’s “purposes of processing are described in a too generic and vague manner“, and “that the information about the retention period is not provided for some data.”

The introduction of the GDPR has had other, rather unexpected, applications. For example, Prince Harry’s lawyers invoked the GDPR to argue that a helicopter taking pictures inside his home had invaded his privacy.

So whilst we look ahead to the next year of GDPR compliance across the EU and beyond, and the impending fines under GDPR coming to fruition as case law in this area continues to be built upon and precedents set. Companies that have embraced GDPR as part of the fabric of their digital strategies are already seeing benefits in terms of privacy friendly innovation and growth of their customer bases. GDPR may be viewed as a driver towards increased customer trust and overall business growth. So, 2019 could be the year when the ways companies that comply with GDPR get more uniform across industries, positively affecting customer perspectives.

Platinum blog Ken Pritchard

Kenneth Pritchard OBE played a key role in the Society’s contribution to the Solicitors (Scotland) Act 1980 during his 21 years as the Secretary of the Law Society of Scotland. Mr Pritchard became an honorary member of the Law Society of Scotland in 1997.
Read more about Platinum blog Ken Pritchard

Platinum blog Andrew C Ferguson

As part of our Platinum Anniversary blog series, Andrew C Ferguson, a solicitor at Fife Council, discusses how the gender balance of the profession has changed since he became a solicitor over 30 years ago.
Gender balance: a remarkable turnaround about Platinum blog Andrew C Ferguson

Platinum blog Caroline Pigott

In the latest in our series of platinum anniversary blogs, Scottish solicitor and chartered trade mark attorney Caroline Pigott looks at how IP has changed over the years
Read more about Platinum blog Caroline Pigott
Add To Favorites

Additional

Categories

  • Equality and diversity
  • opinion
  • practice management
  • law society of scotland
  • executries
  • tax
  • mental health-adult incapacity
  • trusts-asset management
  • employment
  • europe
  • civil litigation
  • professional regulation
  • family-child law
  • criminal law
  • information technology
  • careers
  • reparation
  • human rights
  • property (non-commercial)
  • consumer
  • licensing
  • commercial property
  • planning/environment
  • insolvency
  • immigration
  • government-administration
  • welfare/benefits
  • client relations
  • education-training
  • interview
  • dispute resolution
  • corporate
  • agriculture-crofting
  • reviews
  • banking-financial services
  • intellectual property
  • New lawyers
  • Business support
  • Law Society news
  • Non-regulatory committees
  • Regulatory Committee
  • Career growth
  • International
  • Schools
  • Wellbeing
  • Member benefits
  • Professional support
  • Research and policy
  • In-house lawyers
  • Regulation
  • For the public
  • Legal aid
  • obituary
  • Public Policy Committee
  • Sustainability
  • Professional support
  • Wellbeing

News Archive

  • 2025
  • 2024
  • 2023
  • 2022
  • 2021
  • 2020
  • 2019
  • 2018
  • 2017
  • 2016
  • 2015
  • 2014
  • 2013
  • 2012
  • 2011
  • 2010
  • 2009
  • 2008

Related articles

  • Stay curious - and stand for the Law Society Council
  • Law Society launches WIDEN network
  • Meet our new Head of AML: Gemma Turnbull
  • Getting us all in the room where it happens
Law Society of Scotland
Atria One, 144 Morrison Street
Edinburgh
EH3 8EX
If you’re looking for a solicitor, visit FindaSolicitor.scot
T: +44(0) 131 226 7411
E: lawscot@lawscot.org.uk
About us
  • Contact us
  • Who we are
  • Strategy reports plans
  • Help and advice
  • Our standards
  • Work with us
Useful links
  • Find a Solicitor
  • Sign in
  • CPD & Training
  • Rules and guidance
  • Website terms and conditions
Law Society of Scotland | © 2025
Made by Gecko Agency Limited