Skip to main content
THE GENERAL DATA PROTECTION REGULATION TURNS 5!
Back to all Insights

Insights · Clarius Group

The General Data Protection Regulation turns 5!

Iris Duch, MLE, lawyer & Chief Privacy Officer, and lawyer Dr Andreas Pagiela have worked extensively with the GDPR over the years. To mark the GDPR anniversary, they give us a personal retrospective of their experience and of how the GDPR has developed.

Published
25 May 2023
Reading time
7 min read

Share this article

In May 2018, the General Data Protection Regulation (GDPR) entered into force. It is intended to harmonise and modernise data protection law in the European Union. The provisions of the GDPR directly require companies in the Member States of the European Union to comply with certain conditions of lawfulness for processing data, and they also strengthen data subjects’ rights to information and access. In the event of breaches of the GDPR, companies must expect processing bans or fines.

Iris Duch, MLE, lawyer & Chief Privacy Officer, and lawyer Dr Andreas Pagiela have worked extensively with the GDPR over the years. To mark the GDPR anniversary, they give us a personal retrospective of their experience and of how the GDPR has developed.

An initial assessment: where does the GDPR stand on its 5th birthday?

Dr Andreas Pagiela: The GDPR has arrived in the economy, I would say. It has in fact taken data protection to a new level and made companies highly aware of these issues.

Iris Duch, LL.M.: I clearly agree. Difficulties often arise when the numerous data-subject rights have to be implemented. Smaller companies in particular are frequently surprised at what citizens are entitled to under the GDPR. In large companies it is more the additional effort, which causes considerable administrative costs.

When the Regulation entered into force, waves of fines were feared for companies unable or unwilling to comply. Did the feared notices actually increase?

Iris Duch, LL.M.: The fine against the Meta group of EUR 1.2 billion is on everyone’s lips at the moment. But that should not distract from the fact that, in the end, most fines are moderate – that is, in the range of under EUR 10,000.00. Apart from individual cases, of course – and those individual cases increase the risk for companies overall. The Schrems II case law of the Court of Justice of the European Union in particular has caused uncertainty with regard to data transfers outside the EU and especially in the interplay with the United States. It will be interesting to see whether the EU finally creates relief for companies as well through a new adequacy decision. Otherwise, similar fines on the scale of the one against Meta cannot be ruled out.

Dr Andreas Pagiela: The amounts that are – for companies – in the majority rather lower are indeed imposed across the board. However, one should put this in the context of other fine proceedings: how many fines are imposed in other areas of regulatory law?! In that light, the GDPR is as a rule not an outlier.

Iris Duch, LL.M.: On the other hand, a fundamental question arises for me here: does the European Union actually want to burden companies even more? Are there not other ways of securing and implementing data protection? I fear that, as the burden of implementation duties from the field of EU compliance increases, companies may become more risk-tolerant and adopt an attitude of abstention. Along the lines of: “If I cannot do it properly, I will simply leave it.”
Of course that would not be appropriate, but it is not only the GDPR that demands considerable effort and a binding of resources from companies. As an example I am happy to name the German Supply Chain Due Diligence Act. The GDPR has its justification, but one must take care that data protection as a whole is not done a disservice by uncertainties in implementation and excessive harshness.

Have companies in fact been predominantly burdened, or have you also noticed positive reactions and follow-on effects?

Iris Duch, LL.M.: The importance of data protection has virtually permeated the DNA of many companies. Whereas people used to send an email with an open distribution list “just like that”, today that only happens by accident. For data protection breaches, emergency concepts that work very well have by now been implemented in the vast majority of cases.

Dr Andreas Pagiela: On top of that, citizens now have an instrumentarium of their own with which they can put companies under pressure with regard to the handling of their data. Unlike in civil law, citizens can call on the data protection authorities of the Länder or of the Federation if their rights are not respected. In addition to the courts, they therefore have a strong advocate at their side.

Iris Duch, LL.M.: Companies have also recognised that the protection of personal data is at the same time protection of the company’s interests. I am thinking here of satisfied customers and falling numbers of claims cases caused by data misuse.

Dr Andreas Pagiela: A great many! One has to see in principle that a legal rule always arises in the interplay between the legislator, the courts and social developments. It can take years before the courts decide open questions at last instance. At 5 years old, the GDPR is still a very young law; it will take a long time before all questions of interpretation are resolved.

Iris Duch, LL.M.: Many questions are still open. Apart from many individual topics, there is the fundamental question of how the GDPR interacts with other areas of law. In criminal law the iron principle applies that one must not be required to incriminate oneself – how far, then, must companies report their data protection breaches? In civil law the prohibition of a fishing expedition applies: each party is responsible for producing its own evidence. With the GDPR this can theoretically be undermined by requesting access to data. How far and how extensively a right of access applies is, however, likewise disputed, or is being shaped by more recent case law.

That does indeed sound like room for improvement. Do you have concrete proposals to make the GDPR more workable in practice?

Iris Duch, LL.M.: The great challenge under the GDPR is the balance between effective enforcement of the law for citizens – and workable solutions for the economy. Citizens ultimately benefit from the latter as well.

Dr Andreas Pagiela: Take cookie banners, for example: in principle it is entirely right to inform about data processing already when a site is accessed and to grant freedom of choice. If in practice, however, the banners are mostly just “clicked away” – then a different, better solution is needed.

Iris Duch, LL.M.: ​​​​​​ That is a good example. Here I would like to encourage MEPs to be bolder in looking at the GDPR from all directions – the protection of EU citizens and the perspective of the economy. Above all, however: to find creative solutions. The courts can and may only interpret the wording of the law. When it comes to genuinely new approaches, it is always the legislature, the European Parliament, that is called upon.

What expectations can one, in your assessment, have of the development of European data protection?

Dr Andreas Pagiela: The countries of Europe and the EU should for the time being concentrate on the further implementation of the GDPR and the corresponding case law. As so often in the legal world, people call for new rules – when one would only need to apply the existing ones comprehensively.

Iris Duch, LL.M.: I think that the protection of children’s and young people’s personal data will be an increasingly important topic in future. The developments around the TikTok platform have shown what market power – but also what social influence in the media – exists in relation to young people. Developing ways of contemporary, effective youth protection is the great challenge. Companies that use social media channels in marketing are currently on thin ice for these and, of course, other reasons.

What is your personal “birthday wish for the GDPR”

Dr Andreas Pagiela: Keep it up, but always remember that behind every legislative text there are people who have to implement it.

Iris Duch, LL.M.: All the best for the next 5 years – and by all means more courage for practical solutions. Cheers!

Do you have questions about this topic?

We can assess what the development means for your organisation and advise you directly.

Contact us

Would you like to stay up to date with the latest developments?

Sign up for our newsletter

From EU directives and AI to the industrialisation of different service areas, the market is undergoing significant change, and so is Clarius.

Our newsletter provides regular updates on developments that may be relevant to you.

Form loading …

Your personal contact

Matthias Schulz

Matthias Schulz

Director Sales

Get in touch by email