A week on from the dreaded GDPR implementation, how are organisations and individuals coping with the biggest change to privacy laws in the 21st Century? Is our data any safer? And will the stragglers be able to catch up?
Only a week into the world according to GDPR, and it already feels like so long ago that businesses were frantically seeking advice on what needed to be done to remain compliant in the face of harsh punishment. But for anyone hoping to see a sudden end to GDPR’s spotlight reign and domination on the headlines, it’s a disappointing time.
As we crossed the threshold into a new era of data protection, some things changed for the better, others didn’t, and many are still scrambling to become compliant even after the deadline has passed. So, are we in a better place now?
Day One in Silicon Valley
The security which is afforded by GDPR is sure to become historic, and likewise, people won’t forget the first twenty-four hours of its implementation. For big names such as Google and Facebook, who had both put in over a year of preparation each, Day One was a blessing and a curse.

Thanks to Google sowing seeds of doubt amongst marketers weighing up which ad platform to use post-GDPR, the first twenty-four hours saw 95% of advertising spend make its way through Google – the most trusted platform. This is compared with two days earlier, when about 50% of ad spend moved through Google. By Tuesday, however, things were back to normal.
Despite their preparation, some critics were waiting in the wings to trip Silicon Valley’s giants up the moment the new privacy laws came into effect. Austrian activist Max Schrems, for instance, filed lawsuits amounting to $8.8billion against Facebook and Google, accusing the giants of coercing users into sharing personal data. Both denied any wrongdoing despite Schrems’ claims that how they gather consent puts users into an “all-or-nothing” situation. If Schrems’ lawsuit is successful, it will likely be the first such instance under GDPR, and will set the tone for other big names.
Confusion and Chaos
It wasn’t just big brands experiencing an interesting start to a new privacy era, either. Since GDPR was first announced, small businesses have had a vague dread around what it entails, with some arguing that the information and guidance on offer have been insufficient, whilst others build new business offerings to take advantage of the situation.

That confusion still existed last Friday, on launch day. The Church of England, for example, misinterpreted the guidelines, with priests initially being informed that they couldn’t pray for people without their consent, before the situation was clarified. Meanwhile, Elizabeth Denham – the UK’s Information Commissioner – reassured small businesses that they wouldn’t be made an example of if they weren’t ready for compliance in time.
There were some organisations, however, who seemingly took the deadline in their stride by opting to take more drastic measures instead, come Friday 25th May. Some US news sites, including the Chicago Tribune and LA Times, blocked European users rather than jump through the various GDPR-shaped hoops, leaving members of the public angry and confused – with some falsely accusing Europe of censorship.
Where Do We Go from Here?
Despite a rocky start that’s seen inboxes filling up, lawsuits being filed, and a general air of confusion still clearing, we must remember that this is only the beginning of GDPR’s reign. Under the new guidelines, we’ve been afforded a thorough level of protection with organisations dissuaded from putting our privacy at risk for fear of harsh penalties.

Whether or not the utopian vision of a secure world awaits us further into GDPR’s era, however, has yet to be decided. Critics such as Icann, the owner of website hosting directory Whois, have made a case for GDPR hindering police and making it harder to catch hackers, whilst experts in the luxury industry have pointed out that it will now be more difficult to track down and stop the sale of fakes.
It would seem, then, that GDPR still requires some fine-tuning now that it’s officially implemented in the wider world. Over the next few months and years, we could certainly see guidelines being re-shaped to find a compromise between protecting personal data and hindering law enforcement. But considering that it’s only been a week and the world didn’t end for small businesses, I think we can all agree that it hasn’t been quite as terrifying an experience as some had once led us to believe it would be. Cue a sigh of relief.
Find out more about Kaleida’s bespoke software development services by exploring our website, or feel free to get in touch to talk to our team.

