Data Sovereignty / Source date:

GDPR year six and continuing compliance duties

A historical 2024 discussion of continuing data-protection duties, without an unverified cumulative fine total or automatic retention rule.

Illustration of a privacy reviewer checking fictional access-request and retention records.

Historical context. The original 6 November 2024 date is retained. This is a discussion of that period, not a current total or regulatory-status check. No cumulative fine amount is asserted without a dated dataset, scope and treatment of appeals. What matters is the shape of it: where the money came from, what conduct attracted it, and what that implies for an organisation that will never be the subject of a billion-euro decision.

The total is concentrated in a handful of decisions against a handful of companies. The enforcement that will reach you is smaller, duller and far more common

Read the distribution rather than the sum, and the practical priorities change completely.

What the distribution actually shows

A very large share of the cumulative total comes from a small number of decisions against major technology platforms, concerning transfers, advertising consent and the legal basis for behavioural processing. Those cases are genuinely important and almost entirely irrelevant as a guide to your own risk. Underneath them sits the enforcement that happens continuously: modest fines and corrective orders against ordinary organisations for security failures that led to a breach, excessive video surveillance, retention of data long past any purpose, employee monitoring without a proper basis, failure to honour access and deletion requests within the deadline, and failure to notify a breach in time. That second category is the one your organisation lives in. It is driven overwhelmingly by complaints from individuals — employees, former employees, customers — rather than by regulators auditing at random.

Three patterns worth internalising

The complaint is the trigger. Most enforcement begins with a person who asked for something and was ignored. That makes your request-handling process, not your policy document, the main determinant of whether you ever meet a regulator. Cooperation changes the outcome. Decisions consistently treat the response — speed of notification, candour, remediation — as a material factor. Organisations that argued and delayed fared worse than comparable organisations that fixed and disclosed. Employee data is underrated. A large share of ordinary enforcement concerns the workforce rather than customers: monitoring, biometric attendance systems, excessive collection during recruitment, and retention after departure. Privacy programmes built around the customer database routinely miss this entirely.

The access request is the cheapest thing you are getting wrong

One month to respond, extendable in limited circumstances. Almost every organisation that has received a difficult access request — usually from a departing employee, frequently with a dispute in the background — has discovered that it cannot assemble the data in the time available, because nobody knows where it all is. Run one against yourselves. Pick a real employee record and try to produce everything: the human resources system, payroll, the email archive, the messaging platform, the building access logs, the closed-circuit footage, the recruitment system, the expense tool, the departmental spreadsheet. Time it. That exercise will tell you more about your actual exposure than any gap assessment.

Retention is where the ordinary failures accumulate

The most common finding in routine enforcement is holding data for no articulated reason. It is also the least expensive thing to fix and the most persistently deferred, because deletion has no advocate inside the organisation. A short schedule that names the categories, the periods and the legal basis for each, actually implemented in the systems rather than documented in a policy, closes off a disproportionate share of realistic risk.

Practical Guidance for GDPR Maturity Assessment

  • Run a live access request against your own records and time it.
  • Map where employee data actually sits, including informal systems.
  • Implement a retention schedule in the systems, not just on paper.
  • Rehearse applicable breach duties. Under Article 33, controllers notify without undue delay and, where feasible, within 72 hours of awareness unless a breach is unlikely to risk individuals' rights and freedoms. Processor escalation and high-risk communication to individuals are separate. EDPB guidance supplies the thresholds.
  • Review monitoring and biometric attendance for a lawful basis.
  • Review recruitment-data retention against purpose, lawful basis, statutory duties and legal holds. The end of recruitment is not an automatic universal deletion deadline; Article 17 has legal-obligation and legal-claims exceptions.
  • Document your decisions, because reasoning is what gets assessed.
  • Treat cooperation as strategy, not as capitulation.

The Regional Angle

The first point is jurisdictional and frequently misjudged in both directions. A regional company with no European establishment can still be caught where it offers goods or services to people in Europe or monitors their behaviour, and where it does, the Article 27 representative requirement needs assessment, including its limited exemptions. No measured prevalence of missed appointments is asserted here. Equally, plenty of regional businesses have been sold compliance programmes they did not need, on the strength of a European customer who is a controller in their own right while the regional firm is merely a processor. Establish which you are, in writing, for each relationship. Processor obligations are real but different, and the difference is worth several months of unnecessary programme. The second is that the European regime is no longer the only clock. Saudi Arabia's personal data protection law has moved through its grace period this year, the United Arab Emirates federal law is in force while its executive regulations remain awaited, and Bahrain, Qatar, Oman and the financial free zones each maintain their own frameworks with their own registration, breach notification and transfer rules. A group operating across the Gulf therefore faces overlapping requirements that are broadly similar in principle and different in the details that cost money — notification timelines, registration duties, the treatment of cross-border transfers within the group. Build one control set and maintain a short matrix of the jurisdictional variations rather than running separate programmes per country, and make sure someone owns the matrix, because the variations are still changing. The third is the practice that generates the most realistic regional exposure and attracts the least attention. Workforce monitoring here is more extensive than in most markets: biometric attendance across sites, vehicle tracking for fleets and drivers, camera coverage of warehouses and retail floors, and detailed personal documentation held for visa and labour purposes including passports, medical records and dependant information. Much of that collection is genuinely required by law, which is exactly why it is rarely questioned — but the requirement covers the collection, not the indefinite retention, the group-wide sharing, or the secondary uses that accumulate around it. Separate what a regulator requires you to hold from what the business has started doing with it, set a retention period for each, and check what happens to the file when an employee leaves. That last question has an embarrassing answer in most regional groups.

The objection worth taking seriously

The strongest objection is that the enforcement statistics do not justify the spending. Six and a half years in, the overwhelming majority of the money has landed on a dozen very large companies over practices no mid-market business engages in. The realistic exposure for an ordinary organisation outside Europe is a complaint from an individual, a corrective order, and a fine that is small relative to what a serious compliance programme costs to run. On the numbers, the rational position is to maintain a defensible minimum and spend the difference on something that generates revenue. That arithmetic is more honest than most privacy advocacy admits, and anyone budgeting a large programme on fine avoidance alone is being sold something. Where it breaks down is in the assumption that the fine is the cost. The expensive outcomes in this area are rarely the penalty: they are the regulator's order to stop a processing activity the business depends on, the four months of executive time consumed by an investigation, the customer contract lost because you could not answer a due diligence questionnaire, and the deal delayed while a buyer's counsel works out what you are holding and on what basis. Those costs land on organisations of every size and none of them appear in a fine tracker. The work that prevents them — knowing where the data is, being able to answer a request, holding nothing you cannot justify — is also the cheapest part of the programme. Do that part properly and treat the rest as proportionate.

Common Questions

Does the regulation apply to us with no European entity?

Possibly, if you offer goods or services to people in Europe or monitor their behaviour. If it does, check whether you also need to designate a representative in the Union.

What is the most common cause of enforcement against ordinary companies?

Security failures leading to a breach, and failures to respond properly to individuals exercising their rights. Both are process problems rather than technology problems.

How seriously is the seventy-two hour breach clock enforced?

Article 33 requires controller notification without undue delay and, where feasible, within 72 hours of awareness unless the breach is unlikely to risk individuals' rights and freedoms. EDPB guidance defines awareness as a reasonable degree of certainty that a security incident compromised personal data. Processor escalation and high-risk communication to individuals have separate tests. This is not a claim that every incident starts a clock before awareness or that lateness always has the same penalty effect.

What should we expect over the next twelve months?

Expect continued attention to the lawful basis for behavioural advertising and to transfers, which will keep the headline numbers concentrated at the top. Expect artificial intelligence deployments to be examined under existing data protection law well before the new artificial intelligence regime bites, particularly where personal data is used for training. Expect employee monitoring to attract growing regulatory interest across several jurisdictions at once. And expect Gulf regulators to move from registration and awareness towards their first substantive enforcement actions.


GDPR Maturity Assessment — we test whether you can actually answer a request and justify what you hold, which is what enforcement turns on.

Continue reading

Talk to OPS

Start with the operating problem.