{"id":2445,"date":"2019-07-19T13:50:41","date_gmt":"2019-07-19T13:50:41","guid":{"rendered":"https:\/\/seersco.com\/blogs\/?p=2445"},"modified":"2023-09-25T12:10:05","modified_gmt":"2023-09-25T12:10:05","slug":"fine-enforcements-and-data-protection-regulations","status":"publish","type":"post","link":"https:\/\/seersco.com\/blogs\/fine-enforcements-and-data-protection-regulations\/","title":{"rendered":"Fine Enforcements And Data Protection Regulations Changes All Around The World"},"content":{"rendered":"<p>Everyone desires for something extra, whether it is, knowledge, advantage, service or anything. Similarly, this article is going to provide you with Compliance updates, a piece of additional knowledge about fines and extra tips to get compliant.<\/p>\n<p>Fines become a reality when organisations fail to protect the data of their customers. Obviously, a customer\u2019s confidential data has great importance; otherwise, it will enhance the ratio of targeting, blackmailing and many sorts of other crimes.<\/p>\n<p>No matter, an organisation has a significant influence over society, or it\u2019s just a small scale company, the General Data Protection Regulations (GDPR) is for everyone. Because, these companies contain vital data of its clients, and when Data Privacy precautions are not taken, a company always ends up losing that information.<\/p>\n<p>Which is why fines and penalties are imposed to abate the cyber attacks.<\/p>\n<p>Three huge enterprises are set to fine and created a history. British Airways, Marriott Hotels, and Facebook received the most significant fines of all times and still being targeted in many controversies.<\/p>\n<p>Let\u2019s have a quick recall.<\/p>\n<h2>British Airways<\/h2>\n<p>The Information Commissioner Officer fined British Airways for its last year security system hacking and data breach. As per BA resources, it was a sophisticated, malicious criminal attack.<\/p>\n<p>Whereas, according to the ICO, the penalty which is handed over to British Airways broke all the previous records. The ICO said the users of the British Airways website were diverted to a scammed website.<\/p>\n<p>The attackers hacked the details of 500,000 customers, from that fraudulent site. The compromised information included the login, payment card, and travel booking details as well as name and address information.<\/p>\n<p>After all the chaos, the BA co-operated very well with the Commissioner Officer and investigation. It also acted quickly to make improvements to its security arrangements.<\/p>\n<h2>Marriott Hotel<\/h2>\n<p>Recently, you probably have noticed that data breach kept on hitting the large organisations and Marriott cyberattack is in the same <a href=\"https:\/\/seersco.com\/articles\/what-is-data-inventory-and-why-its-important\/\">inventory<\/a> now.<\/p>\n<p>Personal data of more than 500m people, including credit card details, passport numbers, and date of birth has been hacked. Many are regarding this mishap as s \u201ccolossal\u201d hack of Marriott International.<\/p>\n<p>The company\u2019s primary sources said that they became aware of this infringement early in September. The information obtained by hackers contained names, mailing addresses, phone numbers, email addresses, and passport numbers.<\/p>\n<p>Marriott&#8217;s data breach created plenty of headlines and spice stories, but no one knew the enforcer behind it. However, it was a Chinese intelligence-gathering effort that hacked many more types of data, including the health and security clearance of Americans, according to the investigations.<\/p>\n<p>Though, the news says the hackers implemented on the instructions of the ministry of state security and the civilian spy agency.<\/p>\n<p>This discovery is made when Trump administration was planning to target China\u2019s trade, cyber and economic policies within days.<\/p>\n<p>According to the four government officials, they are planning to impose a fine and required investigation on those Chinese hackers working under the intelligence.<\/p>\n<p>As a result, the Trump administration decided to derestrict the reports to cancel the effect in case the hackers reveal the identity of US government officials.<\/p>\n<h2>Facebook<\/h2>\n<p>Facebook is set to face a $5bn fine following an investigation into the Cambridge Analytica data-stealing scandal.<\/p>\n<p>The Federal Trade Commission (FTC) began investigating Facebook back in March 2018, after a whistleblower revealed it. Users taking a personality quiz via an app on the site had their data collected by Facebook.<\/p>\n<p>The company also recorded the public data of their friends. Around 87 million users affected despite only 305,000 users installing the quiz app.<\/p>\n<p>This data then sold to Cambridge Analytica, which used it to profile US voters psychologically. It then targeted users with material to help Donald Trump 2016 presidential campaign.<\/p>\n<p>Facebook received a fine of \u00a3500,000 by the UK data protection watchdog back in October.<\/p>\n<h3>Ongoing investigations and Penalties all around the world<\/h3>\n<p>The GDPR was implemented in 2018; however, 2019 is the year of GDPR enforcement. Data Protection Authorities (DPAs) in Germany have started their audits, and France\u2019s DPA, the CNIL, fine earlier this year. Due to its enforcement and influence, many companies have launched their new legislation, ranging from a penalty to imprisonment.<\/p>\n<p>Ongoing fines are for companies to realise the value of data protection for their clients. In accordance with <a href=\"https:\/\/seersco.com\/articles\/complete-gdpr-summary\/\">GDPR<\/a>, a single violation will make you pay $1,000,000. Whereas, in some countries, being <a href=\"https:\/\/seersco.com\/blogs\/compliant-vs-non-compliant-cookie-banners\/\">non-compliant<\/a> is itself an offense no matter any data breach incident has stroked it or not.<\/p>\n<p>In recent times, a comparison of the <a href=\"https:\/\/seersco.com\/articles\/gdpr-compliance\/\">GDPR compliance<\/a> within 24 countries around the world, have started, from Germany to Japan to Israel. The upshot declared that 65% of these countries either improved their data protection laws or issued new compliance rules after the GDPR was announced in 2016.<\/p>\n<p>There are reasons why countries have increased fines for Data Protection Regulations. Organisations want to gain adequacy agreement with the EU under the GDPR, for the free flow of data between them. Secondly, penalties will reflect how persuasive a country\u2019s supervisory authority is in terms of data protection laws.<\/p>\n<h4 style=\"margin-top: 0px !important; padding-top: 0px !important;\">Previous controversial Fines<\/h4>\n<p>The news is, some countries do not stop at corporate fines. The GDPR allows EU Member State derogations for penalties. Many countries, like Germany, France, Japan, the Philippines, Mexico, and Indonesia, issue sanctions to individuals who are responsible for a data compromise.<\/p>\n<h4 style=\"margin-top: 0px !important; padding-top: 0px !important;\">Germany<\/h4>\n<p>Germany started to lead the GDPR enforcement and started its audit back in July. It issued a plethora of penalties last summer. Knuddels is a German social media, had received the first fine.<\/p>\n<p>In July of 2018, intruders planned a cyber-attacks, and as a result, it compromised the personal information of more than 330,000 Knuddels users, including 808,000 email addresses and passwords.<\/p>\n<p>However, in November, the LfDI fined this small scale company, which was \u20ac20,000. It was a shock for many because it could go around \u20ac10 million or 2% of the company\u2019s annual revenue.<\/p>\n<h4 style=\"margin-top: 0px !important; padding-top: 0px !important;\">Poland<\/h4>\n<p>Poland&nbsp;On April 1, 2019, Poland\u2019s DPA, the UODO, fined a digital marketing agency \u20ac220,000 for non-compliance with the GDPR\u2019s data subject rights requirements.<\/p>\n<h4 style=\"margin-top: 0px !important; padding-top: 0px !important;\">CNIL Google<\/h4>\n<p>We all have heard Google\u2019s cautionary tale. In January of 2019, the French DPA, the CNIL, fined the tech giant \u20ac50 million for violating the requirements of the Data Protection Regulations. A noteworthy fact, it received fine not in the reciprocation of a data breach but due to subject data complaints.<\/p>\n<p>The recent research of DLA Piper brought out some interesting statistics regarding data breaches and fines post-GDPR implementation. According to a report, published in February 2019, found that only 91 fines issued under the GDPR and 59,000 personal data breaches reported. The regulator&#8217;s main focus is high-profile and severe violations, leaving many companies waiting to see what may happen with their cases.<\/p>\n<p><strong>Japan,<\/strong> the person involved in a data breach will confront imprisonment of a year.<\/p>\n<p><strong>Philippine,<\/strong> the culprit will face up a prison sentence ranging from 1 to 7 years.<\/p>\n<p><strong>Switzerland,<\/strong> anyone who fails to convey accurate information to the Federal Data Protection and Information Commissioner will receive a personal fine.<\/p>\n<p><strong>Countries are now ready for GDPR compliance.<\/strong><\/p>\n<h4 style=\"margin-top: 0px !important; padding-top: 0px !important;\">1) India<\/h4>\n<p>India has decided to follow EU-GDPR long ago. In 2017, the Indian Government opted out Justice BN Srikrishna to lead a former judge of the Supreme Court of India the committee of experts to create the legal framework for data protection and data privacy in India. He is also a former judge of the Supreme Court of India.<\/p>\n<p>The agenda of the committee was, \u201cto make specific suggestions for consideration of the Central Government on principles consideration for data protection in India and suggest a draft data protection bill.\u201d<\/p>\n<h4 style=\"margin-top: 0px !important; padding-top: 0px !important;\">2) Brazil<\/h4>\n<p>On August 14, 2018, Brazil approved the General Data Protection Law. However, the law will come into effect after its 18th adaptation period, in early 2020. The <a href=\"https:\/\/seersco.com\/blogs\/lgpd-ready-to-go-live\/\">LGPD<\/a> has introduced a new legal framework for the use of personal data in Brazil.<\/p>\n<p>The structure is for both online and offline, in the private and public sectors. A notable fact is, Brazil has more than 40 legal norms at the federal level that directly and indirectly deal with the protection of privacy and personal data in a sector-based system.<\/p>\n<h4 style=\"margin-top: 0px !important; padding-top: 0px !important;\">3) Ecuador<\/h4>\n<p>On Wednesday, January 16, 2019, the National Directorate for the Registration of Public Data (DINARDAP), an Ecuadorian public entity attached to the Ministry of Telecommunications.<\/p>\n<p>The person represented the first law of personal data protection of Ecuador to the public. This productive approach indicates the Government is stepping forward to make the regulatory changes in terms of data privacy transparent and inclusive for all.<\/p>\n<p><strong>Your vision our mission &#8211; Enjoy the privilege.<\/strong><\/p>\n<p>When it comes to protecting your data, you\u2019re in safe hands. Seers is at the forefront of <strong>cybersecurity<\/strong> and <strong><a href=\"https:\/\/seersco.com\/articles\/complete-gdpr-summary\/\">data protection<\/a><\/strong>. We privacy management tools and launched eight privacy products and have 1,500 users. We\u2019re proud to say that we\u2019ve helped many organisations successfully.<\/p>\n<p>We\u2019re UK\u2019s leading provider of cyber risk and privacy management solutions and have built a strong global presence with our deep technical expertise and proven track record.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>GDPR | Seers Blog<\/p>\n","protected":false},"author":3,"featured_media":2460,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"rank_math_lock_modified_date":false,"footnotes":""},"categories":[20,1],"tags":[],"class_list":["post-2445","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-megamenufull","category-uncategorized","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","no-featured-image-padding"],"_links":{"self":[{"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/posts\/2445","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/comments?post=2445"}],"version-history":[{"count":0,"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/posts\/2445\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/media\/2460"}],"wp:attachment":[{"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/media?parent=2445"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/categories?post=2445"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/tags?post=2445"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}