SlideShare a Scribd company logo
TALEND GDPR
COMPLIANCE
BENCHMARK
SEPTEMBER 2018
33
GDRP BENCHMARK PARAMETERS
103
Companies
In the panel
Rights for Data
Access &
Portability
Worldwide study
Financial
Services
24%
Travel,
Transport,
Hospitability
24%
Retail &
consumer
goods
24%
Media,
Telco,
Utilities
28%
Europe
70%
APAC 11%
NORAM 19%
Regions Sectors
44
GDPR BENCHMARK - BACKGROUND
GDPR: The General Data Protection Regulation is a regulation in EU law on data protection and privacy for all individuals
within the European Union. The regulation, which sets a new standard for consumer rights regarding their data, came into
effect on May 25, 2018. The governing body is expected to levy significant fines to companies that do not comply with the
new regulations.
Market Compliance Research: Talend, a leader in data integration and management software, conducted market research
to assess companies’ ability to comply with the new GDPR regulation. The analysis involved the following:
• Assessing whether or not companies had updated their privacy policies to account for GDPR
• Researching whether or not companies had dedicated ways for consumers to request GDPR data (i.e., the personal
information the company has on them)
• Requesting GDPR data and assessing how quickly and thoroughly companies comply
• Requesting GDPR data in a way that may be directly accessed and reused by the individual (data portability)
The research involved 103 GDPR-relevant companies across the globe (EU companies or companies based in the U.S. or
APAC that conduct business in Europe) from a range of industries (Retail, High-Tech, Media, Transport/Travel/Hospitality,
Utilities/Telco, Public Sector, Finance)
55
SURVEY HIGHLIGHTS
Policies are defined…
98%HAVE UPDATED THEIR
PRIVACY POLICIES FOR
GDPR
70%FAILED TO PROVIDE THE
DATA REQUESTED
IN 30 DAYS !
21 days
AVG TIME IT TOOK
COMPLIANT COMPANIES
TO RESPOND
But are not enforced… or poorly delivered
66
GDPR COMPLIANCE - REGIONAL BREAKDOWN
Almost
90%
FRENCH AND SOUTHERN
EUROPEAN COMPANIES
HAD THE HIGHEST FAILURE
RATE OF ANY REGION
35%
OF EUROPEAN
COMPANIES PASSED
50%OF NON-EUROPEAN
COMPANIES PASSED
EU-based companies were less likely to comply
to GDPR than companies outside the EU
Vs
77
GDPR COMPLIANCE - INDUSTRY BREAKDOWN
47% TRAVEL/TRANSPORTATION HOSPITALITY
24% RETAILERS
50% FINANCIAL SERVICES
COMPLIANCE
FAILURE
WHILE MOST INDUSTRIES ARE DOING A POOR
JOB OF COMPLYING TO GDPR, RETAILERS ARE BY
FAR THE WORST OFFENDERS
40% MEDIA/TELCO/UTILITIES
88
GDPR COMPLIANCE – COMPLIANT COMPANIES
30%PROVIDED GDPR
DATA UPON
REQUEST
WITHIN 30 DAYS
21THE AVG NUMBER OF DAYS
IT TOOK COMPLIANT
COMPANIES TO RESPOND
6%THE PERCENTAGE OF
COMPLIANT COMPANIES
THAT ASKED FOR AN
EXTENSION* TO COMPLY
*Allowed under article 12.3 of GDPR
22%THE PERCENTAGE OF
COMPANIES THAT
RESPONDED IN A 24HRS
65%THE PERCENTAGE OF
COMPANIES THAT
ANSWERED IN 10+ DAYS
99
ADDITIONAL
EXPERIENCES
• 7% of companies mistakenly assumed we were asking
to be forgotten (half of them were hospitality leaders)
• 4 companies actually deleted our account and data
without notice
• Some companies asked for a range of personal data
before beginning our request (ID, loyalty number,
birthday, data of transactions…) and then still didn’t
comply
• Virtually every company failed to fulfill our request for
data portability
• 4 companies asked “what do you mean by personal
data”?
• A leading global firm in the financial sector fulfilled our
request by sharing the data they held on us through
printed pages that they physically delivered through a
secure mail courier.
• Only a few delivered a 1-click memorable customer
experience, including Spotify (Sweden), N26 (Germany),
Garmin (US), and Next (Germany). They offered a clear
explanation of their usage of our personal data, direct
access to our data via a portal, and data portability.
1010
THE ROAD TO
COMPLIANCE:
WHY DO
COMPANIES FAIL?
• The majority of companies do not
adequately track personal information
• Lack accountability
• Absence of Data Privacy Owner (DPO)
• No department clearly appointed to answer
requests
• Lack data control and visibility
• Can’t identify customers: some companies
have requested personal data in order to start
processing the requests
• Can’t locate data or deleted data
• Provided incomplete data sets (siloed data)
• Lack proper processes or tools
• Need for human data integrators
• Companies are overwhelmed: fail to deliver
after the extension with article 12.3
1111
OUR KEY TAKE AWAYS
GDPR is seen as a
legal project and not
as a driver for better
customer experience,
Engagement, and
trust
LEGAL VS
CUSTOMER
How organizations
empower data
workers towards
GDPR and the
importance of having
a data owner or
controller
DATA CULTURE/
DATA OWNERSHIP
Customers data is
siloed and the
majority of
companies do not
know their customers
CUSTOMER
360°
Organizations do not
have automated
processes: GDPR is
not a one-click
process (human data
integrator)
AUTOMATION
GDPR Benhmark: 70%  of companies failing on their own GDPR compliance claims

More Related Content

PDF
Delivering Analytics at Scale with a Governed Data Lake
PDF
Liberating data with Talend Data Catalog
PDF
Enacting the data subjects access rights for gdpr with data services and data...
PDF
3 Steps to Turning CCPA & Data Privacy into Personalized Customer Experiences
PDF
Deliver Data Governance with a “Yes”
PDF
Operationalising gdpr compliance with data management
PDF
Delivering analytics at scale with a governed data lake
PDF
Dynamic Talks: "Data Strategy as a Conduit for Data Maturity and Monetization...
Delivering Analytics at Scale with a Governed Data Lake
Liberating data with Talend Data Catalog
Enacting the data subjects access rights for gdpr with data services and data...
3 Steps to Turning CCPA & Data Privacy into Personalized Customer Experiences
Deliver Data Governance with a “Yes”
Operationalising gdpr compliance with data management
Delivering analytics at scale with a governed data lake
Dynamic Talks: "Data Strategy as a Conduit for Data Maturity and Monetization...

What's hot (20)

PDF
Delivering data you can trust for data privacy
PDF
Delivering data governance with a Yes
PDF
Big Data LDN 2017: Disruption in Data
PDF
Data strategy demistifying data
PPTX
Big data engineering slideshare - v0.4
PDF
Understanding the Data You Have Before Applying a Governance Strategy
PDF
Slides: Achieving a “Single Source of Truth” with BI in Your Enterprise
PDF
Big Data Strategy
PDF
Big Data LDN 2017: Data Governance Reimagined
PDF
Slides: Applying Artificial Intelligence (AI) in All the Right Places in the ...
PDF
Delivering data you can trust with Talend 2019
PDF
Big Data SurVey - IOUG - 2013 - 594292
PPTX
Big Data Strategies
PDF
You Can’t Have Best in Class Governance Without Best in Class Data Lineage
PDF
Slides: Data Governance Reality Check
PDF
Data Catalog as the Platform for Data Intelligence
PDF
Predictive vs Prescriptive Analytics
PDF
Evtm 281 07_bi2015_infographic_r2h
PDF
Navigating the Complex World of Compliance Guidelines
PDF
New Strategies for More Effective Remote/Branch Office Data Protection
Delivering data you can trust for data privacy
Delivering data governance with a Yes
Big Data LDN 2017: Disruption in Data
Data strategy demistifying data
Big data engineering slideshare - v0.4
Understanding the Data You Have Before Applying a Governance Strategy
Slides: Achieving a “Single Source of Truth” with BI in Your Enterprise
Big Data Strategy
Big Data LDN 2017: Data Governance Reimagined
Slides: Applying Artificial Intelligence (AI) in All the Right Places in the ...
Delivering data you can trust with Talend 2019
Big Data SurVey - IOUG - 2013 - 594292
Big Data Strategies
You Can’t Have Best in Class Governance Without Best in Class Data Lineage
Slides: Data Governance Reality Check
Data Catalog as the Platform for Data Intelligence
Predictive vs Prescriptive Analytics
Evtm 281 07_bi2015_infographic_r2h
Navigating the Complex World of Compliance Guidelines
New Strategies for More Effective Remote/Branch Office Data Protection
Ad

Similar to GDPR Benhmark: 70% of companies failing on their own GDPR compliance claims (20)

PDF
GDPR & Data Privacy Guide - Free Download
PDF
Flash Friday: Data Quality & GDPR
PDF
Data Protection and Privacy
PPTX
GDPR How to get started?
DOCX
Top gdpr assessment tools
PDF
GDPR (En) JM Tyszka
PDF
U.S. Data Privacy Report - Patchy preparation for GDPR shows U.S. businesses ...
PDF
Are Your Data Ready for GDPR? (with MAPR and Talend)
PDF
Data Quality-Driven GDPR: Compliance with Confidence (EMEA)
PDF
Marketing data management | The new way to think about your data
PDF
Data Quality-Driven GDPR: Compliance with Confidence
PPTX
Do You Have a Roadmap for EU GDPR Compliance?
PDF
GDPR ASAP: A Seven-Step Guide to Prepare for the General Data Protection Regu...
PPTX
GDPR: Data Privacy in the New
PPTX
Do You Have a Roadmap for EU GDPR Compliance?
PPTX
The Meaning and Impact of the General Data Protection Regulation
PDF
GDPRIBMWhitePaper
PDF
EY General Data Protection Regulation: Are you ready?
PDF
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
PPTX
Gdpr action plan
GDPR & Data Privacy Guide - Free Download
Flash Friday: Data Quality & GDPR
Data Protection and Privacy
GDPR How to get started?
Top gdpr assessment tools
GDPR (En) JM Tyszka
U.S. Data Privacy Report - Patchy preparation for GDPR shows U.S. businesses ...
Are Your Data Ready for GDPR? (with MAPR and Talend)
Data Quality-Driven GDPR: Compliance with Confidence (EMEA)
Marketing data management | The new way to think about your data
Data Quality-Driven GDPR: Compliance with Confidence
Do You Have a Roadmap for EU GDPR Compliance?
GDPR ASAP: A Seven-Step Guide to Prepare for the General Data Protection Regu...
GDPR: Data Privacy in the New
Do You Have a Roadmap for EU GDPR Compliance?
The Meaning and Impact of the General Data Protection Regulation
GDPRIBMWhitePaper
EY General Data Protection Regulation: Are you ready?
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Gdpr action plan
Ad

More from Jean-Michel Franco (19)

PPTX
A commonsense approach to data
PPTX
Prendre la data par le bon sens
PDF
Reveal the Intelligence in your Data with Talend Data Fabric
PDF
Dévoilez l'essentiel de vos données avec Talend
PDF
Libérez vos données avec un catalogue de données
PDF
Make Data Better Together
PDF
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
PDF
Créer la vue 360° des employés
PDF
Etapes Pratiques Pour La Mise En Conformité Au GDPR avec Talend
PDF
Practical steps to GDPR compliance
PDF
Présentation de Talend Winter 2017
PDF
Talend winter 2017 overview webinar
PDF
Self-service data and data governance: friends or foes?
PDF
Etablir une collaboration durable entre les équipes informatiques et les méti...
PDF
Big Data : au delà du proof of concept et de l'expérimentation (Matinale busi...
PDF
Piloter l'entreprise par ses données (présentation Talend pour la matinale ED...
PDF
Talend Summer 16 (version française) : la Préparation des Données à la Portée...
PDF
Talend Summer 16 launch présentation: Open Data Preparation for Everyone
PDF
Bi et partage des données financières en libre -service
A commonsense approach to data
Prendre la data par le bon sens
Reveal the Intelligence in your Data with Talend Data Fabric
Dévoilez l'essentiel de vos données avec Talend
Libérez vos données avec un catalogue de données
Make Data Better Together
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
Créer la vue 360° des employés
Etapes Pratiques Pour La Mise En Conformité Au GDPR avec Talend
Practical steps to GDPR compliance
Présentation de Talend Winter 2017
Talend winter 2017 overview webinar
Self-service data and data governance: friends or foes?
Etablir une collaboration durable entre les équipes informatiques et les méti...
Big Data : au delà du proof of concept et de l'expérimentation (Matinale busi...
Piloter l'entreprise par ses données (présentation Talend pour la matinale ED...
Talend Summer 16 (version française) : la Préparation des Données à la Portée...
Talend Summer 16 launch présentation: Open Data Preparation for Everyone
Bi et partage des données financières en libre -service

Recently uploaded (20)

PPTX
MYSQL Presentation for SQL database connectivity
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
KodekX | Application Modernization Development
PDF
Approach and Philosophy of On baking technology
PPTX
Big Data Technologies - Introduction.pptx
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
solutions_manual_-_materials___processing_in_manufacturing__demargo_.pdf
PPTX
breach-and-attack-simulation-cybersecurity-india-chennai-defenderrabbit-2025....
PDF
Electronic commerce courselecture one. Pdf
PDF
Advanced Soft Computing BINUS July 2025.pdf
PDF
Advanced IT Governance
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
[발표본] 너의 과제는 클라우드에 있어_KTDS_김동현_20250524.pdf
PDF
Modernizing your data center with Dell and AMD
MYSQL Presentation for SQL database connectivity
Diabetes mellitus diagnosis method based random forest with bat algorithm
Per capita expenditure prediction using model stacking based on satellite ima...
Unlocking AI with Model Context Protocol (MCP)
KodekX | Application Modernization Development
Approach and Philosophy of On baking technology
Big Data Technologies - Introduction.pptx
NewMind AI Weekly Chronicles - August'25 Week I
solutions_manual_-_materials___processing_in_manufacturing__demargo_.pdf
breach-and-attack-simulation-cybersecurity-india-chennai-defenderrabbit-2025....
Electronic commerce courselecture one. Pdf
Advanced Soft Computing BINUS July 2025.pdf
Advanced IT Governance
Mobile App Security Testing_ A Comprehensive Guide.pdf
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
NewMind AI Monthly Chronicles - July 2025
CIFDAQ's Market Insight: SEC Turns Pro Crypto
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
[발표본] 너의 과제는 클라우드에 있어_KTDS_김동현_20250524.pdf
Modernizing your data center with Dell and AMD

GDPR Benhmark: 70% of companies failing on their own GDPR compliance claims

  • 2. 33 GDRP BENCHMARK PARAMETERS 103 Companies In the panel Rights for Data Access & Portability Worldwide study Financial Services 24% Travel, Transport, Hospitability 24% Retail & consumer goods 24% Media, Telco, Utilities 28% Europe 70% APAC 11% NORAM 19% Regions Sectors
  • 3. 44 GDPR BENCHMARK - BACKGROUND GDPR: The General Data Protection Regulation is a regulation in EU law on data protection and privacy for all individuals within the European Union. The regulation, which sets a new standard for consumer rights regarding their data, came into effect on May 25, 2018. The governing body is expected to levy significant fines to companies that do not comply with the new regulations. Market Compliance Research: Talend, a leader in data integration and management software, conducted market research to assess companies’ ability to comply with the new GDPR regulation. The analysis involved the following: • Assessing whether or not companies had updated their privacy policies to account for GDPR • Researching whether or not companies had dedicated ways for consumers to request GDPR data (i.e., the personal information the company has on them) • Requesting GDPR data and assessing how quickly and thoroughly companies comply • Requesting GDPR data in a way that may be directly accessed and reused by the individual (data portability) The research involved 103 GDPR-relevant companies across the globe (EU companies or companies based in the U.S. or APAC that conduct business in Europe) from a range of industries (Retail, High-Tech, Media, Transport/Travel/Hospitality, Utilities/Telco, Public Sector, Finance)
  • 4. 55 SURVEY HIGHLIGHTS Policies are defined… 98%HAVE UPDATED THEIR PRIVACY POLICIES FOR GDPR 70%FAILED TO PROVIDE THE DATA REQUESTED IN 30 DAYS ! 21 days AVG TIME IT TOOK COMPLIANT COMPANIES TO RESPOND But are not enforced… or poorly delivered
  • 5. 66 GDPR COMPLIANCE - REGIONAL BREAKDOWN Almost 90% FRENCH AND SOUTHERN EUROPEAN COMPANIES HAD THE HIGHEST FAILURE RATE OF ANY REGION 35% OF EUROPEAN COMPANIES PASSED 50%OF NON-EUROPEAN COMPANIES PASSED EU-based companies were less likely to comply to GDPR than companies outside the EU Vs
  • 6. 77 GDPR COMPLIANCE - INDUSTRY BREAKDOWN 47% TRAVEL/TRANSPORTATION HOSPITALITY 24% RETAILERS 50% FINANCIAL SERVICES COMPLIANCE FAILURE WHILE MOST INDUSTRIES ARE DOING A POOR JOB OF COMPLYING TO GDPR, RETAILERS ARE BY FAR THE WORST OFFENDERS 40% MEDIA/TELCO/UTILITIES
  • 7. 88 GDPR COMPLIANCE – COMPLIANT COMPANIES 30%PROVIDED GDPR DATA UPON REQUEST WITHIN 30 DAYS 21THE AVG NUMBER OF DAYS IT TOOK COMPLIANT COMPANIES TO RESPOND 6%THE PERCENTAGE OF COMPLIANT COMPANIES THAT ASKED FOR AN EXTENSION* TO COMPLY *Allowed under article 12.3 of GDPR 22%THE PERCENTAGE OF COMPANIES THAT RESPONDED IN A 24HRS 65%THE PERCENTAGE OF COMPANIES THAT ANSWERED IN 10+ DAYS
  • 8. 99 ADDITIONAL EXPERIENCES • 7% of companies mistakenly assumed we were asking to be forgotten (half of them were hospitality leaders) • 4 companies actually deleted our account and data without notice • Some companies asked for a range of personal data before beginning our request (ID, loyalty number, birthday, data of transactions…) and then still didn’t comply • Virtually every company failed to fulfill our request for data portability • 4 companies asked “what do you mean by personal data”? • A leading global firm in the financial sector fulfilled our request by sharing the data they held on us through printed pages that they physically delivered through a secure mail courier. • Only a few delivered a 1-click memorable customer experience, including Spotify (Sweden), N26 (Germany), Garmin (US), and Next (Germany). They offered a clear explanation of their usage of our personal data, direct access to our data via a portal, and data portability.
  • 9. 1010 THE ROAD TO COMPLIANCE: WHY DO COMPANIES FAIL? • The majority of companies do not adequately track personal information • Lack accountability • Absence of Data Privacy Owner (DPO) • No department clearly appointed to answer requests • Lack data control and visibility • Can’t identify customers: some companies have requested personal data in order to start processing the requests • Can’t locate data or deleted data • Provided incomplete data sets (siloed data) • Lack proper processes or tools • Need for human data integrators • Companies are overwhelmed: fail to deliver after the extension with article 12.3
  • 10. 1111 OUR KEY TAKE AWAYS GDPR is seen as a legal project and not as a driver for better customer experience, Engagement, and trust LEGAL VS CUSTOMER How organizations empower data workers towards GDPR and the importance of having a data owner or controller DATA CULTURE/ DATA OWNERSHIP Customers data is siloed and the majority of companies do not know their customers CUSTOMER 360° Organizations do not have automated processes: GDPR is not a one-click process (human data integrator) AUTOMATION