• Career
  • Contact us
  • Support & Downloads
Home
/
Rethink Work blog
/
Security
/
Taking stock after 100 days: how are things going with GDPR?

Business Areas

Digital WorkplaceProfessional PrintingHealthcareTextile Printing Services

Corporate Information

CareerAbout usNewsWhistleblower HotlineSustainabilityWhere to buy

Global Information

Corporate InformationCompany OverviewBusiness UnitsSustainabilityInvestor RelationsTechnology

Konica Minolta Business Solutions Europe GmbH

Terms of Use|

Privacy Policy|

Imprint|

©2026 Konica Minolta Business Solutions Europe GmbH

  • Taking stock after 100 days: how are things going with GDPR?

    01 Sep 2018

    Before 25 May 2018, there was a lot of reporting and heated discussion about the upcoming implementation of GDPR and all its legal consequences – now, on 1 September, the European General Data Protection Regulation has already been in force for 100 days. Time for an initial review.

    Pscq77ipkp3pr0vovj1qcbi04v
  • The biggest challenge for small and medium-sized businesses – documentation and reporting procedures
  • Positive trend: three-quarters of all companies intend to fulfil the GDPR standards by the end of 2018

Taking 25 May 2018 as the first day of validity of the European General Data Protection Regulation (EU GDPR) following the two-year transition period, 1 September 2018 marks 100 days of the new law – an opportunity for an initial review. How are things going with the EU GDPR? Job Wizards listened to what people had to say and did some online research.

The biggest challenge for small and medium-sized businesses – documentation and reporting procedures

The 100-day review from the German Association for Small and Medium-sized Businesses (BVMW) is critical: ‘The authorities are overwhelmed as there are too few members of staff for the number of enquiries, entrepreneurs are still uncertain, as there are many unanswered questions about GDPR, and politicians don’t know what to do,’ reports Eberhard Vogt, Press Officer for the BVMW. He continues: ‘Many small and medium-sized businesses don’t know what they should and should not do according to the regulation: do I have to document this process? Do I have to register these plans with the authorities or not – which, by the way, is another reason the authorities are overwhelmed, because to stay on the safe side entrepreneurs are transferring almost everything. Furthermore, different interpretations of the regulation exist in the individual federal states.’ The provisional summary is: ‘What entrepreneurs need is a GDPR road map approved by all the authorities.’

Positive trend: three-quarters of all companies intend to fulfil the GDPR standards by the end of 2018

‘Small and medium-sized companies in particular had difficulty adjusting to the new General Data Protection Regulation rules. In many cases, it used up a lot of time, patience and money,’ says Fabian Wehnert, head of the department for small, medium-sized and family companies at the Federation of German Industries (BDI), regarding the experiences of SMEs in Germany. Nevertheless, the EU GDPR is ‘a milestone, as for the first time there is a shared data protection standard for all companies and all other institutions in Europe,’ Fabian Wehnert adds.

Apparently, most entrepreneurs share that view, as a study recently published in the USA* shows that – even if not all companies in Europe and the USA managed to implement GDPR on time by 25 May – 96% have begun implementation and 74% expect to meet the standards by the end of 2018. 93% intend to reach this goal over the course of 2019. An initial inventory with which data protectors can be very satisfied.

‘Small and medium-sized companies in particular had difficulty adjusting to the new General Data Protection Regulation rules. In many cases, it used up a lot of time, patience and money. At the same time, the actual sanctions threatened were – and are – nowhere near the horror scenarios that some had pictured beforehand.’
Fabian Wehnert, head of the department for small, medium-sized and family companies at the Federation of German Industries (BDI)

‘Within the course of EU GDPR, countless small businesses and associations deleted their websites for fear of reprimands. Did you expect that kind of reaction?’
Ansgar Skoda, freelance journalist, interviewing data protection expert Ralf Bendrath on Treffpunkteuropa.de

‘No, [we] really didn’t [expect] such extreme reactions. It really seems to be a particularly German phenomenon. We haven’t heard of anything like that from other EU member states. It seems a bit of targeted panic was stirred up.’
Ralf Bendrath, data protection expert and close colleague of Jan Philipp Albrecht, seen as one of the fathers of GDPR, on Treffpunkteuropa.de

Achieving and maintaining GDPR compliance is a complex and expensive initiative for companies of all sizes, across all geographies and industries. While only a small percentage (20%) reported being compliant by the May 25 deadline, almost all have started (96%), three quarters (74%) expect to be compliant by the end of 2018 and almost all (93%) expect to be fully compliant sometime in 2019.
From the conclusion of the July 2018 Research Report commissioned by TrustArc on ‘GDPR Compliance Status – A Comparison of US, UK and EU Companies’

‘We are closely connected to the European small and medium-sized businesses’ umbrella organisation European Entrepreneurs. There, it is clear: while Germany is taking care to adhere precisely to the regulations, not everywhere in Europe takes the same approach.’
Eberhard Vogt, Press Officer for the BVMW (German Association for Small and Medium-sized Businesses)

Digital monitoring company Catchpoint found that after GDPR went into full effect in late May, many EU site versions for US-based news organizations — suddenly unburdened by a huge number of third-party tags — started running much faster and delivering a better user experience.

‘This is a direct result of the fact that many external third-party elements previously integrated into these pages (which could impact user experience and performance) have been stripped away, including ad servers, Google services/analytics, social media plug-ins and more’
Catchpoint Chief Executive Mehdi Daoudi im Interview mit Martech Today Autorin Robin Kurzer

Share:

Related Topics

Rising Tariffs, Geopolitical Uncertainty, and Inflation: How Companies Can Become More Resilient Now
Rising Tariffs, Geopolitical Uncertainty, and Inflation: How Companies Can Become More Resilient Now
In an increasingly unstable world, businesses must be able to cope with difficult economic and political changes that can threaten their existence. Their business processes and systems must be resilient, but how can they achieve this?
The EU CSDDD: Responsibility along the supply chain
The EU CSDDD: Responsibility along the supply chain
Global supply chains are often linked to human rights violations and environmental damage. The new EU CSDDD directive now obliges companies to take responsibility—from raw material extraction to the final product. Find out what the directive means, who it affects, and why it is a crucial step toward greater sustainability and fairness. 
How can you ensure that you comply with EU e-invoicing regulations?
How can you ensure that you comply with EU e-invoicing regulations?
E-invoicing has become an important part of business interactions and there are further important changes taking place across Europe. What do you need to know about these changes and how can your business take full advantage of e-invoicing?