DataAI & Technology

GDPR in its 8th year: experts offer their thoughts on data protection regulation today

Eight years after GDPR came into force, we can see that it’s had far-reaching impacts across industries. Through its enforcement, GDPR has helped uphold a new era of reliability and trust with data protection and transparency. For GDPR, its influence extends far beyond data privacy compliance. Widely regarded as one of the world’s most significant pieces of digital regulation, GDPR has reshaped how organisations approach governance, accountability and customer trust.  

Now we’re nearly a decade on from its inception. And, as businesses navigate an increasingly complex landscape of AI, cyber resilience and emerging regulations, industry leaders reflect on the lasting lessons of GDPR. Four experts from Vanta, PagerDuty, Pipedrive and Bitpace weigh in on GDPR and why its principles remain as relevant today as they were in 2018. 

New standards of transparency 

Matt Cooper, Director, GRC at Vanta said: “GDPR helped establish transparency, accountability and responsible data governance as business priorities. But the rise of AI is creating new challenges around privacy, oversight and risk management, while placing additional pressure on already stretched teams.  

“The organisations that will succeed are those that treat compliance as an ongoing business discipline rather than a one-off exercise. Automation can help organisations keep pace with growing regulatory demands, but accountability for how data is governed and used cannot be outsourced.” 

Building trust in today’s business landscape 

Lee Fredricks, Director Solutions Consulting, EMEA, PagerDuty said: “The introduction of GDPR caused an enormous business reaction, shifting the topic of privacy from a compliance concern to a trust issue. Organisations that managed this efficiently learned lessons in change management and positioned themselves well for the challenging digital landscape that followed: hybrid and cloud environments, interconnected systems, further regulations like DORA and the EU AI Act and, now, AI. 

“Digital operations that are strong, resilient, adaptable, and capable of learning provide the link between policy, business, technology, and response. Organisations now struggling to balance these in the age of AI are those still relying on manual handovers, unclear accountability, and retrospective reporting. They suffer from poor digital operations and resilience, not having learned the underlying benefits that came from embedding GDPR principles into day-to-day operations. 

“The great legacy of GDPR is that strong organisations know that compliance is not a once-a-year exercise. They demonstrate their maturity every time they detect, respond to, and learn from a digital incident safely while maintaining customer and organisational data security. Trust is built through operational performance so treating privacy, resilience, and incident response as connected disciplines enables organisations to meet regulatory expectations, strengthen operational resilience and grow customer confidence.

Managing customer data the right way  

Sean Evers, VP of Sales and Partner, Pipedrive said: “GDPR had a silver lining for responsible organisations as it forced businesses to treat customer data as a responsibility rather than a mere growth asset. That helped sales teams to use data to build better relationships as opposed to increasing outreach volume at the cost of their prospects’ inboxes. Managing customer data goes hand in glove with nurturing long-term relationships. 

“CRM data can run the risk of becoming messy or disconnected from customer context. Poor permissions, unclear consent and blanket outreach create compliance risks and make sales feel less human. And in a world where automation can do so much in business, real relationships carry a deeper meaning. Sales teams using CRM data well should know when a customer last engaged, what they care about and whether follow-up is appropriate, rather than treating every contact as a target for another generic email. 

“The legislation helped show those who really engaged with it that that relevance, respect and trust are commercial advantages. Good data practice should make customer relationships stronger, showing respect and consideration.” 

GDPR in industry: how is it impacting crypto? 

Can Taner, Chief Product Officer, Bitpace said: “GDPR’s anniversary is a reminder of how far data protection regulation has raised global standards for data privacy, accountability and transparency. For the crypto industry, these principles and values are crucially important. Trust is not built through blockchain security alone. It also depends on the diligence, governance and operational controls that organisations put in place to protect users, merchants and partners. 

“For crypto businesses, this means security and data governance cannot sit apart from the core product. They need to be embedded across operations, from how customer information is collected and stored, to how payments, exchanges and merchant relationships are managed. Blockchain may bring greater transparency at the transaction level, but businesses still need robust controls and clear compliance frameworks to protect personal and financial information. 

“Strong data practices are also an enabler of growth. When users, merchants, and institutional partners are confident their information is being handled responsibly, it supports adoption and helps bridge the gap between traditional finance and digital assets. For the crypto market as a whole, sustainable growth depends on the industry’s ability to prove that security, privacy and accountability are built into its foundations.” 

What lies ahead for GDPR 

There’s a lot to unpack with where GDPR has been and where it’s going. While the regulatory landscape has evolved considerably since GDPR’s introduction, experts agree its core legacy lies in the perception shift around compliance. Rather than seen just as a tick-box legal obligation, compliance is recognised as a driver of trust and operational maturity.  

Alongside enforcing stricter standards on data protection, lessons have been learned for other key pieces of legislation. The central tenets of GDPR have also been brought into the AI age. Now, the organisations that continue to embed GDPR’s principles into everyday operations are better positioned to meet future regulatory demands.

Whether an organisation is managing AI systems, strengthening cyber resilience or securing digital assets, which broadly are all forms of data handling, GDPR provides oversight that puts customer priorities in the forefront. Moving forward, maintaining a strong adherence to GDPR will prove critical as organisational leaders look to maintain a competitive edge in the market, all while building lasting confidence among customers, partners and stakeholders. 

Related Articles

Back to top button