Macroeconomic Monitor
Home / Economy / European companies will spend €200 billion on GDPR compliance

European companies will spend €200 billion on GDPR compliance

Author: Georgi Georgiev

Companies in the European Union are expected to spend around €200 billion to bring their personal data processing and storage procedures into line with the General Data Protection Regulation (EU 2016/679). This is around 4 times the estimated GDP of Bulgaria for 2017.

The regulation comes into effect in a few days on May 25, 2018, and carries heavy fines – up to 4% of the global turnover of an offending company, or up to 20 million euros (whichever is greater).

For Bulgarian companies, costs are expected to be lower than the EU average due to the lower cost of labor and services (legal, accounting, IT costs). A small, non-representative survey among owners of small and medium-sized Bulgarian companies shows that two-thirds of them have invested or expect to invest between 5,000 and 10,000 leva, and one-third – under 5,000 leva. The costs for large enterprises are, of course, much higher, with companies in the financial and IT sectors being the most affected.

Companies from the rest of the world will also have to comply with the new EU rules. Estimates show that in the US alone, companies will spend nearly $41.7 billion to comply with the new regulation.

The data comes from a study by GIGAcalculator.com and is based on surveys of CEOs, CIOs, and CTOs of companies from the US, UK, and Japan, combined with extrapolation of data based on business statistics from Eurostat and the US Census Bureau.

For comparison, with the costs that will go to comply with GDPR, we could build about 66.5 million houses for the poor in Africa (unit price $3,600 according to the website of the largest charitable foundation in the US). Using an interactive tool for calculating the cost of GDPR, you can visualize the cost of this legislation by comparing it with other goods and services, for example, with the number of new smartphones, the number of food packages for the poor, or even the number of scientific research to fight cancer that could be funded with these amounts:

Of course, the cost itself is not a problem, the problem is what it is used for and to what extent it represents lost productivity or a meaningful investment. And how can we judge the need for such regulation, if not by the market? If there was a real need that this regulation satisfies, there would already be a popular market solution for it. The name of the most popular such solution is DuckDuckGo – a search engine whose main marketing advantage is that it does not collect data about you. However, how many of you have heard of it, even though it has been around for 10 years? And how many use it instead of the leader Google?

Another way to achieve relative anonymity is VPN (Virtual Private Network). Although their popularity has increased in recent years, they are still mainly used by companies concerned about the security of their data and systems against attacks that have little to do with the GDPR.

Let's think about one of the main rules in the GDPR – the "right to be forgotten", i.e. asking a company to remove the data about you they have. It has two main practical applications: if you don't want to receive spam and if you want a major social network to not just delete/deactivate your account, but also to remove all traces of it except as required by law.

Obviously, in the first case, this regulation will not help, because despite many regulations, spam continues to exist and spammers continue to operate as legitimate companies. The situation is the same as with the gun ownership regime - criminals will continue to acquire and use weapons regardless of the laws.

For the second case – no company wants their support department to be overwhelmed with data deletion requests and their engineers to manually clean up complex databases of your information. If there were a noticeable percentage of such requests from customers, these procedures would be automated and made available to users anyway.

From this position, I see 90% to 100% of the costs related to GDPR as a pure waste of productivity, and the productivity of some of the most capable among us: engineers, IT specialists, lawyers, accountants. And the bigger and more successful the company, the more it is affected. In this sense, I expect this new regulation to have an effect similar to the previous one, the so-called "cookies law" on websites, but ten times worse. If the main problem with the previous one was a little more costs for businesses and the inconvenience for users to have their screen occupied by pop-up windows from above, below and on the sides asking "Do you accept cookies to use our site?", now the damage will be much greater due to the much broader scope of the regulation, the draconian fines and the fact that it affects all companies, not just online businesses.

And in the end, as we well know, the end user bears the cost of everything.

 

Did you like it? Take a minute to support the EKIP on Patreon!
Become a patron at Patreon!

About Guest Author

Read more

Гренландия и илюзията за европейска отбрана

Между политическото желание за защита и правната възможност за такава зее пропаст – и именно …