Do British businesses have a clue regarding corporate policy and GDPR?


Today, new research has revealed that large British businesses are facing three major obstacles to EU General Data Protection Regulation (GDPR) compliance: data sprawl, a huge influx of personal customer information and uncertainty around data ownership.

In fact, these British businesses appear to be facing an uphill struggle to achieve GDPR compliance, with many left managing end users’ personal data across 24 different systems and a network of 48 other companies on average.

>See also: GDPR compliance: what organisations need to know

The research – commissioned by Citrix and carried out by One Poll – quizzed 500 IT decision-makers in companies with 250 or more employees across the UK to pinpoint the hidden obstacles still facing British businesses when it comes to GDPR compliance.

The research offers a snapshot of the extent to which large UK businesses recognise ownership of customers’ personal data, how much personal data they are collecting and if they have plans in place to ensure compliance around this data.

Data sprawl

Surveyed UK businesses are facing a major challenge to GDPR compliance: controlling huge amounts of data across disparate systems. According to the study, while the average large UK business now uses 24 systems to manage and store personal data, one in five (21 per cent) use over 40 systems to do so.

>See also: Is your business GDPR compliant? Probably not…

Additionally, almost half (47%) of the respondents share personal data from customers with other businesses – severely adding to data sprawl. On average, they share this data with 48 other businesses but nearly half (48%) of businesses admitted to sharing this data with over 50 businesses. While the majority believe they retain complete control over this shared data, 15 per cent admit to losing at least a degree of control over data once it has been shared.

Information overload

On average, large UK businesses that responded to the survey collect personal data from 577 individuals each day. However, more than one in four (26 per cent) large businesses collect personal data from over 1,000 individuals every 24 hours – creating a huge influx of data to store and manage in the enterprise.

Over half (58%) of the respondents admit to storing personal data for over a year yet a quarter (25%) end up storing personal data for over five years. Despite this, two fifths (40%) of respondents admitted that not all the personal data stored is actually used by the business while almost one in ten (8%) admit they never use any of the personal data they store.

Division on data ownership

Almost two thirds (65%) of the firms surveyed store and manage personal data based on predictive analytics but, interestingly, businesses could not agree on who owned this data. Only a quarter (27%) of businesses believe this data is owned by the customer while half (50%) think it belongs to the organisation.

>See also: Operating a successful data management strategy

Understanding data ownership and accountability is one initial key step in the journey to GDPR compliance. So, perhaps unsurprisingly, almost two fifths (38%) of respondents acknowledge that they are not ready for the GDPR, either admitting that current control access policies are insufficient to comply with the regulation or they have ‘no idea’ whether they meet the regulation’s standards.

In fact, just half (52%) of the large UK businesses surveyed carry out data privacy impact assessments for all or most personal data stored by the enterprise – an essential step to implementing policies which ensure data privacy.

Chris Mayers, chief security architect, Citrix, said: “The GDPR will do far more than strengthen data privacy rights. The regulation will set a high bar for responsibility and accountability – and not one that every business will meet. While many British organisations are taking steps to achieve compliance in time for the May 2018 deadline, our research clearly reveals some significant obstacles, including uncontrolled data sprawl and lack of understanding around data ownership.”

“Ensuring data privacy processes and systems are in place – from privacy by design to privacy by default – requires an organisation to know exactly where their data is and who can access it. Yet many are losing sight of data, spread across multiple systems and shared with multiple partners, while also struggling to scale up to store and control the huge influx of personal customer data they receive today.”

>See also: The information age: unlocking the power of big data

“Businesses must recognise that more centralised application and data storage environments will make it easier to meet technical compliance goals. This centralisation can be achieved in various ways, from introducing unified access controls across on-premise and cloud services with single sign-on to rolling out centrally-managed virtual workspaces. However it is done, controlling data sprawl and recognising enterprise accountability around data privacy will be key to GDPR compliance.”


The UK’s largest conference for tech leadershipTech Leaders Summit, returns on 14 September with 40+ top execs signed up to speak about the challenges and opportunities surrounding the most disruptive innovations facing the enterprise today. Secure your place at this prestigious summit by registering here

Avatar photo

Nick Ismail

Nick Ismail is a former editor for Information Age (from 2018 to 2022) before moving on to become Global Head of Brand Journalism at HCLTech. He has a particular interest in smart technologies, AI and...

Related Topics