GDPR Breach Notifications in 25 Member States, August 2019

Latest BPM Index update shows continued disparity in the number of breaches across EEA Member States

August 2019 figures for BPM Index (with information from 25 EEA Member States) shows continued, consistent disparity among Member States on number of personal data breach notifications per million of population and per million of businesses.

[29 October update to August 2019 figures to include figures for 25 EEA Member States.]

As always, we’re very grateful to the DPAs, who provide us with their monthly figures.  This update includes monthly figures for 22 Member States in August 2019 and the GSheet has monthly figures we’ve received from DPAs up to and including August 2019.  As always, we welcome input from all Member States.

So, what does the update say?  Well, notifications to data protection authorities (‘Notifications’) haven’t been on summer holiday.  After 18 months, it looks like the notification rates are pretty steady.  The UK, Ireland and Denmark still consistently record larger numbers of notifications, with Ireland and Denmark staying high when you normalise for millions of businesses and population.  Some larger countries remain far lower.

Examples from August 2019:

  • the UK had 930 Notifications (the highest in the 20 countries that month), giving a BPM Pop of 14 and BPM Biz of 377,
  • Denmark had 597 Notifications, giving a BPM Pop of 103 and BPM Biz of 2,665 (the highest in the 20 countries that month),
  • Ireland had 510 Notifications, giving a BPM Pop of 105 (the highest in the 20 countries that month), and BPM Biz of 2,040, whereas
  • Spain had 42 Notifications, giving a BPM Pop of 1 (the equal lowest in the 20 countries that month) and BPM Biz of 14 (the 2nd lowest in the 20 countries that month).

And comparing that with November 2018, and including France for that month:

  • the UK had 1,183 Notifications, giving a BPM Pop of 18 and BPM Biz of 480,
  • Denmark had 403 Notifications, giving a BPM Pop of 70 and BPM Biz of 1,799,
  • Ireland had 409 Notifications, giving a BPM Pop of 85, and BPM Biz of 1,636, whereas
  • France had 167 Notifications, giving a BPM Pop of 3 and BPM Biz of 47, and
  • Spain had 73 Notifications, giving a BPM Pop of 2 and BPM Biz of 24.

Please do review the underlying data and join in the conversation!

#BPMIndex

bpm@keepabl.com


Related Articles

Blog Case Studies Downloads News & Awards
Times Higher Education chooses Keepabl to manage GDPR

Times Higher Education is the world-famous provider of insights on all things Higher Education, with almost 5 decades of experience. Their data and benchmarking tools, and their consultation offerings, are…

Read More
News & Awards
CNIL fines Google & Amazon €135m on cookie fails

Lessons from French data protection authority’s record fines on Google, Amazon for basic cookie failures Originally published by Thomson Reuters © Thomson Reuters. Lessons from French data protection authority’s record…

Read More