Skip to main content
QUICK REVIEW

[Paper Review] Are we there yet? Understanding the challenges faced in complying with the General Data Protection Regulation (GDPR)

Sean Sirur, Jason R. C. Nurse|arXiv (Cornell University)|Aug 22, 2018
Privacy, Security, and Data Protection6 references18 citations
TL;DR

This paper investigates the real-world challenges organizations faced in complying with the EU's General Data Protection Regulation (GDPR), drawing on interviews with diverse organizations. It finds that large firms and security-focused SMEs managed compliance effectively, while general SMEs struggled due to the regulation's breadth, ambiguous language, and complex data mapping requirements, highlighting a critical need for targeted support and clearer implementation guidance.

ABSTRACT

The EU General Data Protection Regulation (GDPR), enforced from 25th May 2018, aims to reform how organisations view and control the personal data of private EU citizens. The scope of GDPR is somewhat unprecedented: it regulates every aspect of personal data handling, includes hefty potential penalties for non-compliance, and can prosecute any company in the world that processes EU citizens' data. In this paper, we look behind the scenes to investigate the real challenges faced by organisations in engaging with the GDPR. This considers issues in working with the regulation, the implementation process, and how compliance is verified. Our research approach relies on literature but, more importantly, draws on detailed interviews with several organisations. Key findings include the fact that large organisations generally found GDPR compliance to be reasonable and doable. The same was found for small-to-medium organisations (SMEs/SMBs) that were highly security-oriented. SMEs with less focus on data protection struggled to make what they felt was a satisfactory attempt at compliance. The main issues faced in their compliance attempts emerged from: the sheer breadth of the regulation; questions around how to enact the qualitative recommendations of the regulation; and the need to map out the entirety of their complex data networks.

Motivation & Objective

  • To understand the practical challenges organizations encountered when interpreting and implementing GDPR, particularly in translating its qualitative requirements into technical and operational practices.
  • To assess the feasibility of GDPR compliance across different organizational sizes and security maturity levels, especially in the context of limited resources and complex data ecosystems.
  • To examine how organizations perceived GDPR, their awareness levels, and expectations regarding enforcement and penalties.
  • To investigate the implementation processes, support mechanisms sought (e.g., governmental, industrial, academic), and methods used to verify compliance.
  • To identify systemic barriers—especially for SMEs—impeding effective compliance and to inform future regulatory design and support frameworks.

Proposed method

  • Conducted semi-structured interviews with multiple organizations across different sectors and sizes, focusing on their GDPR compliance journey.
  • Combined qualitative interview data with a review of existing literature and regulatory texts to contextualize organizational experiences.
  • Focused on understanding how organizations interpreted GDPR’s qualitative language, mapped data flows, and implemented technical and organizational measures.
  • Analyzed organizational responses to identify patterns in compliance maturity, resource allocation, and challenges related to regulation breadth and ambiguity.
  • Evaluated the role of external support—especially governmental guidance—in enabling compliance, particularly for less mature organizations.
  • Used thematic analysis to identify recurring challenges and success factors across organizations, with attention to differences between large firms and SMEs.

Experimental results

Research questions

  • RQ1How do organizations perceive the feasibility and clarity of GDPR’s requirements, especially its qualitative recommendations?
  • RQ2What are the primary challenges organizations face in mapping their data flows and implementing GDPR-compliant controls?
  • RQ3How do organizational size and security maturity influence the ability to achieve GDPR compliance?
  • RQ4What types of support (governmental, industrial, academic) do organizations seek, and how effective are they in facilitating compliance?
  • RQ5How do organizations verify their compliance, and what are the limitations of these verification processes?

Key findings

  • Large organizations and SMEs with a strong focus on data protection found GDPR compliance to be reasonable and achievable, indicating higher compliance maturity.
  • General SMEs without a dedicated security or privacy focus struggled significantly, often unable to make a satisfactory compliance effort due to resource and expertise constraints.
  • The primary challenges stemmed from the regulation’s broad scope, the ambiguity of its qualitative requirements, and the complexity of mapping extensive and often fragmented data networks.
  • Many organizations found it difficult to interpret and operationalize GDPR’s principles, especially where no clear technical mappings existed, leading to inconsistent implementation.
  • External support—particularly from governmental bodies—was identified as crucial, especially for less mature organizations, though industrial and academic support also played a role.
  • The study suggests that GDPR’s flexibility in interpretation, while beneficial for mature organizations, created a barrier for SMEs lacking the expertise to navigate it independently, risking a compliance gap between organizational types.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.