Survey Reveals Nine Out of Ten Businesses Are Not Ready for New Data Rules
A survey by leading law firm Blake Morgan has revealed nine out of 10 businesses have still not made crucial updates to their privacy policies – a key requirement ahead of major changes to data protection laws.
As time runs out to comply with the General Data Protection Regulation (GDPR), the survey found many organisations may be at risk of non-compliance, risking regulatory action and reputational and brand damage for not getting their house in order.
With the massive growth of the digital economy, GDPR represents the biggest shift in data protection for many years and all organisations which retain or process personal information will need to comply. The new law focuses on greater transparency as to how personal data is collected, retained and processed, makes organisations more accountable and gives enhanced rights to those whose personal data is being collected and processed.
It is backed up with a significantly higher fines regime for the most serious breaches of up to £17m or 4% of worldwide turnover (whichever is greater) and a requirement to notify personal data breaches within 72 hours where they are likely to result in a risk to people’s rights and freedoms.
Blake Morgan’s research revealed just over 10 per cent of those surveyed had updated their privacy policies to comply with the new law, while only a quarter had put in place systems to ensure data security breaches were notified in line with GDPR.
The findings showed almost 40 per cent of organisations surveyed had not taken steps to prepare for the new regulations, while more than a third were not confident they would be able to comply with GDPR by 25th May next year when the law comes into force.
A key finding was that just over a fifth of businesses surveyed were not aware of GDPR and the forthcoming and related ePrivacy Regulation and what these will mean for their organisation.
Simon Stokes, a Partner specialising in data protection law at Blake Morgan, said: “Our survey highlights that a significant proportion of organisations across the public and private sectors are still underprepared for these major changes to data protection law.
“There appears to be a genuine confusion among many business leaders about what the new law means and how to achieve full compliance.
“Some of the survey comments highlight a desire for clearer guidance and the mountain of work that many organisations believe they are facing because of the sheer volume of data and a limited timescale.
“With the clock counting down to the law coming into force, we would recommend a focused effort by businesses to get to grips with the changes and implement a strategic plan of action.
“GDPR Compliance is good corporate housekeeping. Not only will it avoid running the risk of financially and reputationally damaging fines or sanctions – ultimately it will assure the public’s trust in your organisation at a time when data privacy and security are more important than ever before. As the UK’s data protection regulator ICO has recently highlighted GDPR is essentially about trust.”
Important findings included:
- Only around one in 10 businesses (13 per cent) had updated privacy policies, one of the significant requirements of GDPR.
- Almost a quarter of businesses (23 per cent) said they were unaware of the new data protection laws despite the looming deadline of 25 May 2018.
- Around four out of 10 businesses (39 per cent) had not taken any steps at all to prepare for the new law – leaving just months to act.
- Around four out of 10 businesses (38 per cent) were not confident they would be able to comply with GDPR by 25 May.
- Around one in five businesses (21 per cent) did not currently have a senior person in place responsible for data protection.
- More than three quarters of businesses (76 per cent) had not put in place systems to ensure data security breaches are notified in line with GDPR.
- More than three quarters of businesses (77 per cent) had not reviewed their data processing contracts which will be under greater scrutiny under GDPR.
- More than four out of 10 businesses (42 per cent) were unaware that the rules on direct marketing and the use of internet cookies are likely to change with the forthcoming ePrivacy Regulation which also has a target implementation date of 25 May 2018.
Blake Morgan has launched a free guide, GDPR: A Practical Guide to Achieving Compliance, which gives detailed analysis on key changes on the way and helpful advice on actions businesses can take.
Blake Morgan is the only law firm accredited to provide the BCS Certificate in Data Protection course, which is an intensive five-day course leading to a professional qualification (on successful completion of an externally marked exam). The qualification is ideal for anyone with data protection responsibilities, particularly those taking on the Data Protection Officer role under the GDPR.
Blake Morgan’s data protection and regulatory experts are available to answer questions from organisations about GDPR at GDPR@blakemorgan.co.uk
To download a free copy of the guide visit www.blakemorgan.co.uk/GDPR.
More in Solicitors
Freeths backs next generation of female leaders through ongoing Women of...
Leading law firm Freeths is continuing its support for the Women of the Year (WOTY) Awards 2026, as the search begins for women making a meaningful impact across business and society. Now in its 44th year, Women of the Year remains one of the UK’s longest‑standing platforms for celebrating female achievement. Freeths is once again […]
B4 welcomes the renewed membership of Jenny Harvey Immigration
Jenny Harvey Immigration is a niche immigration law firm advising Oxfordshire-based businesses and individuals, with clients spanning the globe. Jenny has lived and worked in Oxford for over forty years and has run her own firm for almost a decade. As a sole practitioner, she enjoys the flexibility her role offers—whether that’s speaking with US-based […]
The Renters’ Rights Act comes into force this Friday, 1 May...
The Renters’ Rights Act, which is designed to give residential tenants better protection, comes into force on Friday and applies to both existing and new tenancies. The new regulations do not currently apply to social housing or lodgers. The Act is being implemented in phases. The main changes on Friday will be: • All assured […]
From this author
Devolution and Local Government Reform in Oxfordshire and beyond
Our final OBS2026 Impact Session focused on the future governance of Oxfordshire, bringing together business leaders, council officials and policymakers to explore opportunities for regional growth and development.
Blake Morgan renews B4 membership to help strengthen business relations
Blake Morgan has renewed their membership of the B4 Business Community, helping to strengthen their business relationships in the Thames Valley.
80TH BIRTHDAY CELEBRATIONS FOR OXFORD PARTNER AFTER 46 YEARS AT LAW...
This month an institution in the Oxford legal sector, John Deech, has celebrated his 80th birthday, which comes as he remains an active full-time partner at law firm Blake Morgan. John’s colleagues threw him a surprise birthday party – reflecting on the almost 50 years he has worked at the firm and marking this milestone.

