• Latest

GDPR Is One Year Old. What’s the Impact?

June 5, 2019
Stock photo of a businesswoman viewed from behind, looking at a computer monitor displaying a red “Fraud Alert” warning with “Suspicious Activity Detected,” listing unusual login location, multiple failed attempts, and an unrecognized device.

81% of Finance Leaders Hit by AI-Generated Fraud Attempts, Certos Survey Finds

October 9, 2026
Stock photo of the bronze “The Department of the Treasury” sign outside the U.S. Treasury Building, with its columned facade and an American flag visible in the background.

Treasury’s Expanded Payment Verification Stopped $175M in Payments to Deceased Recipients

October 9, 2026
Digital Wallet Fraud Security: How to Secure Apple Pay, Google Pay, and Stored-Value Accounts

Digital Wallet Fraud Security: How to Secure Apple Pay, Google Pay, and Stored-Value Accounts

October 8, 2026
Stock photo of a FedEx Express delivery truck with a cardboard box in the foreground bearing a "Stripe | FedEx Dataworks" label, illustrating a partnership between the two companies.

Stripe and FedEx Dataworks Team Up on SMB Underwriting

October 8, 2026
Stock photo of two businesspeople shaking hands over a desk, with LegitScript and Kompliant branded folders, a pen, and a signed document on the table, and company logo banners in the background, symbolizing a partnership between the two compliance companies.

LegitScript Expands Merchant Underwriting With Kompliant Integration

October 8, 2026
Stock photo of a laptop displaying a "Fraud Monitoring" dashboard with a "Potential Fraud Detected" alert, a transaction overview chart, a donut chart showing 37% fraudulent, 12% at risk, and 51% approved, and a recent transactions list, with a person's hand holding a pen beside a stack of papers.

PYMNTS Study: Nearly Half of Firms Can’t Detect Fraud in Real Time

October 7, 2026 - Updated On October 8, 2026
Stock photo of an office desk with a white nameplate displaying the Plaid logo beside a stack of three wooden blocks labeled "AI," "Fraud Detection," and "Credit," each with a matching icon, evoking AI-driven fraud detection in financial data and credit services.

Plaid Launches AI Models for Credit and Fraud Detection, Cites Nacha Compliance Gap

October 7, 2026
Stock photo of an office desk with two acrylic nameplates displaying the Trustpair and Basware logos, alongside a shield padlock icon, a credit card, a pen, and a document, evoking a fraud prevention and payment security partnership.

Basware Completes Acquisition of Trustpair to Strengthen Fraud Prevention

October 7, 2026
Stock photo of a smartphone and laptop on a desk, surrounded by glowing icons (social, gaming, cryptocurrency, shopping cart, bank, hospitality, airline, wireless signal) radiating from a central red shield with an exclamation mark, symbolizing fraud risk across high-risk industries such as gaming, crypto, travel, and online retail.

8 High-Risk Industries Most Targeted by Fraud in 2026

October 6, 2026
Close-up stock photo of a smartphone on a wooden desk displaying an incoming call screen labeled "Unknown Caller," with a generic contact icon and red/green decline and accept buttons, illustrating the risk of voice phishing (vishing) scam calls; a laptop, mug, notebook, and pen sit nearby.

What Is Voice Phishing (Vishing) and How to Train Your Team to Spot It

October 6, 2026
Messy desk piled with compliance notices, surcharging regulation updates, and a merchant processing agreement, beside an ISV compliance manual, a calendar marked with new rule dates, and a 'Small Business Owner' mug.

State Surcharging Rules Multiply, Squeezing Merchants and ISVs

October 5, 2026
Refund form under a magnifying glass beside wooden blocks reading 'AML,' 'Monitoring,' and 'Risk,' with shipping boxes and a credit card nearby.

Refund Fraud Is Pointing to a Blind Spot in AML Monitoring

October 5, 2026
  • Contribute
  • Contact Us
  • About
  • Join Us
  • Advertise
Sunday, October 11, 2026
Merchant Fraud Journal
ADVERTISEMENT
  • Home
  • Articles
    • Chargebacks
    • Fraud Prevention
    • Influencer Insights
  • Resources
    • Recorded Webinars
    • Podcasts
    • Vendor Directory
    • eCommerce Fraud Reports
    • Training and Certifications
    • Jobs Board
    • Associations and Non-Profits
  • News
No Result
View All Result
  • Home
  • Articles
    • Chargebacks
    • Fraud Prevention
    • Influencer Insights
  • Resources
    • Recorded Webinars
    • Podcasts
    • Vendor Directory
    • eCommerce Fraud Reports
    • Training and Certifications
    • Jobs Board
    • Associations and Non-Profits
  • News
No Result
View All Result
Merchant Fraud Journal
No Result
View All Result

GDPR Is One Year Old. What’s the Impact?

Last Updated on June 5, 2019 by

Enforcement of the General Data Protection Regulation (GDPR) is one year old. This new pan European Union (EU) legislation is intended to protect consumers’ data by standardizing data capture and storage practices across all businesses operating within the EU. Specifically, it regulates the way companies of a certain size can collect, process, and store consumer data.

But since its inception, the legislation has been a cause of concern for merchants. For starters, the definition of “personal data” under Regulation (EU) 2016/679 encompasses “any information relating to an identified or identifiable natural person”. In other words, anything about anyone.

Statutory Definitions Unclear

Adding to the complication is the fact that the Regulation threatens large penalties for data breaches. Specifically, it establishes the possibility of eight-figure fines, or in the worst cases, even entire percentages of revenue:

Non-compliance with an order by the supervisory authority as referred to in Article 58(2) shall, in accordance with paragraph 2 of this Article, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher.

Adding to the trifecta of misery is the amazingly vague definition of what constitutes a data breach. The text defines it as “a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed”. Again, a definition that encompasses almost anything.

Finally, each individual EU member state is empowered to interpret the law as they see fit. All told, there was a lot of uncertainty about how the Regulation would play out in practice. One year on, the outlines of what we can expect moving forward have already begun to take shape.

Unfortunately, the European Data Protection Board (EDPB) does not have any uniform standards for how member states must report data. That makes it difficult to gauge the impact. However, the implementation reports published by the EDPB give some indication. The reports show EU citizens made nearly 100,000 complaints since May 2018. That number includes almost 65,000 claimed data breaches.

GDPR Penalties So Far

One year on, it appears fears of the ambiguity and large compliance fines is warranted. National governments imposed hundreds of fines on companies for a variety of violations, including:

  • €80,000 for publishing personal health data onto the internet
  • €20,000 for not hashing stored passwords
  • €50,000,000 for unauthorized processing of personal data (by Google)

In addition, the European Data Protection Board (EDPB) recently published information about the scope and size of fines. The first heading of the text ominously reads “expect more GDPR fines in 2019.” It goes on to tout that Poland levied its first fine of €220,000 for public data scraping. The message that the regulation is here to stay is clear.

What Is the Future of GDPR?

Which raises the question of where we go from here. GDPR’s goal is to harmonize the law between all EU countries. This is in the best interests of individuals and companies. In fact, Article 63 of the Regulation states:

“In order to contribute to the consistent application of this Regulation throughout the Union, the supervisory authorities shall cooperate with each other and, where relevant, with the Commission, through the consistency mechanism as set out in this Section.”

However, it’s already obvious that different member states will levy fines differently. A board does exist to eliminate ambiguity, but it’s unclear what practical effect it will have. There is already a huge discrepancy in the size of fines and level of scrutiny. It is clear it will be a long time before all of the ambiguity is eliminated.

It is encouraging that clarity this is one of the stated goals for the future. In addition to closer cooperation and communication, the EDPD recently stated:

“Another opportunity is to adopt consistency opinions and decisions. These decisions mainly address the national supervisory authorities and ensures a consistent application and enforcement of the GDPR.”

It will take time for this to materialize. Hopefully, reporting will be more systematic and robust in the near future. It will also be helpful if member states communicate between one another and standardize their interpretations of the law.

Whatever form it takes, the hope is year two of GDPR will bring more clarity. In the meantime, businesses must continue to do their best to protect consumer data from account takeovers and other attacks.

Tags: GDPR
TweetShareSend
Previous Post

BalBix Releases New Report: How to Use AI to Tackle Cyber-Security Challenges

Next Post

PayPal Commerce Platform Launches

Next Post

PayPal Commerce Platform Launches

Search:

No Result
View All Result

Our Latest Reports

Fraud Trends Report

Consumer Payments Survey Report

Fraud Prevention Tactics that Enable Exceptional Customer Experience

ATO Fraud In Retail Report

3 Ways a Unified Chargeback Management and Fraud Platform Increases Revenue

Digital Trust And Safety Report: Combating the Evolving Complexities of Payment Fraud

On-Demand Webinars

New Trends in The Payments Ecosystem

Balancing Customer Experience and Fraud Prevention: What’s the Secret?

Stopping Fraud Across the Customer Lifecycle

Addressing Payment Fraud and the Customer Experience in 2022

 

Quick Navigation

  • Home
  • News
  • Join Us
  • About Us
  • Contact Us
  • Advertise
  • Contribute
  • Privacy Policy

Privacy Policy

Our Privacy Policy
Our Terms of Use

Resources

  • Articles
  • eCommerce Fraud Reports
  • eCommerce Fraud Webinars
  • Associations and Non-Profits
  • Podcasts
  • Vendor Directory
  • Chargeflow – AI Chargeback Management

Featured Vendors

  • Signifyd
  • TransUnion
  • PayRetailers
  • Spotrisk
  • CB-ALERT
  • Chargeflow
  • Corepay
  • AtData
No Result
View All Result
  • About Merchant Fraud Journal
    • Interested in Contributing or Guest Posting to Merchant Fraud Journal?
    • Merchant Fraud Journal Editorial Guidelines
  • Advertise on Merchant Fraud Journal
  • Articles
    • Chargebacks
    • Fraud Prevention
    • Influencer Insights
  • Contact Us
  • Download Addressing Payment Fraud and Customer Experience Report
  • Download Chargebacks Consumer Survey Report 2022
  • Download Evolving Complexities of Payment Fraud Report
  • Download Fraud Prevention Tactics that Enable Exceptional Customer Experiences Report
  • Download Merchant Fraud Journal 2023 Fraud Trends Report
  • Download Merchant Fraud Journal 2024 Fraud Trends Report
  • Download Merchant Fraud Journal Generative AI Fraud Prevention Checklist for SMBs
  • Download Quantifying the Challenge of Friendly Fraud: Your Post-purchase Strategy for the Future
  • Download the 2020 Chargeback and Representment Report
  • Download the 2020 Merchant Fraud Journal Vendor Guide
  • Download the 2021 Fraud Trends Report
  • Download the 2022 Fraud Trends Report
  • Download the 2023 Consumer Payment Trends Report
  • Download the 3 Ways a Unified Chargeback Management and Fraud Platform Increases Revenue Report
  • Download the MFJ 2022 Customer Experience Report
  • Download the MFJ ATO in Retail Report
  • Home
  • Home Elementor
  • Job Dashboard
  • Join The Merchant Fraud Journal Community
  • Merchant Fraud Journal Advertising Agreement
  • Merchant Fraud Journal Advertising Agreement – Signifyd
  • MFJ Fraud Trends Report Giveaway
  • News
  • Post a Job
  • Privacy Policy
  • Resources
    • #9978 (no title)
    • 2020 Chargeback Representment Guide for Merchants
    • 2020 Vendor Guide
    • 2023 Consumer Payments Survey Report
    • 3 Ways a Unified Chargeback Management and Fraud Platform Increases Revenue
    • 8 Fraud Prevention Training and Certifications: A 2026 Guide
    • Addressing Payment Fraud and the Customer Experience in 2022
    • Associations and Non-Profits
    • ATO Fraud In Retail Report
    • Balancing Customer Experience and Fraud Prevention: What’s the Secret?
    • Chargebacks Consumer Survey Report 2022
    • Digital Trust & Safety: Combating the Evolving Complexities of Payment Fraud
    • eCommerce Fraud Reports
    • eCommerce Fraud Webinars
    • Fraud Prevention Tactics that Enable Exceptional Customer Experiences
    • How to Build a Recession Proof Chargeback Prevention Strategy
    • How to Reduce Customer Friction During Holiday Sales Season
    • How to Stop Fraud During the 2022 Holiday Season
    • Jobs Board
    • Merchant Fraud Journal 2023 Fraud Trends Report
    • Merchant Fraud Journal’s Fraud Trends 2020 Report
    • Merchant Fraud Journal’s Generative AI Fraud Prevention Report: A Checklist for SMB Companies
    • Merchant Fraud Journal’s Fraud Trends 2021 Report
    • Merchant Fraud Journal’s Fraud Trends 2022 Report
    • MFJ’s 2022 Customer Experience Report
    • Podcasts
    • Prevent High-Velocity Fraud Attacks During the 2021 Holiday Season
    • Quantifying the Challenge of Friendly Fraud: Your Post-purchase Strategy for the Future
    • Stopping Fraud Across the Customer Lifecycle
    • The surprisingly easy way to secure your payment data, reduce your risk, and win the war on ecommerce fraud
    • Vendor Directory
    • Webinar – Addressing Payment Fraud and the Customer Experience in 2022
    • Webinar – Mitigating Fraud and Risk on the ACH Network
    • Win January Chargeback Disputes
  • Subscribed
  • Terms and Conditions

© 2026 Merchant Fraud Journal

Not enough quota to unlock this post
Unlock left : 0
Are you sure want to cancel subscription?