FF News Logo
Tuesday, February 24, 2026
FFNews x MoneyLIVE

A Quarter of UK Businesses Cancel Preparations for EU General Data Protection Regulation

Almost a quarter of UK firms have cancelled all preparation for the EU General Data Protection Regulation in the misunderstanding that it will not apply after Brexit.

The regulation, which has been years in the pipeline, is designed to harmonise data protection regulation throughout Europe and provide citizens with more control over their personal data.

It has been ratified by the UK and is due to come into force in May 2018 – almost certainly before Britain completes its exit from Europe, despite triggering Article 50 this week.

However a survey of IT decision makers at UK companies by information management experts Crown Records Management has revealed some shocking results.

It showed that:

  • 24 per cent of firms have cancelled all preparation for the regulation.
  • A further 4 per cent have not even begun preparation.
  • 44 per cent think the regulation will not apply to UK business after Brexit.

John Culkin, Director of Information Management at Crown Records Management, believes the results are alarming.

He said: “For so many businesses to be cancelling preparations is a big concern because this regulation is going to affect them all in one way or another.

Firstly, it is likely to be in place before any Brexit. Secondly, although an independent Britain would no longer be a signatory it will still apply to all businesses which handle the personal information of European citizens.

When you consider how many EU citizens live in the UK it’s hard to imagine many businesses here being unaffected.”

UK officials and politicians were heavily involved in the drawing up of the new regulation and Culkin believes the general principles behind it are set in stone.

The reality is we are likely to continue to see stringent data protection in an independent UK rather than a watered down version,” he said.

Our survey revealed that at least half of companies saw Brexit as an opportunity for Britain to position itself as the safest place to do business through even more robust legislation.

This means the best course is to prepare now and have a watertight information management system in place as soon as possible. This issue is not going away.”

There was some good news from the Crown Records Management Survey, however. It also revealed that:

  • 70 per cent of businesses with more than 100 employees have already appointed a data protection officer, one of the requirements of the EGDPR.
  • Half have introduced staff training and only 4 per cent do not plan to.
  • 72 per cent have reviewed data protection policies.
  • 44 per cent have undertaken an information audit.

These are important statistics,” said Culkin. “But this is not the time to delay or give up on preparations.”

The EU GDPR will bring in massive fines for data breaches – as high as 20million Euros or up to 4 per cent of global turnover – as well as new rules to ensure privacy is designed in to data policies, plus new rights for citizens to ask for their personal data to be edited or deleted.

To sign up to Crown Records Management’s webinar “EU GDRP – Staff training and Data Protection Officers on 3 May 2017, visit http://bit.ly/2nmc4z3.

  1. The Hashgraph Group announces the launch of TrackTrace for Compliance with EU’s Digital Product Passport (DPP) Regulation Read more
  2. Basware Launches New Agentic AI Capabilities to Transform Intelligent Finance Read more
  3. Meet Rising Fintech Leaders and Venture Partners at MoneyLIVE Summit Read more
  4. Incard Secures EMI Licence to Continue Its Mission of Building the Financial Operating System for Digital Entrepreneurs Read more
  5. Checkout.com Returns to Full-Year Profitability and Surpasses $300B in Volume, as It Positions for the Era of Agentic Commerce Read more
Digital Transformation in Insurance x FFNews