Failing to comply with the GDPR: what are the risks?
Quick reply
Administrative fines, criminal penalties and reputational damage: what a company really risks when it falls short of the GDPR.

As technology and the stakes around data security keep shifting, the GDPR has quickly become a cornerstone of data protection across the European Union. Failing to comply with it, however, can have serious consequences for a company. This article walks you through the nuances of the GDPR, its objectives, and the penalties you face if you fall short of it.
Understanding the GDPR: who does it apply to and what are its objectives?
The General Data Protection Regulation (GDPR) is a legal framework governing how personal data is collected, processed, used and stored within the European Union. In force since 25 May 2018, it aims to put an end to the carelessness with which personal data was once handled.
Any organisation, whether based inside or outside the EU, that collects or stores the personal data of European citizens has to comply with the GDPR. Its main objectives are several:
- Harmonisation: ensuring personal data is protected consistently across every EU member state.
- Accountability: requiring every organisation handling data to take a responsible, effective approach.
- Stronger individual rights: giving citizens more control over their own personal data.
Want to go further? Head here to find out more about the GDPR
Penalties for failing to comply with the GDPR
Falling short of the GDPR is not without consequence. Companies at fault can be heavily penalised, both administratively and criminally.
Administrative fines
These fines vary with the seriousness of the breach. Minor infringements can lead to fines of up to 10 million euros or 2% of the company's worldwide turnover. More serious breaches, such as ignoring an order from the CNIL (France's data protection authority) or transferring data without authorisation, can lead to fines of up to 20 million euros or 4% of worldwide turnover.
Criminal penalties
Beyond fines, prison sentences can be handed down. In France, for instance, breaching the GDPR can carry a prison sentence of up to 5 years and a fine of 300,000 euros.
Other consequences of failing to comply with the GDPR
Alongside financial penalties, falling short of the GDPR can also damage a company's reputation. A study by IntoTheMinds recorded an 86% rise in data protection complaints between 2017 and 2018, which shows how much importance the public now places on the protection of their data.
Some companies, Cambridge Analytica among them, have even had to close their doors following major scandals. Others have been forced to pay out enormous sums in damages for the harm caused to individuals by a data leak.
Protect your company
Given the risks attached to GDPR non-compliance, it is essential for companies to adopt reliable tools for managing and protecting data. Platforms such as NetExplorer offer secure ways to store and share files, and so help guarantee GDPR compliance.
The point is this: the GDPR is not only a legal obligation, it is a necessity in today's digital world if personal data is to be protected. Failing to comply can cost companies dearly, financially and reputationally. So make sure you put robust practices and tools in place to guarantee compliance and protect the trust your clients place in you.
Other articles you might like
SecNumCloud, ISO 27001, HDS: what are the differences?
ISO 27001, HDS, SecNumCloud: the question each standard answers, what it really covers, and which one to aim for in your sector.


But let's be honest, our cloud-based file storage and sharing solution is much easier.


