723 results for gdpr in Reports

Trend Report

Tech leaders and other decision-makers involved with data or AI must also note that: GDPR compliance is a prerequisite. No new pieces of legislation — whether it’s the AI Act, the Data Act, or those related to consumer protection — supersede the General Data Protection Regulation (GDPR), despite some commentary implying otherwise. Quite the contrary: Where personal data comes into it, new legislation assumes full GDPR compliance is in place.

How To Report

Compliance includes SOC 2, GDPR, and PCI DSS. This graphic has an associated spreadsheet that includes all data presented. Please access the spreadsheet for details. Figure 6 Telecommunications And Utilities CRM Telecommunications CRMs allow telcos to create and launch new products (see Figure 7).

Trend Report

Figure 4 GDPR Fines By Month, 2025 Figure 5 shows monthly GDPR enforcement activity in 2025, including the number of fines issued and total fine amounts across all 12 months. The most significant data points are substantial spikes in fine amounts in May and September. This graphic has an associated spreadsheet that includes all data presented. Please access the spreadsheet for details.

Predictions Report

For example, GDPR exemptions, such as dropping Records of Processing Activities for firms with less than 750 staff, will backfire as larger controllers flood smaller firms with due diligence requests, forcing many to remain compliant. Act now to assess impacts across your suppliers and value chains and proactively manage information to contain costs. No European enterprise will shift entirely from US hyperscalers.

Best Practice Report

Today’s Privacy Regulations Are Prevalent And Comprehensive Since the GDPR went into effect in 2018, the privacy regulatory landscape has only grown more complex. Marketers are struggling to keep up: In Forrester’s Marketing Survey, 2025, 58% of B2C marketing decision-makers say that they are concerned about their ability to comply with new global privacy laws.
Stephanie Liu, Melissa Bongarzone

Trend Report

GDPR is the most enforced privacy regulation in the world. European privacy regulators issued 20 of the 35 highest fines of 2024 for violations of the GDPR (see Figure 5). The Spanish regulator leads with the highest number of fines issued, and the Irish regulator tops the list for the highest amount fined.

Data Overview Report

While many regulations, such as GDPR or GLBA, may not explicitly refer to full-disk or file-level encryption, security leaders can use these approaches to meet the requirements for safeguarding sensitive data like personal or financial information.

Trend Report

Privacy In Asia Pacific: Why GDPR Compliance Isn’t Enough GDPR is often considered the world’s most stringent privacy regulation. In Forrester’s Business Privacy Survey, 2024, 46% of privacy decision-makers in APAC reported that their organization fully complies with GDPR. But multinational companies frequently operate under the misconception that GDPR compliance ensures that they meet the highest standards globally.
Xiaofeng Wang

Best Practice Report

Privacy Teams Must Be Cross-Functional To Address Rapid Changes While the General Data Protection Regulation (GDPR) remains a landmark privacy regulation, much has changed since it went into effect in May 2018 — and the law itself is potentially getting a refresh.
Stephanie Liu, Enza Iannopollo, Heidi Shey

Best Practice Report

Centralized oversight enforces consistent data practices, supports regulatory frameworks like GDPR and HIPAA, and reduces the risk of breaches or violations. Data sovereignty requirements. Sectors that demand data sovereignty, such as audit or multicountry telecom, will necessitate designing your DAAI org to follow strict data sovereignty compliance demands. Audit firms will need centralized governance to uphold Sarbanes-Oxley requirements and protect financial data integrity.

Get help finding what you need
Ask Forrester AI for instant answers or submit a research request and receive a curated list of research within 48 hours.