64 Percent of UK Employees Admit to Forwarding Work Emails, in Violation of GDPR
British technology services provider Probrand said it surveyed 1,002 full- or part-time U.K. employees, 64 percent of whom fessed up to forwarding a customer email to their personal accounts in the four months following the introduction of GDPR in May 2018.
January 04, 2019 at 02:23 PM
3 minute read
More than a majority of United Kingdom employees recently surveyed admitted to violating the General Data Protection Regulation (GDPR) shortly after it went into effect in May 2018 by forwarding a customer email to their personal accounts.
British technology services provider Probrand said it surveyed 1,002 full- or part-time U.K. employees, 64 percent of whom fessed up to committing the breach in the four months following introduction of GDPR.
In addition, 84 percent of those who admitted to forwarding the customer emails said there was no malicious intent behind their actions and thus they did not feel that they were doing anything wrong. Unfortunately, this is likely no defense to an alleged GDPR breach and the nightmares it may cause, said Matt Royle, marketing director at Probrand.
“What may seem like an innocent and even helpful action of workers trying to catch up on work out of hours is actually a clear breach of GDPR laws,” he said in a statement. But “seemingly innocent actions could have substantial repercussions. A GDPR breach can result in fines that potentially run into the millions. This financial impact along with the knock on effects this can have for businesses, including reputational damage, the loss of customer loyalty and trust, can be hugely damaging for companies in the long term.”
Although “worrying,” the results are not necessarily surprising, Royle said, given that earlier research from Probrand found that 55 percent of all U.K.-based businesses were breaching GDPR laws by not having an official process or protocol for disposing of obsolete IT equipment.
The results may be even more troubling to companies in light of the fact that data from the U.K.'s Information Commissioner's Office (ICO) revealed that the number of reported whistleblower complaints about potential data breaches at businesses have increased 165 percent since last May. The European Union's expansive regulation imposes new rules on any entity that offers goods and services to people in the European Union or that collects, processes or stores data tied to EU citizens.
“Given the amount of publicity around GDPR it is perhaps surprising that more workers (and employers) are not aware of the basics of what is required for GDPR compliance,” Royle said. “It is clear from these findings that businesses need to do more to educate their employees on the laws surrounding GDPR and data protection.”
In November, it was revealed that a Portuguese hospital was seemingly the first business to be hit with a monetary penalty under the GDPR, after it was fined 400,00 euros—about $453,000—by the country's data protection supervisory authority for allowing too many users to have access to patient data in the hospital's patient management system.
The hospital, Central Hospital of Barreiro Montijo, is appealing the decision, and may initiate legal proceedings, it said at the time.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllPre-Internet High Court Ruling Hobbling Efforts to Keep Tech Giants from Using Below-Cost Pricing to Bury Rivals
6 minute readWill Khan Resign? FTC Chair Isn't Saying Whether She'll Stick Around After Giving Up Gavel
$25M Grubhub Settlement Sheds Light on How Other Gig Economy Firms Can Avoid Regulatory Trouble
8 minute readTrending Stories
Who Got The Work
Michael G. Bongiorno, Andrew Scott Dulberg and Elizabeth E. Driscoll from Wilmer Cutler Pickering Hale and Dorr have stepped in to represent Symbotic Inc., an A.I.-enabled technology platform that focuses on increasing supply chain efficiency, and other defendants in a pending shareholder derivative lawsuit. The case, filed Oct. 2 in Massachusetts District Court by the Brown Law Firm on behalf of Stephen Austen, accuses certain officers and directors of misleading investors in regard to Symbotic's potential for margin growth by failing to disclose that the company was not equipped to timely deploy its systems or manage expenses through project delays. The case, assigned to U.S. District Judge Nathaniel M. Gorton, is 1:24-cv-12522, Austen v. Cohen et al.
Who Got The Work
Edmund Polubinski and Marie Killmond of Davis Polk & Wardwell have entered appearances for data platform software development company MongoDB and other defendants in a pending shareholder derivative lawsuit. The action, filed Oct. 7 in New York Southern District Court by the Brown Law Firm, accuses the company's directors and/or officers of falsely expressing confidence in the company’s restructuring of its sales incentive plan and downplaying the severity of decreases in its upfront commitments. The case is 1:24-cv-07594, Roy v. Ittycheria et al.
Who Got The Work
Amy O. Bruchs and Kurt F. Ellison of Michael Best & Friedrich have entered appearances for Epic Systems Corp. in a pending employment discrimination lawsuit. The suit was filed Sept. 7 in Wisconsin Western District Court by Levine Eisberner LLC and Siri & Glimstad on behalf of a project manager who claims that he was wrongfully terminated after applying for a religious exemption to the defendant's COVID-19 vaccine mandate. The case, assigned to U.S. Magistrate Judge Anita Marie Boor, is 3:24-cv-00630, Secker, Nathan v. Epic Systems Corporation.
Who Got The Work
David X. Sullivan, Thomas J. Finn and Gregory A. Hall from McCarter & English have entered appearances for Sunrun Installation Services in a pending civil rights lawsuit. The complaint was filed Sept. 4 in Connecticut District Court by attorney Robert M. Berke on behalf of former employee George Edward Steins, who was arrested and charged with employing an unregistered home improvement salesperson. The complaint alleges that had Sunrun informed the Connecticut Department of Consumer Protection that the plaintiff's employment had ended in 2017 and that he no longer held Sunrun's home improvement contractor license, he would not have been hit with charges, which were dismissed in May 2024. The case, assigned to U.S. District Judge Jeffrey A. Meyer, is 3:24-cv-01423, Steins v. Sunrun, Inc. et al.
Who Got The Work
Greenberg Traurig shareholder Joshua L. Raskin has entered an appearance for boohoo.com UK Ltd. in a pending patent infringement lawsuit. The suit, filed Sept. 3 in Texas Eastern District Court by Rozier Hardt McDonough on behalf of Alto Dynamics, asserts five patents related to an online shopping platform. The case, assigned to U.S. District Judge Rodney Gilstrap, is 2:24-cv-00719, Alto Dynamics, LLC v. boohoo.com UK Limited.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250