European Commission Publishes Results of Surveys on One Year of GDPR Application
Time 2 Minute Read

To mark the GDPR’s one-year anniversary, the European Commission recently published the results of two surveys meant to illuminate the public’s awareness of the GDPR and its practical applications.

Special Eurobarometer 487a – GDPR Report

The first survey, the special Eurobarometer 487a (the “Eurobarometer”), was meant to elucidate the public’s awareness of the GDPR, as well as the public’s practical experiences and opinions of data protection issues more generally.

The Eurobarometer focused on respondents’:

  • use of the Internet and activity on online social networks and shopping platforms;
  • awareness of the GDPR, individuals’ rights under it and the national supervisory authority in charge of enforcing the GDPR;
  • perceived control over personal data provided;
  • level of apprehension they experience as a result of not feeling fully in control of their data;
  • reactions to the information they receive regarding how their personal data is collected and used (including the potential further use) of their personal data;
  • attitudes vis-à-vis privacy notices, the percentage of respondents who read online privacy notices and the reasons for not (fully) reading them; and
  • use of privacy settings and reasons for not changing the default settings.

Access the full report with the results of the Eurobarometer.

GDPR Multistakeholder Expert Group Report

The European Commission also published the Contribution from the Multistakeholder Expert to the Stock-Taking Exercise of June 2019 on One Year of GDPR Application (the “Report”). The Report was compiled by the GDPR Multistakeholder Expert Group (the “Group”), a committee of academics, legal practitioners and representatives of business and civil society organizations that supports the European Commission connection with the GDPR’s application.

The Report reflects the GDPR Multistakeholder Expert Group members’ feedback on certain aspects of the GDPR, including:

  • the impact of the GDPR on the exercise of data subjects’ rights;
  • the challenges related to the new conditions for valid consent;
  • the number of complaints and legal actions introduced since the application of the GDPR;
  • experiences with Data Protection Authorities and the one-stop-shop mechanism;
  • feedback on the implementation of the accountability principle and the risk-based approach;
  • interactions with Data Protection Officers;
  • feedback on the controller/processor relationship;
  • the need to adapt/further develop Standard Contractual Clauses for international transfers; and
  • GDPR implementation in national legislation at the Member State level.

For more information, please find the complete Report.

You May Also Be Interested In

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Time 2 Minute Read

On March 3, 2026, the European Commission published draft guidelines intended to clarify the application of the Cyber Resilience Act and opened a public consultation to gather feedback from stakeholders.

Time 2 Minute Read

On February 23, 2026, a Joint Statement on AI-Generated Imagery was published by 61 data protection authorities. The Joint Statement addresses concerns regarding AI systems capable of generating realistic images and videos depicting identifiable individuals without their knowledge or consent.

Time 2 Minute Read

On February 18, 2026, Virginia Attorney General Jay Jones announced that his office intends to fully enforce new provisions of the Virginia Consumer Data Protection Act restricting minors’ use of social media.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page