Search
Contact
02.05.2018 | Deal Notifications, Press releases

Study in collaboration with The Legal 500: “The GC Guide to the GDPR”.

Study: Less than half of all German companies are prepared for the new EU General Data Protection Regulation

In a survey conducted by The Legal 500 and KPMG Law between November 2017 and February 2018, only 46 percent of surveyed Head of Law indicated that their company had already done enough to be compliant with the General Data Protection Regulation (GDPR). The new regulations for data protection in companies come into force on May 25.

The study combines a survey of around 450 in-house lawyers with in-depth, structured interviews with more than 30 heads of legal in companies. It discusses the level of preparedness and the risks and opportunities that the new regulation poses for companies and institutions. As a result, a considerable need to catch up is revealed.

For example, less than ten percent of respondents believe that employees in their companies are aware of their data protection obligations under the GDPR and national legislation. “This is an alarming number,” says Dr. Konstantin von Busekist, Partner and Head of Compliance, Governance & Organization at KPMG Law. “As of May 25 of this year, increased documentation and transparency requirements apply, which affect almost all areas of the company, require a high level of implementation effort, and failure to comply is subject to significant fines.” Barbara Scheben, Partner at KPMG AG Wirtschaftsprüfungsgesellschaft in the area of Compliance & Forensic and Head of Data Protection adds: “Against this background, a considerable implementation delta is to be expected.

The respondents to the study see the following points in particular as the most important challenges posed by the GDPR:

  • Implementation of measures within the entire company, not just in a single department
  • Close integration of the legal department with all other corporate divisions
  • Interpretation of legal requirements (principles instead of normative rules) without legal precedents.
  • Complete understanding of and control over all IT systems, processes and data processing activities

At the same time, the unloved topic of the GDPR certainly offers opportunities, as Jan-Dierk Schaal, Senior Manager and Head of Technology, Media & Telecommunications at KPMG Law, points out: “A high level of data protection strengthens customer confidence and creates greater transparency about one’s own processes, which also limits risks in other areas of the company, such as the topic of bribery and corruption. Disciplined management of customer data can create opportunities to optimize communications and produce better service, especially through digital solutions.”

More info on the study can be found here.

 

Explore #more

05.01.2026 | In the media

KPMG Law expert in the Börsen-Zeitung on the digital euro

The digital euro is set to arrive by 2029. However, the central bank still has a lot of convincing to do. There is a great…

22.12.2025 | KPMG Law Insights

New EU directive tightens environmental criminal law

Environmental crime will be punished more severely in future. Directive (EU) 2024/1203 on the protection of the environment through criminal law is being transposed into…

19.12.2025 | KPMG Law Insights

Digital Omnibus: More efficiency instead of deregulation

The EU Commission wants to streamline digital laws. On November 19, 2025, it presented its proposals for the “Digital Omnibus” (including a separate AI Omnibus).…

18.12.2025 | Deal Notifications

KPMG Law and KPMG advise the shareholders of Frerk Aggregatebau on the sale to DEUTZ

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) and KPMG AG Wirtschaftsprüfungsgesellschaft (KPMG) provided comprehensive advice to the shareholders of Frerk Aggregatebau GmbH (Frerk) on the sale…

17.12.2025 | KPMG Law Insights

AI-supported risk checks of NDAs and CoCs: how legal departments benefit

Artificial intelligence can relieve legal departments of routine tasks such as checking non-disclosure agreements (NDAs) or codes of conduct (CoCs). These documents are part of…

16.12.2025 | In the media

Interview with KPMG Law experts: CSDDD after the omnibus: “Toothless tiger” or pragmatic solution?

The agreement on the Omnibus I package is causing discussion. Among other things, the thresholds for the EU Supply Chain Directive (CSDDD) have been significantly…

15.12.2025 | In the media

KPMG Law guest article in Tagesspiegel Background: What the digital omnibus means for companies today

The debate on the digital omnibus has only just begun. Companies should contribute their expertise to the ongoing process and strengthen their internal foundations –…

12.12.2025 | KPMG Law Insights

Focus offshore: NRW buys extensive tax data on international tax havens

According to recent press reports from December 11, 2025, the state of North Rhine-Westphalia has purchased an extensive data set with tax-relevant information from international…

12.12.2025 | KPMG Law Insights

Legal changes in 2026: New obligations and relief for companies

Rarely has the new year been as difficult for companies to plan as 2026. All the signs in the EU are currently pointing towards reducing…

12.12.2025 | Deal Notifications

KPMG Law advises The Chemours Company on the implementation and closing of a large-volume factoring financing

KPMG Law Rechtsanwaltsgesellschaft GmbH (KPMG Law) advised the US-American Chemours Company on the implementation of a cross-border factoring financing. The legal implementation was managed by…

Contact

Dr. Konstantin von Busekist

Partner
Leiter Global Compliance Practice
KPMG Law EMA Leader

Tersteegenstraße 19-23
40474 Düsseldorf

Tel.: +49 211 4155597123
kvonbusekist@kpmg-law.com

© 2024 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.

 KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.

Scroll