We are experiencing a big moment in data privacy. The General Data Protection Regulation (GDPR) went into effect in May 2018, along with potential fines of up to 4% of gross revenue, and many countries have passed or updated their own privacy laws to align with the GDPR framework. California passed a new privacy law that went from draft to law in less than a week last June, and other states have or are considering doing the same. A U.S. federal data protection law is under serious discussion. In this context, companies have been working hard to comply and prepare for these privacy requirements, and would like to know how their investments are helping their organizations beyond meeting compliance requirements. Is there a return on investment beyond fine and penalty avoidance?
In commemoration of International Data Privacy Day, a Data Privacy Benchmark Study 2022 has been released that reveals the impact and business benefits of data privacy investments. The study is based on responses in a survey of more than 3,200 privacy and security professionals in 18 countries.
Impact of GDPR readiness
The study finds that companies are benefiting from their privacy investments beyond compliance. While only 59% of companies believe they are ready for all or most GDPR requirements, those that are ready are realizing significant business benefits, such as reduced sales difficulties and greater data security compared to others. Specifically, GDPR-ready companies are experiencing shorter sales delays due to customer privacy concerns. Their average delay was 3.4 weeks compared to 5.4 weeks for those who are less GDPR-ready.
GDPR-ready companies are also less likely to be targets of attacks (74% were attacked) compared to those less GDPR-ready (89% breach). And, interestingly, when an assault did occur, fewer data records were impacted. GDPR-ready companies averaged 79,000 records impacted compared to 212,000 records impacted for the least GDPR-ready. As a result, only 37% of GDPR-ready companies had data breaches costing more than $500,000, compared to 64% of the least GDPR-ready companies.
Assessing sales delays
Customers are asking more questions during the sales process about how data is captured, used, stored, transferred, accessed and disposed of, and this is creating delays in the sales cycle for companies globally. In last year’s study, we found that 66% of companies had sales delays, and the average delay was 7.8 weeks. This year, we found that 87% of companies reported sales delays, and the increase is likely due to increased awareness of privacy issues caused by GDPR and the frequency of data breaches in the news. Interestingly, the average delay was about half of last year, with an average delay of 3.9 weeks for existing customers and 4.7 weeks for prospects. Corporations are getting better at responding to customer privacy questions. They are no longer struggling to answer data privacy questions for the first time, and many have developed robust capabilities to share their data privacy practices and policies with customers and prospects as needed in the sales process.
What does this mean for companies?
Nearly all companies (97%) say they are currently receiving ancillary benefits from their data privacy investments beyond meeting compliance requirements. And most companies identified multiple areas of benefits. In addition to mitigating losses from non-compliance and reducing sales delays, these benefits include increased agility and innovation, competitive advantage over competitors, and operational efficiencies. Most companies now say that privacy is a competitive differentiator in their markets.
The results of this study highlight that privacy is good for business. Cisco recommends companies:
- Invest in privacy enhancement, to comply with GDPR requirements and other relevant privacy regulations and frameworks.
- Measure any privacy-related sales delays with existing customers or prospects, identify the causes of the delays and take action to reduce them.
- Minimize the amount of personal data that is stored and processed, and install appropriate protections for this data based on risk, to help reduce costs and minimize the impact if there is a data breach.
- Once data is adequately protected, work to maximize the value of the organization’s data assets throughout the data lifecycle.
In future blogs, I will discuss what we have learned about how GDPR applicability and readiness varies across countries and industries, the underlying causes of privacy-related sales delays, and the progress companies are making to maximize the value of their data assets.

I can’t believe companies still underestimate the importance of data privacy! Wake up, people! 😡🔐
“Who even cares about data privacy? I just want my online shopping to be seamless!”
Title: GDPR Readiness: A Blessing in Disguise or Just Another Hassle?
Comment: Who knew data privacy could be so thrilling? GDPR, let the games begin! 🕵️♂️🔐
“GDPR? More like Gotta Deal with Privacy Regulations! Companies better buckle up!”
“Who needs privacy anyway? Let’s share ALL our data with everyone! 🙄”
I never thought data privacy could be so interesting. GDPR, sales delays, companies… woah! 🤔
Are you kidding? Data privacy is one of the most crucial topics of our time! It affects our personal information, online security, and the power of big corporations. It’s about time we all educate ourselves and take it seriously. Wake up! 🚨