Home/ Law 101/ 22 September 2026
AI Digest
10 Sources Updated 12h ago Morning Edition 4 min read

GDPR Bites Back: 86% Failed. You're Probably Next.

| Law, Business & Power Correspondent --- 86 percent.

AI-generated digest · 10 verified sources · Updated twice daily Add as preferred source
What You Missed Today
Durable
Durable
Durable builds a professional website in 30 seconds. AI does the design.
Learn more →
Buffer
Buffer
Buffer schedules your social media so you post consistently without thinking about it.
Learn more →
AI Fiesta
AI Fiesta
Every AI tool worth knowing about — in one place. AI Fiesta.
Learn more →
Aircall
Aircall
Aircall: business phone system that lives in your browser. No hardware.
Learn more →
Apollo.io
Apollo.io
275M contacts. Verified emails. Sequencing. Apollo replaces 4 outbound tools.
Learn more →

By Harvey Specter Jr. | Law, Business & Power Correspondent

---

86 percent. That is the number Swansea University put on paper, and it is the number that should be sitting uncomfortably with every compliance officer, every legal team, and every business operator in Europe who read it and immediately thought about their own cookie banner.

The research focused on UK Gambling Commission-licensed websites, but here is what the headline writers missed: GDPR does not stop at the white cliffs of Dover. The Regulation — the General Data Protection Regulation, Regulation (EU) 2016/679, the one that has been in force since May 2018 and still surprises people who should know better — applies to any organisation that processes the personal data of individuals in the European Union, regardless of where that organisation is based or what sector it operates in. The gaming sector is not special. It is simply the sector that got studied this time.

And the timing could not be more loaded. The European Data Protection Board has just adopted draft Guidelines 04/2026 on how supervisory authorities should calculate and apply fines under GDPR. These are not philosophical musings. They are a methodology — a formula for turning your compliance failures into a specific number with a euro sign in front of it. The EDPB is essentially publishing the pricing guide for violations, and they have done it in the same month a major piece of research documented an industry-wide failure rate of eighty-six percent.

Read that sequence again. The regulator publishes the fine calculation framework. The researchers publish the breach rate. The connection is not subtle.

What the EDPB's draft Guidelines 04/2026 do — and this matters for anyone running a business in Malta, Cyprus, Ireland, or any other EU jurisdiction with a significant digital services footprint — is standardise the methodology that national data protection authorities use when deciding whether to fine you and for how much. Previously, there was enough variation between member states that a sophisticated operator could argue inconsistency, could point to how a comparable breach was handled in a neighbouring jurisdiction, could create enough noise in the process to soften the outcome. That window is narrowing. The Board is harmonising the approach, which means the defences that worked in 2022 may not survive 2027.

The DSA interplay piece matters too. The EDPB has also finalised guidelines on how GDPR intersects with the Digital Services Act — Regulation (EU) 2022/2065 — which came into full force for all platforms in February 2024. If your platform has users in the EU, you are now operating under two overlapping regulatory frameworks, each with its own enforcement teeth, and the Board has just drawn the map of where those teeth connect. A data protection failure can simultaneously be a DSA compliance failure. One incident, two regulators, two potential enforcement tracks.

I had a client — years before the suits, in the period I do not spend much time describing — who thought that keeping his records loose was a kind of freedom. It was not freedom. It was debt he had not been invoiced for yet. Compliance works the same way. The 86 percent who failed did not fail dramatically. They failed quietly, in footnotes, in cookie consent flows designed to frustrate rather than inform, in data retention schedules nobody reviewed after the initial setup. The invoice arrives later. With interest.

The practical reality for Malta-based operators — and Malta has a significant concentration of licensed digital businesses precisely because the regulatory environment was considered manageable — is that Guidelines 04/2026 will, once finalised after the consultation period, become the operational manual that the Information and Data Protection Commissioner uses when assessing penalties. The IDPC is a member of the EDPB. It participates in these decisions. It will implement this methodology. What the Board decides in Brussels lands in Valletta.

The Starbucks settlement in Florida — $1 million, paid without admission of wrongdoing, with significant operational restrictions attached — is worth noting not for its size but for its structure. The payment is almost secondary. The restrictions on how Starbucks can use race as a criterion in its programmes going forward are the real terms. This is the thing most people miss when they read settlement announcements: the money is the number everyone reports, but the behavioural changes in the agreement are the actual outcome. The other side agreed to change how they operate. That is worth more than the cheque.

It is a negotiation principle I apply every time. Never go

Editor's Note
Forty years in Malta have taught me one thing about that 86 percent: the number is never the story — the 14 percent who think they're compliant is.
Harvey Specter Jr.
Harvey Specter Jr.
Law, Business & Power Correspondent
Harvey Specter Jr. has been in rooms where deals are made and rooms where lives fall apart — sometimes the same room. He found law the hard way. He never lost a case he cared about. He has two children he would burn everything down for, and he has. Twice.
View all articles →
Ilhan Irem Yuce
Edited by Ilhan Irem Yuce · Chief Editor, News Beast