1. The fundamentals
Chapter 1 of 6 · 3 min
Fundamental GDPR regulation and its impact on companies.
10x Insight
GDPR (General Data Protection Regulation) entered into force in May 2018 and applies to all companies that handle personal data about EU citizens.
GDPR (General Data Protection Regulation) entered into force in May 2018 and applies to all companies that handle personal data about EU citizens. The six basic principles — lawfulness, purpose limitation, data minimization, accuracy, storage time and integrity — create a framework that companies must follow.
The maximum fine is 20 million EUR or 4% of the global revenue, depending on which is higher. For Swedish tech companies like Spotify (revenue ~13 bn EUR), the maximum fine would be 520 million EUR. Even though the fines are rarely maximal, they are large enough to noticeably affect the result.
For investors, the central thing is understanding what data the company collects, where it is stored, and which third parties have access. Companies with a 'data lake' strategy (collect everything, ask later) have higher risk than those with a 'data minimization' strategy.
Swedish companies must report data breaches to IMY within 72 hours. If a company delays the report, the fines increase markedly. For investors, the timing of the report is a signal — a quick report shows maturity, a late report indicates a hidden problem.
Many Swedish tech companies have breach preparedness, but few test it regularly. A question to ask investor relations: 'When did you last practice breach response?' If the answer is vague or more than 12 months ago, it is a warning signal.