GDPR's impact on cybersecurity: A review focusing on USA and European practices

Olukunle Oladipupo Amoo 1, Akoh Atadoga 2, Femi Osasona 3, Temitayo Oluwaseun Abrahams 4, *, Benjamin Samson Ayinla 5 and Oluwatoyin Ajoke Farayola 6

1 Department of Cybersecurity, University of Nebraska at Omaha, United States of America.
2 Independent Researcher, San Francisco, USA.
3 Scottish Water, UK.
4 Independent Researcher, Adelaide, Australia.
5 University of Law Business School, Manchester, United Kingdom.
6 Financial Technology and Analytics Department, Naveen Jindal School of Management. Dallas, Texas, USA.
 
Review
International Journal of Science and Research Archive, 2024, 11(01), 1338–1347.
Article DOI: 10.30574/ijsra.2024.11.1.0220
Publication history: 
Received on 27 December 2023; revised on 03 February 2024; accepted on 05 February 2024
 
Abstract: 
The General Data Protection Regulation (GDPR) has emerged as a landmark legislation reshaping the global landscape of data privacy and cybersecurity. Enforced in May 2018, the GDPR has had a profound impact on organizations worldwide, prompting a reevaluation of cybersecurity practices to ensure compliance with stringent data protection standards. This paper provides a comprehensive review of GDPR's influence on cybersecurity, with a particular emphasis on the contrasting approaches and practices adopted in the United States (USA) and Europe. The GDPR introduces a set of robust principles designed to protect the rights and privacy of individuals, emphasizing the need for transparency, accountability, and proactive measures to safeguard personal data. Its extraterritorial scope extends its impact beyond European borders, compelling businesses operating globally to adhere to its regulations. This paper explores the challenges and opportunities arising from GDPR compliance, examining how organizations in the USA and Europe have navigated the evolving cybersecurity landscape. In the USA, where privacy regulations historically differed across states, the GDPR has prompted discussions around the development of federal privacy laws. The review delves into the varying approaches adopted by American businesses, considering the interplay between state and federal regulations in shaping cybersecurity strategies. Conversely, European practices reflect a proactive response to the GDPR, as organizations have embraced the principles embedded in the regulation to fortify cybersecurity frameworks. The paper investigates the evolution of cybersecurity standards in Europe, highlighting successful strategies and potential areas for improvement. By synthesizing experiences from both sides of the Atlantic, this review contributes to a deeper understanding of the GDPR's impact on cybersecurity. It sheds light on the evolving dynamics of data protection, offering insights for organizations seeking to enhance their cybersecurity resilience in the face of a rapidly changing regulatory landscape.
 
Keywords: 
GDPR; Cybersecurity; USA; Europe; Data Protection; Review
 
Full text article in PDF: