Interviews and documents show Europe's GDPR rules have been stymied by a lack of enforcement, poor funding, limited staff resources, and tech companies stalling
Nearly two years in, there has been little enforcement of the General Data Protection Regulation, once seen as ushering in a new era.
Context & Ripple Effects
When the General Data Protection Regulation took effect in May 2018 it was billed as a new era for privacy enforcement, but the record so far is thin: the only substantial privacy action against a major tech company came from Washington, where Facebook was fined $5B — not from any EU regulator. The New York Times reporting pins the shortfall on structural causes rather than legal ones: underfunded authorities, thin staff, and tech companies stalling through procedural delay.
The arc was visible earlier. Critics had already flagged that the Irish Data Protection Commission, the EU's lead enforcer because most big tech firms are headquartered there, faced questions about its willingness to crack down on firms central to Ireland's economy. And compliance economics cut the other way too — big companies absorbed GDPR costs while smaller rivals suffered, concentrating the data economy even as the law aimed to restrain it.
First-order effects
- EU national regulators and the Irish DPC are exposed as capacity-constrained: without more funding and staff, open investigations into large platforms stall in procedure while the statute's two-year anniversary passes with little to show.
Second-order effects
- Enforcement gravity shifts to the US, where the FTC's $5B Facebook fine becomes the de facto global privacy penalty — pushing European policymakers toward either resourcing their own authorities or ceding the enforcement role.
Third-order effects
- If the pattern holds, GDPR risks entrenching exactly what it targeted: well-resourced platforms outlasting underfunded regulators while compliance costs squeeze smaller competitors — a dynamic the four-year retrospective confirms was still unresolved.
The trend: Privacy regulation is converging on a pattern where ambitious statutory frameworks succeed or fail on regulator funding and staffing, with enforcement migrating to whichever jurisdiction can actually act.