A fifth of companies lack continuous encryption for personally identifiable information, and only half have the systems required to meet Articles 16 and 17 of the GDPR legislation. Only half (51%) of companies say they have all the systems in place that will allow them to remove EU Citizen data from servers upon the request, including back-ups, in accordance with Articles 16 & 17 of GDPR. Non-compliance can lead to fines of 20 million or 4% of turnover, but this is far outweighed by the reputational damage that can occur from a data breach.”]
Source: https://informationsecuritybuzz.com/study-research/winmagic-survey-finds-most-companies/