Data Protection Risks in 2025 - ZISHI

Data Protection Risks in 2025

Explore how data protection risks and rules have evolved, and what firms must do to stay compliant.

For the majority of my career, I’ve worked in regulatory risk units across the spectrum of finance firms. I’ve covered the rules around payday loans, the financing of transit vans and oil rigs, paperwork for private banks and debt collection firms and everything in between.

While going through the alphabet soup of SIB, BCSB, FSA, FCA, PRA and ECB, my colleagues and I used to joke that regulatory changes in data privacy were good. After all, they kept the compliance team busy and able to pay our mortgages.

Now, the laughing has stopped. The stakes have always been high, but international firms and their senior manager functions are starting to feel isolated. They’re turning to external advisors and safe discussion spaces with competitors to avoid being the head above the parapet. Heads-up has become heads-down.

Please note: This is not a political piece. It’s simply an analysis of the current state of data protection risks in 2025.

Regulatory Changes to Data Privacy in 2025

Regulatory changes in data privacy have been relatively gradual. Discussion papers lead to advising consultation papers, and then a transition to policy and guidance. Throw in some legislation, and the UK gives the world a heads-up regarding the direction of travel. We may not like the direction, but at least we, and those wanting to operate here, have an idea of what’s expected.

Although we’re not part of the EU, we can still review their plans and understand how they align with ours. We can identify competitive advantage in some areas and recognise our shortfalls in others.

Until late 2024, scanning headlines and reading documents helped us guide clients on where to focus their training and resources.

2025 has altered all of that.

The world has changed. The current US administration is upending the norms of the past 70 years. Now it’s about reacting rather than preparing.

When a CEO of a respectable firm asks whether to issue burner phones to staff travelling to the US to avoid loss of data or challenges at immigration, it’s time to get out the old Risk and Control Assessment spreadsheet and start re-evaluating data protection risks and impacts.

What is the Transatlantic Data Privacy Framework (TADPF)?

The 2023 Transatlantic Data Privacy Framework (TADPF) has gone through a number of iterations. The new version is built on the underpinnings of the old ‘Privacy Shield’ and ‘Safe Harbour.’

There were some misgivings when TADPF was adopted in Europe. However, one can see a pragmatic compromise being taken between the EU and the US (Although sidelined in discussions, the UK has bought into the overall concept- once again, a pragmatic approach).

New EU Data Transfer Rules and Restrictions

With some foresight, the European Data Protection Board published new guidelines for transferring personal data to public bodies outside the EU. This included a change to how subpoenas and compliance requirements in foreign countries could be answered. In short, EU firms can’t, without an international treaty or legislative agreement between the two jurisdictions, move data.

In addition, holding client data ‘just in case’ a foreign power may want it in the future is not a ‘legitimate interest’ in meeting a country’s GDPR compliance requirements.

Now, more member states require detailed risk assessments and risk mitigation plans before any data is moved outside of the EU. As such, data privacy scrutiny is ramping up across the whole industry. Strictly speaking, this doesn’t affect the UK yet. But for every UK firm that deals with Europe, it already sort of does.

🔶 Want to learn more about evolving data protection risks and how to stay compliant? Sign up for free to continue reading the full article.

🔶 This article is written by The ZISHI experts and published in the May 2025 edition of Advice Matters MagazineSubscribe here to stay up to speed with the latest regulatory policies and procedures.

FAQs

What are the risks of data protection?

Data protection risks refer to potential threats to the security, privacy and availability of data. The main risks include data breaches, regulatory non-compliance, loss of trust, operational disruptions, reputational damage, legal challenges and potential fines.

What is the EU-US transatlantic data privacy framework?

The Transatlantic Data Privacy Framework (TADPF) is a data-sharing agreement between the EU and the US. It outlines how personal data can be transferred and processed in the US while ensuring compliance with EU data protection.

Does the UK follow TADPF rules?

The UK is not a formal party to the EU-US transatlantic data privacy framework, but does align with its goals. UK businesses can transfer personal data to US organisations certified to the “UK Extension to the EU-US Data Privacy Framework” (UK Extension) under Article 45 of the UK GDPR.

What are the new EU rules around data transfers?

The EU requires firms to have international treaties or legislative agreements in place for data transfers. Simply storing data ‘just in case’ a foreign power may want it is not compliant with GDPR requirements.

 

Contact us

Please do get in touch with us at info@thezishi.com if you’d like more information about how our education and training solutions can help keep your knowledge, policies and procedures up-to-date.

You might also be interested in:

See all courses
  • Governance, Risk & Compliance

    Provided on request

    VIEW COURSE
  • Cyber Security

    Provided on request

    VIEW COURSE
  • Design & Audit of Internal Control Under SOX & PCAOB Requirements

    Provided on request

    VIEW COURSE
  • Preventing, Detecting & Investigating Financial Crime

    Provided on request

    VIEW COURSE
  • Fundamentals of Financial Risk Management

    Provided on request

    VIEW COURSE

You need to login first to add to Favourites

My Account