EU Reg, Fines, Foreshadow New U.S. Rules

By Ray Birch

ST. PETERSBURG, Fla.—It’s time to pay attention to the European Union’s General Data Protection Regulation (GDPR) and prepare for its impact on financial institutions in the U.S., says one expert.

Feature GDPR  low res

Brian Scott, chief growth officer at PSCU, said recent big moves by European Union regulators indicate not only can E.U. fines hit U.S. organizations, they also foreshadow similar rules in the United States.

“The European Union has now fined a couple big U.S. companies,” said Scott, emphasizing the recent Google fine by France. “What’s interesting here is these rules are being enforced worldwide and now everyone knows the rules are coming here. This is something organizations of all sizes need to stay on top of, especially if large, sophisticated companies are getting fined.”

As CUToday.info reported, France’s data protection regulator CNIL (Commission nationale de l'informatique et des libertés) recently issued Google a $56.8-million fine for failing to comply with its GDPR obligations. This is the biggest GDPR fine yet to be issued by a European regulator. CNIL said the fine was issued because Google failed to provide enough information to users about its data consent policies and didn’t give them enough control over how their information is used. Under GDPR, companies are required to gain the user’s “genuine consent” before collecting their information, which means making consent an explicitly opt-in process that’s easy for people to withdraw.

The E.U.’s General Data Protection Regulation became effective May 25.

The regulation, which purports to apply to companies anywhere in the world with customers or members living in the E.U., contains provisions and requirements pertaining to the processing of personally identifiable information of individuals.

Hitting Apple, Amazon, Facebook

Prior to the Google fine, the European Union's competition commissioner, Margrethe Vestager, ordered Apple and Amazon to pay back taxes and fined Facebook over its WhatsApp acquisition.

“These are all shots across the bow that companies in the U.S.—including financial institutions—need to take notice of,” said Scott.

ScottBrian fianl use this

Brian Scott

Scott said that although similar rules have yet to be adopted by the U.S., companies can no longer sit back and ignore GDPR.

“You should begin preparing for these rules. European Union regulators are now fining people. They have had a significant number of complaints from consumers,” said Scott. “This is all about transparency and the right of people to access their own data and have that data be protected from being shared with others. I see a hyper-sensitivity around this now.”

Key Steps to Take

Scott said key steps credit unions can take today include understanding what GDPR is and developing a plan to have a strategy in place for how to prevent GDPR violations and take action if necessary.

“So when GDPR hits, they won’t be caught behind the eight ball,” said Scott.

Scott believes an even bigger effect than the GDPR rules will be felt by financial institutions when the U.S. adopts similar rules.  

“Again, financial institutions need to closely follow what is happening in Europe,” emphasized Scott.

Early Planning Pays

Scott stressed the importance of early planning, given that GDPR has caught some companies with deep pockets and large resources off guard.

“The key thing to note is that when these laws were enacted, sophisticated companies like Amazon and Google were not able to adapt quickly enough to comply with the new laws,” he said.

The thinking that GDPR will only impact large U.S. companies is flawed, said Scott. He said smaller organizations will someday attract European Union regulators’ attention, but they will certainly be in the crosshairs when similar rules are enacted in the U.S.

Scott believes that day is not far away.

“There are states like California that have enacted laws that are incredibly similar to GDPR,” said Scott. “I understand that these are state laws, but it won’t be long before federal law—and likely lots of states—will be adopting something similar to GDPR. Call it GDPR Lite, and that may happen within this year.”

Section: Standard
Word Count: 905
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/EU-Reg-Fines-Foreshadow-New-U.S.-Rules