Ever since it came into force, firms that hold customer data have been anxious about GDPR compliance. However, no law or regulation can be fully effective unless it is enforced, and we have not yet seen tough enforcement of GDPR breaches. 

It would be wise not to take this as an indication that we can be more relaxed about compliance. Any of the EU's privacy agencies might feel the same way and decide to send a signal to the market that compliance is not negotiable ...