If firms want to avoid tougher penalties and more regulation, they must step up their data protection efforts