← All insights
Future-Ready

GDPR Was Supposed to Force Migration. 7 Years Later, Legacy Won.

The EU's data protection law created the world's strictest compliance regime. European websites are still 75%+ legacy. The regulation didn't change the infrastructure.

· 6 min read
Share on X LinkedIn
GDPR Was Supposed to Force Migration. 7 Years Later, Legacy Won.

The Compliance Paradox

GDPR was enacted in 2018 with the explicit goal of forcing organizations to take data protection seriously. Eight years later, WebPulse data shows European web infrastructure is still overwhelmingly legacy. WordPress, Drupal, and Joomla — frameworks with a combined 13,334+ CVEs — still power the majority of EU websites.

European organizations added cookie consent banners, published privacy policies, and appointed Data Protection Officers. What they didn't do: examine whether a framework with 11,334 known vulnerabilities is an appropriate foundation for GDPR-compliant data processing.

75%+
EU legacy framework share
WordPress + Drupal + Joomla combined across EU TLDs. Source: WebPulse Common Crawl WARC scan.

Article 25: Data Protection by Design

GDPR Article 25 requires 'data protection by design and by default.' Running a contact form that collects personal data on WordPress — a framework with 23 actively exploited vulnerabilities in CISA's catalog — is difficult to reconcile with 'by design.' The enforcement gap exists because regulators evaluate policies and procedures, not infrastructure. No DPA has yet audited a company's web framework choice. When one does, the precedent will force migration across the continent.

The Nordics Show What's Possible

Nordic countries show marginally higher modern framework adoption than southern and eastern Europe — but the 'Nordic digital leadership' narrative doesn't hold up in the data. Even Scandinavia runs majority legacy stacks. The EU needs a framework-level security standard, not just a data protection regulation. Until then, GDPR will continue to be implemented with cookie banners on vulnerable WordPress sites.

23
WordPress actively exploited CVEs
In CISA's Known Exploited Vulnerabilities catalog — confirmed in-the-wild attacks. Source: CISA KEV.
Share this insight
More insights