This article appeared in Cybersecurity Law & Strategy, an ALM publication for privacy and security professionals, Chief Information Security Officers, Chief Information Officers, Chief Technology Officers, Corporate Counsel, Internet and Tech Practitioners, In-House Counsel. Visit the website to learn more.

Data privacy and cybersecurity are easily the hot button issues of the decade. For many organizations, preparing to comply with the EU’s General Data Protection Regulation (GDPR), effective as of May 25, 2018, was a herculean feat and those efforts continue as new guidance is released and companies look to improve their data privacy governance and compliance programs. The most significant overhaul to the EU’s data privacy policies in over 20 years, with extraterritorial reach, the new regime forced American businesses to remediate, and in some cases, overhaul their data privacy governance programs.