When members of the Compliance, Governance and Oversight Council (CGOC) discuss data privacy and security today, I see an entirely new level of urgency. Enterprise data security programs used to be driven by the fear that breached customer and employee data could damage reputations and harm brands. Today, organizations recognize that data privacy is a vital competence driven by evolving regulations around the world and the increasing cost of data breaches and compliance failures. The 2016 Ponemon Institute Cost of Data Breach Study revealed the average cost for each lost or stolen record containing sensitive and confidential information increased from $154 to $158. Even a modest breach of 30,000 records at a small business or startup can cost more than $4.6 million.

In the United States, privacy legislation is targeted at specific industries or populations. These include the U.S. Privacy Act, the Children’s Online Privacy Protection Act (COPPA), the Health Insurance Portability and Accountability Act (HIPAA), and many others. However, U.S. companies of all sizes and in all industries should recognize that the EU’s General Data Protection Regulation (GDPR), going into effect in May 2018, applies to all foreign companies processing data of EU residents. Can your products be utilized by EU customers? If so, it’s imperative that you are ready to comply with the GDPR.