Great points on GDPR. I don’t think any of us truly know the long-term ramifications and impact of this massive piece of legislation, yet I would argue that regardless of what plays out, its’ a watershed moment for privacy, one that is probably long overdue. While I can’t really speak to the level of understanding for GDPR with regards to EU controllers and processors, it’s unfortunately surprising to witness the complete lack of knowledge and understanding of the GDPR for U.S. based processors and controllers.
Will be interesting to see what happens post May, 2018 in the U.S. with enforcement. One of the biggest challenges for GDPR compliance for U.S. companies is trying to dig through the almost endless blogs, white papers, and other technical writings on this topic. Everyone has their own expert advice, and the vast majority of content is great and well-written, it’s just that it is overwhelming in terms of volume of content.
Regardless, I think the biggest advice I can take – and give – regarding GDPR compliance for U.S. businesses is the need for documentation. Specifically, I.T., privacy, consent, and other operational policies, procedures, and processes. Documentation is without question necessary for GDPR. Good luck everyone.