In the decade since the European Unionโ€™s (EU) groundbreaking privacy legislation, the General Data Protection Regulation (GDPR), was approved, companies have faced increased scrutiny over the reasons they collect, retain, and share personal information, as well as the measures they take to ensure its security.

Regulators have also pushed for compliance through a mix of practical advice and guidelines, warnings and reprimands, orders for remedial measures, audits, and finesโ€”though no company yet has been handed a penalty worth up to 4 percent of global turnover for a serious breach.

Neil Hodge is a freelance business journalist and photographer based in Nottingham, United Kingdom. He writes on insurance and risk management, corporate governance, internal audit, compliance, and legal...