Just in time for the one-year anniversary of the EU’s General Data Protection Regulation, a panel of compliance and privacy officers at Compliance Week 2019 shared their experiences on how they prepared for the GDPR, the challenges they faced along the way, and where they continue to find opportunities to enhance their data protection programs.
The GDPR, which took effect on May 25, 2018, established a harmonized set of regulations across the European Union that govern how companies collect and process the personal data of European citizens. At its heart is a fundamental shift in the rights of data ownership; all EU citizens are considered by default to be the owners of their own personally identifiable information, and companies can only use it with their permission.



