Europeโs landmark privacy legislation, the General Data Protection Regulation (GDPR), was officially adopted ten years ago and has been in force since May 2018. It has forced organizations to change the way they think about personal information and has put privacy risk firmly on the boardโs agenda, especially since the sanctions available under the regime are potentially ruinous (up to โฌ20 million/$22.8 millionโor 4 percent of global turnoverโfor severe breaches like violating basic processing principles).



