Both the EU’s General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) in the United States effectively put in place greater restrictions around how companies collect and process the personal information of consumers and employees. “Right of access” requests from data subjects, particularly, are still creating compliance headaches.

Jaclyn Jaeger is a freelance contributor to Compliance Week after working for the company for 15 years. She writes on a wide variety of topics, including ethics and compliance, risk management, legal,...