The world’s most stringent privacy law, the European Union’s General Data Protection Regulation (GDPR), turned 2 years old on May 25. In those 24 months, the rules have put data privacy compliance on every board’s agenda and have given Big Tech notice that their activities—and revenue streams—are under review.

Neil Hodge is a freelance business journalist and photographer based in Nottingham, United Kingdom. He writes on insurance and risk management, corporate governance, internal audit, compliance, and legal...