While most commentators have focused on the Schrems decision around the lack of U.S. data privacy protection from government or company intrusion, for the compliance function, the decision raises serious issues on two significant areas of any best practices compliance programโhotlines and internal investigations.



