As Europe settles into life under the General Data Protection Regulation (GDPR), the United States is grappling with potential legislation of its own to protect consumer information.

Questions remain about what U.S. data privacy legislation might look like, but companies have already begun to strategize. In partnership with RSA, Compliance Week conducted a survey asking U.S. firms whether they’re doing enough to stay compliant with data protection laws; the survey garnered 100 responses from individuals whose scope of responsibility included helping ensure data privacy. Of the respondents, only 36 percent felt their data privacy program is in compliance with state, national, and/or international regulations, while 52 percent felt they were almost there but struggling to keep up.