you are viewing a single comment's thread
view the rest of the comments
[–] 8 points 2 years ago* (1 child)

Not just the legal team. Every time there's new legislation like this, a new set of contractors pop up offering to walk your company through what it needs to do to be compliant. Nobody is quite sure what the limits are--and nobody will for several years until court precedents work out the issues--so those contractors are going to tell you to assume the worst case interpretation.

PCI Compliance (technically a contractual obligation rather than legal), Sarbanes-Oxley, and GDPR were good things, but all of them spawned a sub-industry of grifters.

  • source
  • parent
  • hideshow 2 child comments