With regulatory pressure, operational focus: Twelve action priorities for global privacy, AI governance, and cyber security compliance
Abstract
Global businesses face growing privacy and data protection obligations. Duties can vary by jurisdiction, and many businesses struggle to decide where to direct finite compliance resources. This paper, developed from a panel the authors prepared for the IAPP Global Summit 2026, argues that the European Union’s (EU) General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), the most comprehensive and demanding regimes to which most global businesses are already subject, can serve as a common compliance core whose requirements can be leveraged to satisfy most other data protection regimes. It distils that core into 12 concrete priorities, grouped into five themes: securing the foundation; disciplining the data; respecting the individual; building accountability; and governing automation while anticipating legal change. The paper maps each priority to its anchoring GDPR and CCPA provisions and to the enforcement and litigation exposure that makes it consequential for global privacy, artificial intelligence (AI) governance, and cyber security compliance. The authors conclude that although obligations differ in some details and many organisations face additional sector and jurisdiction-specific rules, businesses that act on these 12 priorities will address the requirements common to data protection laws worldwide and materially reduce risk. The wider implication, underscored by recent deregulatory proposals in the EU and contests between federal and state authorities over AI in the US, is that organisations need a durable, principle-led compliance core and a standing process to monitor change. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
The full article is available to subscribers to the journal.
Author's Biography
Lothar Determann practises technology law at Baker McKenzie, Palo Alto, admitted in California and Germany. He teaches law at the Freie Universität Berlin (since 1994) and Berkeley School of Law (since 2004) and has authored more than 180 articles and six books, including ‘Determann’s Field Guide to Data Privacy Law’ (6th edition, 2025, also available in Arabic, Chinese, French, German, Greek, Hungarian, Italian, Japanese, Korean, Portuguese, Russian, Spanish, Turkish, and Vietnamese), ‘California Privacy Law — Practical Guide and Commentary on US Federal and California Law’ (6th edition, 2026), and ‘Determann’s Field Guide to Artificial Intelligence Law’ (2024, also available in Chinese, French, German, Korean, Spanish, and Turkish).
Graham Doyle is a Deputy Commissioner and Head of Corporate Affairs, Media and Communications at the Irish Data Protection Commission (DPC). He develops and manages the DPC’s communications strategy, including extensive national and international media engagement, and represents the DPC on the European Data Protection Board’s Communications Network. He leads the DPC’s Corporate Affairs team and serves on its Audit and Risk Committee. Graham previously served as Head of Communications and Research at the Garda Síochána Ombudsman Commission and as Head of Communications and Customer Service at Student Universal Support Ireland, and holds a graduate qualification in public management, specialising in law and the administration of justice.
Jennifer M. Urban was appointed by California Governor Gavin Newsom in March 2021 as the inaugural Chair of the California Privacy Protection Agency (CPPA) Board. She is a Clinical Professor of Law at the University of California, Berkeley School of Law, where she directs policy initiatives at the Samuelson Law, Technology and Public Policy Clinic. Jennifer previously founded and directed the Intellectual Property and Technology Law Clinic at the University of Southern California, Gould School of Law, was the Samuelson Clinic’s first fellow, and practised as an attorney with the Venture Law Group in Silicon Valley.
Michael Will was appointed President of the Bavarian State Office for Data Protection Supervision (BayLDA) for a five-year term, first on 1st February, 2020 and again on 1st February, 2025. He began his career as an administrative lawyer in the service of the Free State of Bavaria in 1995 and subsequently held posts at the Supreme Building Authority in the Bavarian State Ministry of the Interior, the Bavarian State Chancellery, and the Landshut District Office. In 2009 Michael was appointed Head of the Data Protection Department at the Bavarian State Ministry of the Interior, Sport and Integration, serving also as official Data Protection Officer and as a member of the Data Protection Commission of the Bavarian State Parliament. On behalf of the Federal Council, Michael followed the deliberations of the Council Working Group on Data Protection and Information Exchange (DAPIX) on the EU General Data Protection Regulation from 2012 to 2015 and acted as country observer on the committee established under Article 93 of the GDPR.