Author
Listed:
- Determann, Lothar
(Baker McKenzie, USA)
- Doyle, Graham
(Data Protection Commission Ireland, Ireland)
- Urban, Jennifer M.
(California Privacy Protection Agency, USA)
- Will, Michael
(Bavarian State Office for Data Protection Supervision (BayLDA), Germany)
Abstract
Global businesses face growing privacy and data protection obligations. Duties can vary by jurisdiction, and many businesses struggle to decide where to direct finite compliance resources. This paper, developed from a panel the authors prepared for the IAPP Global Summit 2026, argues that the European Union’s (EU) General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), the most comprehensive and demanding regimes to which most global businesses are already subject, can serve as a common compliance core whose requirements can be leveraged to satisfy most other data protection regimes. It distils that core into 12 concrete priorities, grouped into five themes: securing the foundation; disciplining the data; respecting the individual; building accountability; and governing automation while anticipating legal change. The paper maps each priority to its anchoring GDPR and CCPA provisions and to the enforcement and litigation exposure that makes it consequential for global privacy, artificial intelligence (AI) governance, and cyber security compliance. The authors conclude that although obligations differ in some details and many organisations face additional sector and jurisdiction-specific rules, businesses that act on these 12 priorities will address the requirements common to data protection laws worldwide and materially reduce risk. The wider implication, underscored by recent deregulatory proposals in the EU and contests between federal and state authorities over AI in the US, is that organisations need a durable, principle-led compliance core and a standing process to monitor change. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Suggested Citation
Determann, Lothar & Doyle, Graham & Urban, Jennifer M. & Will, Michael, 2026.
"With regulatory pressure, operational focus: Twelve action priorities for global privacy, AI governance, and cyber security compliance,"
Journal of Data Protection & Privacy, Henry Stewart Publications, vol. 9(1), pages 9-18, August.
Handle:
RePEc:aza:jdpp00:y:2026:v:9:i:1:p:9-18
Download full text from publisher
As the access to this document is restricted, you may want to
for a different version of it.
Corrections
All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:aza:jdpp00:y:2026:v:9:i:1:p:9-18. See general information about how to correct material in RePEc.
If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.
We have no bibliographic references for this item. You can help adding them by using this form .
If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.
For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Henry Stewart Talks (email available below). General contact details of provider: .
Please note that corrections may take a couple of weeks to filter through
the various RePEc services.