Baker McKenzie Partner Lothar Determann has co-authored a new article in the Journal of Data Protection & Privacy with leaders from some of the world's most prominent data protection authorities, including Graham Doyle of Ireland's Data Protection Commission, Jennifer M. Urban, Chair of the California Privacy Protection Agency, and Michael Will, President of Germany's Bavarian State Office for Data Protection Supervision (each providing their own personal views).
The article examines how multinational organizations can navigate increasingly complex privacy, artificial intelligence and cybersecurity requirements, arguing that the EU's General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) can serve as a practical compliance foundation for organizations operating across multiple jurisdictions.
Drawing on insights from the authors' panel at the IAPP Global Summit 2026, the article identifies 12 key priorities for reducing regulatory and litigation risk, including strengthening cybersecurity programs, preparing for data incidents, minimizing and deleting unnecessary data, responding effectively to data subject requests and establishing governance frameworks for AI systems. The authors emphasize that while privacy obligations continue to evolve globally, organizations can build more resilient compliance programs by focusing on core principles shared across major regulatory regimes.
The article examines how multinational organizations can navigate increasingly complex privacy, artificial intelligence and cybersecurity requirements, arguing that the EU's General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) can serve as a practical compliance foundation for organizations operating across multiple jurisdictions.
Drawing on insights from the authors' panel at the IAPP Global Summit 2026, the article identifies 12 key priorities for reducing regulatory and litigation risk, including strengthening cybersecurity programs, preparing for data incidents, minimizing and deleting unnecessary data, responding effectively to data subject requests and establishing governance frameworks for AI systems. The authors emphasize that while privacy obligations continue to evolve globally, organizations can build more resilient compliance programs by focusing on core principles shared across major regulatory regimes.
Explore Our Newsroom