How to Get Privacy Right
October 2019
By
Axiom Law
Data privacy is the new normal for companies around the globe, especially as an increasing number of countries and US states, pass privacy legislation. When California’s Consumer Protect Act (CCPA) goes into effect on January 1, 2020, it will impact over 500,000 companies alone. In addition, the consequences of getting privacy wrong are becoming crystal clear: $400 million in fines have been issued so far for companies that violated provisions of the EU’s GDPR, which went live in 2018, and in July of 2019 the FTC hit Facebook with a $5 billion fine related to data privacy violations.
However, it’s not just fines, but the reputational damage and erosion of consumer trust that is a looming and priceless factor for many companies. Often companies are caught between “doing the right thing” for data privacy and committing the budget and resources needed to fully comply with new regulations. Thomson Reuters found that 79% of companies worldwide are either failing to comply with privacy regulations, or struggling to keep up. They also reported that compliance with GDPR took up 31% of the average privacy budget, and companies spend $1.3 million on privacy annually, which is set to rise.
To be effective, ongoing privacy work must be incorporated into a company’s daily workflow, business planning, and budgeting, and must have buy-in from company leadership. However, how organizations tackle privacy varies widely, and there is no standard, or “one size fits all” approach to privacy compliance and ongoing maintenance. Privacy solutions will vary depending on the structure, industry, risk tolerance, and revenue model of your business.
Many provisions of CCPA and other data privacy legislation still need to be clarified. However, taking a “wait and see” approach, as many companies are doing, can leave your business scrambling when enforcement begins. In addition, lawyers who specialize in privacy are in high demand. Waiting until the 11th hour to set up your privacy program may mean missing the opportunity to work with a lawyer who is the strongest fit for your company.
Setting up a robust data privacy program is not just about compliance and avoiding fines. Taking privacy seriously gives you an opportunity to be a business leader. As Axiom lawyer and privacy expert Sue Gomez points out, “To run an effective privacy program, you must understand privacy principles and operate within the structure you create. You can be different and be innovative. Privacy should be embraced as a business differentiator.”
Building an effective privacy program requires leadership buy-in and a commitment to working cross-functionally. Privacy goes beyond compliance, but also about standing out as a champion for your customers across all business units. As Axiom lawyer Angelo Basu noted, "Businesses with strong ethical values tend to outperform their peers, so look at the spirit of what the [privacy] law intended and work to own it as a business. Ethics isn’t just a manual, but an operation."
Axiom’s new guide, Get Privacy Operations Right, outlines the steps to take to begin building or scaling an agile privacy function. It includes guidelines for communicating across teams and building buy-in with leadership, so you can better advocate for the resources you need. Developing an operational approach to privacy requires a cross-functional strategy and data privacy experts recommend companies take the following steps:
- Tackle privacy globally
- Privacy requires close collaboration across departments to be effective
- Identify key stakeholders across your organization who may work with existing privacy frameworks
- Build buy-in and leadership support
- Quick wins, coaching, and communication are key for company leaders
- Define a strategy to keep information about privacy flowing to leadership
- Assemble a privacy team of legal, business, and operations professionals
- For privacy projects, define clear goals, deadlines, and scope of responsibility
- Create an organized privacy work process to ensure progress and build trust throughout the organization
- Communicate regularly with leaders and employees
- Provide regular updates on developments in the privacy space and the progress of the working group
- Create privacy training materials, including FAQs, primers, and workshops specific to each department
- Continue to update and iterate on your privacy solution as regulations evolve
While privacy can feel like a moving target, it’s important to take the first steps and get started. Axiom lawyer and privacy expert Dina Maxwell concurs, noting, “There are certain privacy issues that are universal, and others that are more relevant depending on the business. Privacy compliance is always evolving – but the key is to get started and tackle the most pressing issues first.”
For an in-depth look at building a privacy function and incorporating privacy into your business operations, including insight from global privacy leaders, download Axiom’s free guide Get Privacy Operations Right. This guide harnesses insight from our bench of over 200 privacy lawyers and 250-privacy-related client engagements in 2018 and 2019 alone. Learn how to make privacy a seamless part of your business operations, build your privacy function, and be prepared as regulations and enforcement evolve.
Posted by Axiom Law
Related Content
Continuous Volatility Is the New Normal: Building Corporate Legal Departments for Constant Disruption and Uncertainty
Corporate legal teams must adapt to constant global disruption by building flexible, cost-efficient resourcing models for evolving risk and demand.
Same Problem, One Fix: How a Change Management Framework Can End AI Stall and Law Firm Habit Together
Law firms and AI adoption share the same root problem: change resistance. Learn how the Beckhard-Harris model helps legal teams drive transformation.
What the Quiet Revolution Taught Us
Axiom CRO Sara Morgan on 26 years of ALSP growth: why in-house legal leaders are 3x more satisfied with alternative providers—and what comes next.
The Law Firm Reflex Is Costing You Millions
Axiom CRO Sara Morgan: 61% of legal departments default to law firms when workload spikes, and it's costing them millions. Here's how to break the reflex.
AI Governance Framework: How Legal Teams Can Get It Right
AI governance framework guide for legal teams: risk-based AI policies, data governance, vendor safeguards & compliance best practices.
The Real Reason Legal Departments Can’t Change—And What to Do About It
New Axiom research reveals mindset—not budget—is the biggest barrier to legal transformation, and how GCs can close the knowing-doing gap.
Will AI Replace In-House Lawyers? What General Counsel Need to Know
Will AI replace lawyers? Discover how AI is transforming legal work. Learn why human judgment, business acumen, and communication matter more than ever.
What the WSJ $3,400 an Hour Story Really Means for Legal Teams
Premium firms may charge $3,400/hr, but budgets break from rising associate rates. Legal teams need elastic capacity plus AI to control spend.
Best in Class: Study Ranks Axiom #1 Across Key Performance Metrics
Axiom ranks #1 in 8 out of 9 key performance metrics for flexible legal talent providers, demonstrating unmatched expertise, coverage, and cost-effectiveness. Discover why GCs trust Axiom.
ESG Reporting: Full Guide, Standards, and Requirements
Learn what ESG reporting is, key frameworks like GRI and SASB, evolving regulations, and how to build a reporting program that delivers real business value.
Law.com: The CLOUD Act, Encryption and the US-UK Standoff in 2026
The US-UK encryption standoff has trapped tech companies between irreconcilable mandates—in-house counsel must navigate strategic risks when compliance with both jurisdictions becomes impossible.
AI Contract Management: What Legal Teams Need to Know
As legal teams face mounting pressure to do more with less, AI contract management solutions offer a compelling answer, transforming the contract process.
Why 80% of In-House Teams Are Rethinking Their Law Firm Relationships
New research reveals a legal market caught between legacy habits and transformation, with significant implications for how legal work gets done.
State Privacy Laws: 2026 Changes & Compliance
Navigate 2026 state privacy law changes across 15 states. Learn compliance requirements for Indiana, Kentucky, Rhode Island & key CCPA updates.
Why Axiom Outperforms LPO on Quality, Flexibility, and Business Impact
While LPO can solve some problems, it frequently creates new ones. This is where Axiom’s model offers a fundamentally different and better approach.
Finding Professional Confidence, Personal Balance: How Axiom Empowered a Commercial Attorney's Career Transformation
Discover how Axiom empowered commercial attorney Eileen to rebuild her career and confidence while balancing single parenthood after personal tragedy.
The AI Paradox: Why Your Legal Team's Productivity Gains Are Fueling a Retention Crisis
93% of legal professionals say AI boosts productivity, yet 76% fear job loss. New research reveals how AI anxiety is driving turnover. See the new data.
Essential Resources for In-House Legal Teams: 2025 Year in Review
Explore Axiom's top 2025 legal resources on AI adoption, talent retention, budget transformation, regulatory insights for in-house legal teams, and more.
Continuous Volatility Is the New Normal: Building Corporate Legal Departments for Constant Disruption and Uncertainty
Posted by David McVeigh- North America
- Must Read
- Expertise
- Legal Department Management
- Work and Career
- Perspectives
- State of the Legal Industry
- Legal Technology
- United Kingdom
- Australia
- Hong Kong
- Singapore
- Artificial Intelligence
- General Counsel
- Central Europe
- Legal Operations
- Solutions
- Regulatory & Compliance
- Spotlight
- Data Privacy & Cybersecurity
- Technology
- Commercial & Contract Law
- Corporate Law
- Global
- Tech+Talent
- Axiom in the News
- Large Projects
- Finance
- Law Firms
- Featured Talent Spotlight
- GC Report
- Healthcare
- Cost Savings
- Intellectual Property
- Videos
- Capital Markets
- Diversified Financial Services
- Labor & Employment
- Secondments
- Budgeting Report
- Commercial Transaction
- Energy
- Investment Banking
- Regulatory Response
- Banking
- Construction
- Consulting
- Consumer Packaged Goods
- Financial Services
- Healthcare & Life Sciences
- In-House Report
- Industrial
- Legal Support Professionals
- Manufacturing
- Materials
- Mergers and Acquisitions
- Pharmaceuticals
- Retail
- Transportation
- Aerospace & Defense
- Automotive
- Business Services
- Consumer Services
- DGC Report
- Education
- Food And Beverage
- Hospitality
- Insurance
- Litigation
- Private Equity
- Professional Services
- Public Sector
- Real Estate
- Specialized Advice
- Telecom
- Utilities
- News
- Recruitment Solutions
Get more of our resources for legal professionals like you.
