How to Get Privacy Right
October 2019
Posted by
Axiom Law
Data privacy is the new normal for companies around the globe, especially as an increasing number of countries and US states, pass privacy legislation. When California’s Consumer Protect Act (CCPA) goes into effect on January 1, 2020, it will impact over 500,000 companies alone. In addition, the consequences of getting privacy wrong are becoming crystal clear: $400 million in fines have been issued so far for companies that violated provisions of the EU’s GDPR, which went live in 2018, and in July of 2019 the FTC hit Facebook with a $5 billion fine related to data privacy violations.
However, it’s not just fines, but the reputational damage and erosion of consumer trust that is a looming and priceless factor for many companies. Often companies are caught between “doing the right thing” for data privacy and committing the budget and resources needed to fully comply with new regulations. Thomson Reuters found that 79% of companies worldwide are either failing to comply with privacy regulations, or struggling to keep up. They also reported that compliance with GDPR took up 31% of the average privacy budget, and companies spend $1.3 million on privacy annually, which is set to rise.
To be effective, ongoing privacy work must be incorporated into a company’s daily workflow, business planning, and budgeting, and must have buy-in from company leadership. However, how organizations tackle privacy varies widely, and there is no standard, or “one size fits all” approach to privacy compliance and ongoing maintenance. Privacy solutions will vary depending on the structure, industry, risk tolerance, and revenue model of your business.
Many provisions of CCPA and other data privacy legislation still need to be clarified. However, taking a “wait and see” approach, as many companies are doing, can leave your business scrambling when enforcement begins. In addition, lawyers who specialize in privacy are in high demand. Waiting until the 11th hour to set up your privacy program may mean missing the opportunity to work with a lawyer who is the strongest fit for your company.
Setting up a robust data privacy program is not just about compliance and avoiding fines. Taking privacy seriously gives you an opportunity to be a business leader. As Axiom lawyer and privacy expert Sue Gomez points out, “To run an effective privacy program, you must understand privacy principles and operate within the structure you create. You can be different and be innovative. Privacy should be embraced as a business differentiator.”
Building an effective privacy program requires leadership buy-in and a commitment to working cross-functionally. Privacy goes beyond compliance, but also about standing out as a champion for your customers across all business units. As Axiom lawyer Angelo Basu noted, "Businesses with strong ethical values tend to outperform their peers, so look at the spirit of what the [privacy] law intended and work to own it as a business. Ethics isn’t just a manual, but an operation."
Axiom’s new guide, Get Privacy Operations Right, outlines the steps to take to begin building or scaling an agile privacy function. It includes guidelines for communicating across teams and building buy-in with leadership, so you can better advocate for the resources you need. Developing an operational approach to privacy requires a cross-functional strategy and data privacy experts recommend companies take the following steps:
- Tackle privacy globally
- Privacy requires close collaboration across departments to be effective
- Identify key stakeholders across your organization who may work with existing privacy frameworks
- Build buy-in and leadership support
- Quick wins, coaching, and communication are key for company leaders
- Define a strategy to keep information about privacy flowing to leadership
- Assemble a privacy team of legal, business, and operations professionals
- For privacy projects, define clear goals, deadlines, and scope of responsibility
- Create an organized privacy work process to ensure progress and build trust throughout the organization
- Communicate regularly with leaders and employees
- Provide regular updates on developments in the privacy space and the progress of the working group
- Create privacy training materials, including FAQs, primers, and workshops specific to each department
- Continue to update and iterate on your privacy solution as regulations evolve
While privacy can feel like a moving target, it’s important to take the first steps and get started. Axiom lawyer and privacy expert Dina Maxwell concurs, noting, “There are certain privacy issues that are universal, and others that are more relevant depending on the business. Privacy compliance is always evolving – but the key is to get started and tackle the most pressing issues first.”
For an in-depth look at building a privacy function and incorporating privacy into your business operations, including insight from global privacy leaders, download Axiom’s free guide Get Privacy Operations Right. This guide harnesses insight from our bench of over 200 privacy lawyers and 250-privacy-related client engagements in 2018 and 2019 alone. Learn how to make privacy a seamless part of your business operations, build your privacy function, and be prepared as regulations and enforcement evolve.
Posted by Axiom Law
Related Content
The Insourcing Revolution Is Here. And It’s Bigger Than Anyone Expected.
In-house legal teams are insourcing more work than ever, fueled by AI. Axiom's Chief AI and Talent Officer explains why 'possible' isn't 'sustainable.'
How the Top Seven Percent of Legal Teams Prove AI ROI
100% of legal teams are increasing AI spend, but only 7% can prove ROI. Learn the strategies top-performing legal teams use to scale AI successfully.
AI-Generated Marketing Content Compliance: A Checklist for Legal Teams
Learn how legal teams can streamline AI marketing compliance with a practical checklist for risk, review workflows, disclosures, governance and AI use.
Washington My Health My Data Act & Other Privacy Frameworks
Learn how Washington's My Health My Data Act compares with HIPAA and state privacy laws, who must comply, and what businesses need to do.
5 Forces Reshaping the Legal World Gradually, Then Suddenly
Five converging forces are reshaping the legal market—from AI and capital investment to rising costs and buyer power. GCs now have the upper hand.
How to Implement Legal AI: 5 Principles for In-House Teams
Discover five proven principles for successful legal AI adoption and implementation, from training and governance to pilots, measurement and human oversight.
What Is Shadow AI? The Growing Risk Inside Legal Departments
Learn what shadow AI is, why it puts legal departments at risk, and how to govern AI with clear policies, approved tools, training, and oversight today.
How AI-Enabled Legal Teams Are Transforming M&A Due Diligence and Contract Review
Discover how AI-enabled legal teams accelerate M&A due diligence and contract review while combining legal expertise with AI for faster, smarter results.
APAC Regulatory Fragmentation in 2026: What In-House Legal Teams Need to Know
APAC regulations are diverging fast. Learn how in-house legal teams can prioritize compliance, manage risk, and adapt to evolving rules.
AI Privacy Risks: What Legal Teams Need to Know Before Employees Use Public AI Tools
Legal teams face growing AI privacy risks. Learn how public AI tools can expose sensitive data, impact privilege, and create compliance challenges.
The Legal Profession Isn’t Ready for What's Coming: Richard Susskind's Unfiltered Take from Axiom's London Event
Richard Susskind shares a candid vision of AI's impact on law, urging legal leaders to prepare now for AGI, disruption, and transformation.
The Era of the Law Firm Panel is Ending
Law firm panels were built for a different era. Today's GCs need a dynamic portfolio of law firms, ALSPs, AI, and in-house talent to source work strategically.
Legal AI’s ROI Mirage
Legal departments are investing heavily in AI, yet most can't prove its value. Explore the ROI gap revealed in Axiom's 2026 AI report.
How Legal Departments Can Prove ROI from AI Implementation
How legal departments can measure and prove AI ROI with practical frameworks, key metrics, and strategies for turning efficiency gains into budget impact.
We Were Both Wrong About Legal AI. Here’s What Changed Our Minds.
Learn how Axiom's CTO and DraftPilot's CEO went from legal AI skeptics to believers—and the three assumptions they think most legal teams still get wrong.
What Are Export Controls? ITAR & EAR Explained
Export controls explained. Learn the differences between ITAR, EAR, and OFAC, key compliance risks, enforcement trends, and what businesses need to know.
Legal Project Management: Improve Efficiency and Control Costs
Learn how legal project management improves efficiency, controls legal costs, strengthens communication, and delivers predictable outcomes.
What Is Legal Tech? A Guide for In-House Legal Teams
A clear guide to legal tech for in-house teams—what it is, key tools, benefits, and how to implement it to boost efficiency and reduce costs.
- North America
- Must Read
- Expertise
- Legal Department Management
- Work and Career
- Perspectives
- Corporate & Commercial
- Legal Technology
- United Kingdom
- Australia
- Hong Kong
- Singapore
- State of the Legal Industry
- Technology & AI
- Central Europe
- Legal Operations
- Legal Support Professionals
- Projects
- Regulatory & Compliance
- Tech+Talent
- Data Privacy & Cybersecurity
- Talent Spotlight
- Technology
- Secondments
- Global
- Specialized Advice
- Axiom in the News
- Finance & Capital Markets
- Healthcare & Life Sciences
- Intellectual Property
- Law Firms
- Recruitment Solutions
- Cost Savings
- Featured Talent Spotlight
- GC Report
- Diversified Financial Services
- Labor & Employment
- M&A & Divestitures
- Budgeting Report
- Energy
- Investment Banking
- Banking
- Construction
- Consulting
- Consumer Packaged Goods
- In-House Report
- Manufacturing
- Materials
- Pharmaceuticals
- Professional Services
- Retail
- Transportation
- AI Survey Report
- Aerospace & Defense
- Automotive
- Business Services
- Consumer Services
- DGC Report
- Education
- Food & Beverage
- Hospitality
- Insurance
- Litigation & Dispute Resolution
- Private Equity
- Public Sector
- Real Estate
- Telecom
- Utilities
- Media
- TEST TAG NAME CHANGE
Get more of our resources for legal professionals like you.
