The EUs General Data Protection Regulation (GDPR) is a big change from how many firms have approached data protection in the past. Organizations need to first identify if they are a data processor or controller, as well as what data they already hold. PII can be everywhere from email and social platforms to HR, HCM, and CRM systems. There are six lawful reasons for processing personal data: consent, contract, legal obligation, vital interests, public task, and legitimate interests.”]

