The Journal of Data Protection and Privacy published an article this week co-authored by Lothar Determann alongside Graham Doyle of Ireland’s Data Protection Commission and Jennifer M. Urban of the California Privacy Protection Agency that distills complex regulatory demands into 12 concrete action priorities. The piece, titled With regulatory pressure, operational focus, builds directly on remarks the authors prepared for a panel at the IAPP Global Summit in Washington from March 30 to April 2, 2026. According to the co-authors, the European Union’s General Data Protection Regulation and California’s Consumer Privacy Act together establish a robust common core that organisations can adapt to satisfy obligations in most other jurisdictions while reducing overall enforcement and litigation exposure.
The 12 priorities are grouped under five themes that track the personal data lifecycle, starting with securing the foundation through measures to protect data and prepare for incidents. Subsequent themes address disciplining data via minimisation and deletion, respecting individuals by informing them and responding to their requests, building accountability with vendor contracts and impact assessments, and finally governing artificial intelligence lawfully while maintaining a process to monitor regulatory change. The journal article maps each item to specific GDPR articles and CCPA provisions, along with related cybersecurity audit requirements that have taken on added significance as regulators increase scrutiny of operational effectiveness.
Cisco’s 2026 Data Privacy Benchmark Study indicated that 38 percent of organisations now spend 5 million dollars or more annually on privacy compliance, up sharply from 14 percent in 2024, reflecting the mounting resource commitments required to meet these expectations.[[1]](https://app.stationx.net/articles/data-privacy-statistics) Cumulative fines issued under the GDPR have surpassed 7 billion euros since the regulation took effect in 2018, a tally that multiple regulatory trackers show continues to climb as authorities coordinate more closely on cross-border cases. The authors argue that organisations adopting the 12 priorities will address requirements common to data protection laws worldwide and materially lower their risk profiles.
Graham Doyle said at the IAPP Global Summit on March 30, 2026, “Doing something is better than doing nothing. Focus on principles. And don’t let perfect become the enemy of good.” Reports from the summit highlighted a shared regulatory emphasis on moving beyond paper compliance toward demonstrable outcomes, particularly in explaining AI decisions and preventing consumer harm. A separate assessment of the event noted that privacy, cybersecurity and AI governance are increasingly viewed as interconnected rather than separate disciplines.
The journal article carries a clear disclaimer that its content reflects the personal opinions of the authors and must not be attributed to their agencies, boards, law schools, employers or clients. Determann serves as a partner at a major international law firm and holds professorships at Freie Universität Berlin and UC Berkeley Law, while Urban additionally chairs the California Privacy Protection Agency. Promotional coverage of the publication also referenced views from Michael Will, president of Germany’s Bavarian State Office for Data Protection Supervision, although he is not listed among the formal co-authors.
Organisations face an evolving landscape in which proposed digital regulations in the European Union and competing federal and state measures on artificial intelligence in the United States add further complexity. The article concludes that a durable, principle-led compliance program paired with ongoing monitoring represents the most pragmatic approach for multinational entities. This standing process for adaptation, listed as the twelfth priority, equips companies to respond to legal developments without waiting for perfect alignment across all regimes.
ع