These questions come from discussions with privacy officers over the past year. You're not just asking about what happened in 2019, you're trying to figure out what it means for your program in 2020 and beyond. Here's what I'm telling teams who are still catching their breath.
Q1: We barely got CCPA-ready in time. What should we have done differently?
Focus on infrastructure, not just documentation.
The rush to comply with the California Consumer Privacy Act showed a clear pattern: teams that prioritized building intake systems and workflow automation managed better than those who spent months on policy language. Your DSAR response process needs routing logic, assignment rules, and verification steps before it needs perfect prose.
Here's what works: Build a simple intake form that captures request type, identity verification, and scope. Route deletion requests differently than access requests. Set up a tracking system to monitor request status and flag those nearing the 45-day deadline.
Documentation can evolve. The workflow can't wait.
Q2: How do we keep GDPR compliance from becoming a permanent firefighting operation?
Move from reactive to scheduled.
If you're treating GDPR as a project with an end date, you're setting yourself up for burnout. Operationalize GDPR compliance by integrating it into your regular schedule, not as a crisis response.
Set quarterly reviews for your Article 30 records. Schedule bi-annual vendor assessments tied to contract renewals. Update data mapping when you launch new features, not when a regulator requests it. Teams that aren't overwhelmed have turned compliance tasks into calendar events.
Stop trying to document everything perfectly on the first pass. Your records of processing activities under Article 30 will always be incomplete because your business keeps changing. Accept that you're maintaining a living document.
Q3: Our legal team says one thing, our engineering team says another. How do we actually decide what's compliant?
Clarify the requirement, then discuss implementation.
When legal says "we need consent" and engineering says "that'll break the user experience," you're not having the same conversation. Legal refers to Article 6(1)(a) GDPR. Engineering describes a technical constraint. Neither is wrong, but you're talking past each other.
Try this: Write down the exact Legal Obligation, including the article number and specific obligation. Ask engineering to propose three ways to meet it. Then have legal evaluate those options against the standard for freely given, specific, informed, and unambiguous consent.
You'll often find more flexibility than "can't be done" suggests and more constraints than "just get consent" implies.
Q4: What's actually worth tracking for 2020?
Focus on enforcement patterns, not headlines.
Regulatory action in 2019 showed that authorities care more about your breach response than the breach itself. They're looking at your 72-hour notification timeline, your documentation of Technical and Organisational Measures, and whether you took the breach seriously.
Track these three things in 2020: how your peers in similar industries are getting fined, that's your risk profile; what your supervisory authority is publishing in guidance and FAQs, that's your exam answer key; and which of your vendors are getting breached, that's your third-party risk signal.
Ignore speculation about new state laws until they're passed. You can't comply with a bill.
Q5: Should we be preparing for more California-style laws in other states?
Yes, but don't create fifty state-specific programs.
If your CCPA compliance only works for California, you've built the wrong thing. Design for the highest common denominator: the strictest definition of personal information, the shortest response timeline, and the broadest set of rights.
Your intake form should ask "which state are you in?" but your backend process should assume the request might qualify under multiple frameworks. A California deletion request and a GDPR right to be forgotten request should follow the same verification and execution steps.
Teams that handle multi-state compliance well in 2020 are building modular systems now, allowing new requirements to be integrated without overhauling the entire workflow.
Q6: How do we know if we're actually making progress, or just checking boxes?
Measure response time and escalation rate, not policy count.
If your compliance dashboard shows "47 policies published" and "12 training sessions delivered," you're measuring activity, not outcomes. Try these instead: average days to fulfill a DSAR, percentage of requests that required legal escalation, number of processing activities added to your Article 30 records without a corresponding privacy review.
The goal isn't to have the most documentation. It's to make privacy decisions faster and more consistently. If your team can answer "can we process this data for this purpose?" in under a day instead of a week, that's progress.
Where to go for more
Your supervisory authority's guidance library is more useful than any consultant's blog. The European Data Protection Board publishes guidelines on specific GDPR articles, read those relevant to your processing activities. The California Attorney General's office publishes CCPA regulations and proposed modifications, track those if you're subject to California law.
And talk to your peers. The privacy officers who survived 2019 without burning out are the ones who built networks, shared workflow templates, and didn't try to solve every problem alone.



