IAPP Global Privacy Summit – April 2022

EDPO attended the IAPP Global Privacy Summit in Washington DC (12 & 13 April). Here are the main insights from the conferences:
The IAPP Global Privacy Summit kicked off with a great opening session.
According to Apple CEO Tim Cook, “Tech is neither inherently good or bad. It’s what we make of it. It’s a mirror that reflects the people who make it, use it, regulate it”. He added that “People can’t escape their moral responsibility by saying that the machine made them do it. Those who make the tools have a responsibility towards the people they service. Privacy cannot and will not become a relic of the past.”
EU Commissioner Didier Reynders said that “tech and innovation will not come at the cost of values and fundamental rights.” The US and the EU have been working on a new data transfer framework agreement for a year. It will provide safeguards to limit the access of data by governmental authorities in the US. He added: “The work continues: the details need to be finalised and translated into legal text. This could be finalised by the end of the year. This confirms once more how much the US and the EU can achieve with their shared values.”
Brad Smith from Microsoft led a great closing session of the successful IAPP Global Privacy Summit.
“We enter a new era of technology”, he said. “We need a large community and a new mindset to manage tech through the decade ahead.” We can look at tech through two lenses: the present where data can help us solve global issues around the world; and the past where we see that similar rapidly developing technologies were regulated by governments because it had such a big impact on life and law (see the development of the railroad in the US for example).
“However, no industry has ever had to adapt so quickly on a global basis. We’ll need to mature and lean in, to coordinate within governments and across borders, and we need people who think creatively. Progress in a democracy always requires compromise and that’s difficult to find. Comprehensive legislation in the US is not just needed but long overdue. The lack of legislation doesn’t stop global regulation; it just makes the US less influential. This will not be easy, this will not be beautiful. But the future can be bright.”
EDPO at the 38th Privacy Laws & Business Conference in Cambridge
From AI governance to legal design: key takeaways from Europe’s leading privacy event EDPO recently took part in the 38th International...
IAPP Intensive – London, UK – March 2023
DAY 1 The IAPP - International Association of Privacy Professionals Data Protection Intensive: UK 2023 kicked off this Wednesday with John...
EDPO participated in the Belgian Economic Mission to Japan – Dec. 2022
EDPO is thrilled to have been part of the Belgian Economic Mission to Japan with HRH Princess Astrid of Belgium last week - and what a crazy...
Follow us on Linkedin for daily breaking GDPR news!
The General Data Protection Regulation (GDPR) continues to apply to many US companies in 2025, even if they do not have a physical presence in the European Union. Despite years of guidance and enforcement, the same misunderstandings keep reappearing. Here are five of the most common GDPR mistakes US companies make — and how to avoid them.
Mistake 1 – Confusing the Data Protection Officer (DPO) with the EU GDPR Representative
An EU GDPR Representative is a local contact point for data protection authorities and individuals in the EU. Non-EU companies that are subject to the GDPR must appoint a representative to ensure smooth communication and compliance.
A Data Protection Officer (DPO) is responsible for overseeing a company’s internal data protection strategy and ensuring compliance with the GDPR. The DPO monitors data processing, conducts audits, and trains staff.
The DPO works inside the organisation, while the GDPR Representative is based in the EU and acts as an external contact point. Many US companies confuse the two roles, but under the GDPR, they are separate obligations and sometimes both are required.
Mistake 2 – Misunderstanding the extraterritorial scope of the GDPR
The GDPR applies to non-EU companies if they offer goods or services to individuals in the EU or monitor their behaviour online. This applies regardless of where the company is located.
Selling products to EU customers, operating an EU-facing website in EU languages, accepting payments in euros, or tracking EU visitors with cookies or analytics tools can all trigger GDPR obligations.
Mistake 3 – Incorrectly relying on the Privacy Shield (now EU-US Data Privacy Framework)
The Privacy Shield was an agreement that allowed certified US companies to transfer personal data from the EU to the US. In 2020, it was invalidated by the Court of Justice of the European Union in the Schrems II decision.
In 2023, the EU-US Data Privacy Framework (DPF) replaced the Privacy Shield. While participation in the DPF can help facilitate transatlantic data transfers, it does not exempt companies from GDPR compliance.
US companies must ensure that data transfers are lawful under the GDPR. This may involve joining the DPF, using Standard Contractual Clauses (SCCs), or implementing other approved safeguards.
Mistake 4 – Incomplete or unclear privacy policies
The GDPR requires privacy policies to be clear, accessible and transparent. They must explain what personal data is collected, how it is used, the legal basis for processing, and the rights of data subjects.
Many US companies omit details such as data retention periods, contact information for the EU Representative, or instructions on how to exercise data subject rights.
Mistake 5 – Underestimating GDPR fines and enforcement
Data protection authorities have issued fines to companies of all sizes, including non-EU businesses. In 2025, penalties for non-compliance remain high — up to €20 million or 4% of annual global turnover, whichever is higher.
Regular compliance reviews Data Protection Impact Assessments (DPIAs), staff training, and appointing an EU GDPR Representative can help mitigate risks.
How EDPO can help your business stay GDPR compliant
EDPO acts as your official EU GDPR Representative, ensuring compliance with Article 27 of the GDPR and facilitating communication with EU authorities.
For companies targeting the UK market, EDPO also offers UK GDPR Representative services to ensure compliance with the UK’s data protection regime.

