
| Characteristic | EU | United States |
|---|---|---|
| Right to be forgotten | 5 | 5.4 |
| Data portability | 4.6 | 4.9 |
| Conducting data protectection impact assessments | 4.6 | 4.9 |
| Gathering explicit consent | 4.2 | 4.9 |
| Fulfilling subject access requests | 3.9 | 4.7 |
| Cross border data transfer | 3.9 | 4 |
| Understanding regulatory oversight | 3.8 | 4.2 |
| Breach notification requirements | 3.7 | 4.5 |
| Restrictions on profiling | 3.7 | 3.3 |
| Determining your lawful basis for processing | 3.1 | 3.2 |
| Understanding jurisdictional scope | 2.8 | 3.1 |
| Appointing a legal representative pursuant to Article 27 | 2.4 | 3.6 |
| Mandatory DPO requirement | 1.7 | 2.8 |
The chart is not accessible to screen readers. Please switch to the table view to access the data.
Loading statistic...
Download
Region
United States, EU
Survey time period
2019
Number of respondents
370*
Special properties
privacy experts
Method of interview
Online survey
Supplementary notes
This question was phrased by the source as follows:"Rate the following legal obligations of the GDPR in terms of how difficult they are for your company to comply." Score on a 0-10 scale: 0=Not At All Difficult; 10=Extremely Difficult.
*Privacy experts answering the survey worked in companies with headquarters located as follows:
U.S.:39%; EU (UK excluded):33%; UK:13%; Canada: 6%; other; 5%; non-Europe:3%;Australia/New Zealand: 1 %.
Citation formats









