I'm not surprised. I used to work on a team at Google that had to deal with GDPR (I still work at Google, but on a different team), and we had to get legal review for a lot use-cases. For example, we had a backup system that took snapshots of our user-provided data. If a user requested their data be purged, should we purge all the backups as well? Since we had legal counsel in house, it wasn't too terrible. For a sma…
Are there any resources for small businesses in the US that want to protect themselves from onerous fines the data regulators can impose? How can they even begin to assess the risks of noncompliance?