That doesn't match my experience.
But more importantly, there are areas of the law that require fairly comprehensive understanding of computer systems, both on the development, infrastructure and applications such as data science to properly understand. (Not understanding the tech makes it impossible to fully understand the law).
For instance, if an average lawyer tasked with ensuring that a company is in compliance with GDPR, and come across terminology such as "Data Protection by Design & Default" with further references to "Pseudonymization" and "Anonymization", will they even know how to start a review of the present situation in an organization for these topics?
My experience is that there is often a significant gap between where the understanding of the legal team ends and where the development and data science teams take responsibility that isn't covered by anyone.
The main problem is that legal coverage of data protection topics (such as [1]) often do not prescribe very specific specifications for how to be compliant. Instead, it requires people to use good judgement. Someone with a background in law will be used to this, but will usually not understand the technology well enough to have developed the kind of intuition needed to do so.
And when they sit down with a team of typical engineers, communication can get really difficult. The engineers tend to want very specific instructions on what to do, and many will not react well if confronted with the relatively loose (for an engineer) legal language.
Some will just ignore the parts they don't understand, while others will go to the other extreme and propose draconian measures that will at best be extremely costly. The latter group tends to be ignored by management.
In the end, many compliance initiatives end up with a lot of forms that serve as little more than window dressing, but where the hard bits that nobody really understand end up ignored.
To really achieve compliance, an organization will need people who are (in the same person) able to read legal texts with a lawyer's ability to interpret combined with the ability think like a black hat hacker trying to penetrate, a paranoid operations person terrified of data loss or a shady data scientist that keeps taking all sorts of shortcuts.
Few organizations have such lawyers available.
[1] https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-re...