The General Date Protection Regulation (GDPR) made its debut on the global privacy stage in 2018, and now, three years later, most U.S. companies doing business in the EU are well-aware of the regulation’s main provisions and their daily operational impact. However, the GDPR’s rules are expansive; and as a result, some of its “lesser known” articles have been overlooked by a number of smaller companies with limited in-house privacy resources.

