▶EU AI Act 2026, how does it affect privacy jobs?
AI Act adds transparency + risk-assessment requirements for high-risk systems (hiring, credit, content filtering). Privacy engineers now audit ML models for training-data provenance, consent, bias. New roles: "AI Privacy Engineer" (€95-130k EU, £90-120k UK), "Model Governance Analyst" (€80-110k). Compliance deadline ~Feb 2026 in-scope, phased rollout until 2027. Employers scrambling; audit demand up 2.5x since announcement.
▶GDPR vs CCPA penalties, which is more painful?
GDPR: tiered (€10-20M or 2-4% revenue, whichever is higher). CCPA: $2,500/violation or $7,500/intentional violation (no revenue cap, so smaller cos feel it more). CCPA fines rarer but larger per-incident ($100M+ settlements exist). Practical impact: GDPR requires DPO; CCPA just needs a privacy policy. Startups in EU = GDPR first. US + EU = dual-track compliance (OneTrust handles both).
▶What does a Data Subject Access Request (DSAR) actually require?
Person says "give me my data." You have 30 days (GDPR) to return all personal data you hold in machine-readable format (CSV, JSON). Includes inferred data (ML scores, segments). Must review 1000+ systems (email, CRM, analytics, ads platforms). 30% of requests reveal shadow data. Transcend automates DSAR routing; Osano tracks deadlines. Cost per DSAR: €500-2000 without automation, €50-200 with tools.
▶SaaS vendor due diligence, what DPA (Data Processing Agreement) checks matter most?
Ask: (1) Data location + transfers legal basis, (2) Sub-processors listed + approval process, (3) Breach notification timeline, (4) Right to audit + deletion, (5) Encryption at-rest/in-transit. 80% of vendors have boilerplate DPAs; negotiate sub-processor indemnity + breach SLA. BigID scans contracts; TrustArc maintains matrix. Red flag: "we don't track sub-processors" = nope.
▶Which OneTrust features are actually worth the $50k+ license fee?
Consent banner + preference center (mandatory for cookieless tracking). Data inventory (half your ROI). Third-party risk scoring (saves audit time). Skip: workflow automation (overkill for <500 data flows). Cheaper: Osano ($15-25k) for baseline compliance + audit prep. TrustArc $20-30k for best-practice templates. OneTrust = enterprise; Osano/TrustArc = growth-stage. Choose OneTrust if you have >100 SaaS integrations or multi-country footprint.
▶How much do privacy certifications actually matter for hiring?
CIPP/E is gold-standard in EU/UK (opens €95k+ roles, required for some DPO paths). CIPP/US weaker than CIPP/E but standard in US. CIPM (manager-level) + CIPT (technical) less common but valuable if you want to specialize. 60% of posted "Privacy Engineer" roles ask for at least one cert. Self-study via IAPP courses: 60-120 hours + $300-400 exam. Exam pass rate ~65%; study group recommended.
▶Free privacy tools to get started without OneTrust budget?
ICO (UK info commissioner) toolkit = free compliance templates + guidance. Osano free tier = basic policies + audit checklist. Transcend community edition = free DSAR automation for <10k users. Securiti.ai free console = AI Act readiness score (no actual deployment). GDPR cost starts at $0 (write your own processing agreements) but time cost = 200+ hours. If bootstrapped: ICO toolkit + Osano + homegrown spreadsheets. Cross into TrustArc ($20k) once you hit £1M revenue / 50k users.