GDPR and the “Brussels effect” in privacy
Europe passed a privacy regime with strong disclosure and breach notification rules. Global companies often chose worldwide compliance rather than running separate systems by geography.
Companies rewired privacy operations, contracts, and incident response for GDPR timelines.
Privacy expectations shifted globally, even in places without identical laws.
New York and California are trying to create an American version of that compliance gravity.
