I want to start with a comment about the opening statement. "GDPR ... applies to every organization doing business with EU residents." ... I want to challenge that premise. Unless a foreign nation has a treaty on this topic, nothing the EU wants to do is binding on non-EU nations... unless you accept the premise that the EU now has authority over the sovereign laws of other countries. Having said that, SbD and PbD are all good things... I just object to the fact that the EU think they rule see more the world...