Mr Dunn makes some good points, but the problem is like all of us he has a big hammer (the law) so thinks every problem is a nail.

If you think about this carefully, it's just as bad as the two-decade status quo: boards thinking data protection is an IT security problem because "data" means IT and "protection" means security. Which, in a way, is why the GDPR had to be invented.

The issues are too big for a mere comment. I think I should blog on this and the arguably required technology-neutral solutions and, most of all, methodology. If so, I'll come back here with a link...

