JDMurray wrote: » Under Required Skills is "Working knowledge of EU Data Privacy laws, specifically impact of GDPR rollout." That is a requirement most InfoSec people would currently not have. Just when I think that I have the GDPR responsibilities nailed down from an IT InfoSec role viewpoint I discover something else new to me. This all reminds me of the start of both SOX and HIPAA when we were trying to determine what is really required from complying organizations versus what the lawyers are interpreting from the official documents, and how do we keep from being financially penalized is we make a mistake? IT people with a detailed understanding of GDPR is the next thing that will be in hot demand--if not already.