For years, data privacy compliance was viewed by many organizations as a necessary hurdle—a "box-ticking" exercise managed by legal teams to avoid fines.