[LT-03]
The Enforcement Reality
The European Data Protection Board and national supervisory authorities evaluate GDPR compliance based on outcomes, not effort. An organization that used a PII detection tool in good faith, but whose tool systematically missed French, German, and Polish national identifiers, has still failed to implement "appropriate technical measures" under GDPR Article 32.
The "we used a tool" defense does not satisfy the standard when the tool demonstrably cannot detect the pers...