Red teaming for privacy
Since the introduction of the European General Data Protection Regulation (GDPR), most organizations have started treating privacy violations more seriously. The reason for this appears to be the enormous fines that are applicable when violating these privacy regulations. Imposed fines can be as a high as 4% of the annual turnover of the organization. This basically has the potential to significantly impact the bottom lines of organizations, including very large ones.
There are a couple of interesting sections in the regulation. It's worthwhile reading the entire document too. It can be found at https://eur-lex.europa.eu/legal-content/EN/TXT/?qid=1528874672298&uri=CELEX%3A32016R0679.
Article 32 does indeed highlight the requirement and necessity to test regularly as it states the following: