When GDPR became a law recently, it became the most wide-ranging and stringent data protection initiative in history. In preparation for this change and to ensure compliance, IBM, along with most organizations updated their services and information security policies. However applications themselves arguably pose the biggest threat of data breaches and non-compliance with GDPR.In this session, we first review the main tenants of GDPR. We will then describe how GDPR affected IBM Cloud services, what changes and decisions had to be made, how the DevOps and SRE processes were updated. Finally we describe best practices for customer applications to build in data protection from design and achieve GDPR compliance.