Agile development and Privacy by design

A year ago, I talked to some people in a web-project that was run in an agile fashion. One of my questions was how they managed requirements related to the upcoming GDPR regulations. The answer was that we put them in the backlog. Formally correct from an agile perspective, I don’t think it’s the right approach for regulatory requirements.