The General Data Protection Regulation (GDPR) is a regulation enacted by the European Union (EU) to protect the privacy and personal data of individuals within the EU and European Economic Area (EEA). Implemented on May 25, 2018, the GDPR is one of the most stringent data protection regulations in the world, setting a high standard for how companies must handle personal data.
The GDPR gives individuals greater control over their personal information by ensuring transparency, consent, and accountability from organizations that collect or process personal data. Key provisions include the right to access, the right to rectify, the right to erasure (the “right to be forgotten”), and the right to data portability, among others.
For businesses, GDPR compliance involves ensuring that personal data is collected legally, stored securely, and processed in a transparent manner. Companies must also implement strict data protection measures and notify individuals and authorities of any data breaches within 72 hours.
Failure to comply with the GDPR can result in substantial fines, up to 4% of a company’s global annual revenue or €20 million (whichever is greater). The regulation has had a global impact, influencing data privacy laws in many other countries.