General Data Protection Regulation (EU) 2016/679 (GDPR) is a comprehensive regulation adopted by the European Union to govern the collection, processing, and protection of personal data of individuals within the EU and European Economic Area (EEA). Effective from 25 May 2018, GDPR strengthens the rights of data subjects and imposes significant obligations on data controllers and processors. It applies not only to entities established within the EU but also to non-EU organizations offering goods or services to, or monitoring the behavior of, individuals in the EU.
GDPR is structured around 7 fundamental principles of data processing:
Key Compliances Under GDPR
Penalties Under GDPR
GDPR provides for two tiers of administrative fines:
Supervisory authorities may also impose corrective actions such as warnings, reprimands, suspension of processing, or order to rectify/delete data.