GDPR

The General Data Protection Regulation (GDPR) is a European Union law that governs how organizations collect, process, and protect the personal data of individuals in the EU. It was adopted in 2016 and took effect on 25 May 2018, replacing the older 1995 Data Protection Directive. It gives people stronger control over their data and places strict, provable obligations on the organizations that handle it.

What is GDPR?

The General Data Protection Regulation (GDPR) is a European Union law that governs how organizations collect, process, and protect the personal data of individuals in the EU. It was adopted in 2016 and took effect on 25 May 2018, replacing the older 1995 Data Protection Directive. It gives people stronger control over their data and places strict, provable obligations on the organizations that handle it.

Who does GDPR apply to?

  • Anyone handling EU data: It applies to any organization that processes the personal data of people in the EU, regardless of where the organization is based.
  • Extraterritorial reach: A company with no EU office still falls under GDPR if it offers goods or services to EU individuals or monitors their behavior, such as tracking EU website visitors for analytics.
  • Controllers and processors: It covers both the organization deciding why data is processed (the controller) and any third party processing it on their behalf (the processor).

What are the core principles?

GDPR is built on seven principles in Article 5, including:

  • Lawfulness, fairness, and transparency: Processing must have a valid legal basis and be clear to the individual.
  • Purpose limitation: Data is collected for specified, legitimate purposes.
  • Data minimization: Only the data actually needed is collected.
  • Accuracy and storage limitation: Data is kept correct and not held longer than necessary.
  • Integrity, confidentiality, and accountability: Data is kept secure, and the organization must be able to prove compliance.

What rights does it give individuals?

  • Access and portability: People can see their data and request a portable copy.
  • Rectification and erasure: They can have inaccurate data corrected and, in some cases, deleted (the “right to be forgotten”).
  • Objection: They can object to certain processing, including profiling.
  • Consent: Where consent is the basis, it must be freely given, specific, informed, and unambiguous.

What are the obligations and penalties?

  • Breach notification: Controllers must report qualifying breaches to authorities within 72 hours.
  • DPO and DPIA: Some organizations must appoint a Data Protection Officer and run Data Protection Impact Assessments for high-risk processing.
  • Heavy fines: Violations can cost up to 20 million euros or 4 percent of global annual turnover, whichever is higher.

Why does GDPR matter?

  • A global benchmark: It set a worldwide precedent and influenced laws like Brazil’s LGPD and privacy rules in U.S. states.
  • Trust and reputation: Beyond avoiding fines, strong compliance builds customer trust, while public enforcement actions can do lasting reputational damage.