What is the General Data Protection Regulation (GDPR)?

The General Data Protection Regulation (GDPR) is a comprehensive data protection law enacted by the European Union (EU).

What is the General Data Protection Regulation (GDPR)
What is the General Data Protection Regulation (GDPR)

What is the General Data Protection Regulation (GDPR)?

The General Data Protection Regulation (GDPR), which entered into force on May 25, 2018, is a comprehensive data privacy law that establishes a framework for the collection, processing, storage, and transfer of personal data. It requires all personal data to be processed in a secure manner, and includes fines and penalties for companies that do not comply with these requirements. It also provides individuals with a number of rights relating to their personal data.

 

With technological advances and the increasing prevalence of data collection, data privacy has come into the spotlight. At the time of its passage, the GDPR was the most comprehensive data privacy regulation in existence. It harmonized the separate data protection regulations from across the EU. It also expanded the scope of these regulations to apply to non-EU organizations if they process personal data collected in the EU.

The GDPR applies to any company or organization regardless of geographic location if the company or organization offers goods and services to people in the EU or monitors their behavior within the EU.

 

How does the GDPR define “personal data”?

The GDPR expanded what was considered personal data to include any information relating to an identifiable natural person. This includes clearly personal details, such as a person's name and address, and also any other information that can be used to identify a person, including their IP address and specific cookie identifiers associated with a web browsing session.

 

What are the GDPR requirements for data controllers and data processors?

The GDPR defines data controllers as entities that make decisions about the means and purposes for which personal data is collected and processed, and defines data processors as entities that process personal data, typically on behalf of the data controller.

The GDPR also identifies seven core principles for how data controllers and processors should handle personal data:

  • Lawfulness, fairness, and transparency
  • Purpose limitation
  • Data minimization
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality (security)
  • Accountability

Therefore:

In addition to describing these principles in detail, the GDPR requires a number of specific actions that data controllers and processors need to take. Some of these include:

  • Record-keeping: Data processors must maintain records of their processing activities.
  • Security measures: Data controllers and processors must regularly use and test appropriate security measures to protect the data they collect and process.
  • Data breach notification: Data controllers who experience a breach of personal data must notify the relevant authorities within 72 hours, with some exceptions. Typically, they must also notify the individuals whose personal data was affected by the breach.
  • Data Protection Officer (DPO): Companies that process data may need to appoint a Data Protection Officer (DPO). The DPO leads and oversees all GDPR compliance efforts.

 

The full requirements for controllers and processors are outlined in the GDPR regulation.

What rights do data subjects have under the GDPR?

The GDPR defines a data subject as an “identified or identifiable natural person.” Data subjects have the following rights:

  • The right to be informed: Data subjects must be given easy-to-understand information about how their personal data is collected and processed
  • The right to data portability: Data subjects can transfer their data from one data controller to another
  • The right of access: Data subjects are entitled to obtain a copy of the personal data that has been collected
  • The right to rectification: Data subjects can correct inaccurate data about themselves
  • The right to erasure: Data subjects can request deletion of their data (also known as the right to be forgotten)
  • The right to restriction of processing: Under certain circumstances, data subjects can restrict the way their personal data is processed
  • The right to object: Data subjects have the right to object to the processing of their personal data, and under certain circumstances, the data controller or processor will be obligated to comply with the data subject's objection
  • The right to object to automated processing: Data subjects can object to a decision that legally affects them and is based solely on automated data processing

 

What are the penalties for violating the GDPR?

The GDPR describes the fines that will be imposed on companies that violate its policies.

There are two levels of fines under the GDPR, with each level corresponding to a different category of violations:

  • Tier 1: The violation results in a maximum fine of €10 million or 2% of the company's worldwide annual revenue, whichever is higher.
  • Tier 2: The violation results in a maximum fine of €20 million or 4% of the company's worldwide annual revenue, whichever is higher.

In addition to these fines, data subjects can claim compensation for damages when a company violates the GDPR.