General Data Protection Regulation (GDPR)
Summary
The European Union’s comprehensive framework for personal data protection and privacy rights.
Overview
The General Data Protection Regulation (Regulation (EU) 2016/679) is the European Union’s landmark data protection framework, effective May 25, 2018. It applies to any organization processing personal data of data subjects in the EU, regardless of where the organization is based. The GDPR establishes principles for lawful processing: lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability.
Individual Rights
The GDPR grants data subjects extensive rights: the right to be informed about data collection, right of access, right to rectification, right to erasure (right to be forgotten), right to restrict processing, right to data portability, right to object, and rights related to automated decision-making. These rights give individuals significant control over their personal data. Organizations must respond to requests within one month and cannot charge fees except in limited circumstances.
Enforcement and Penalties
Supervisory authorities in each EU member state enforce the GDPR. The regulation establishes a tiered penalty system: up to €10 million or 2% of annual global turnover for certain violations, and up to €20 million or 4% of annual global turnover for the most serious violations. Major fines have been imposed on technology companies for violations including lack of lawful basis for processing, insufficient transparency, and inadequate security measures.