What is GDPR
European data protection regulation
GDPR (General Data Protection Regulation) is a European Union regulation on personal data protection that came into effect on May 25, 2018.
Core Principles
- Lawfulness and transparency — processing only with consent
- Purpose limitation — data only for stated purposes
- Data minimization — collect only what is necessary
- Accuracy — maintain data accuracy
- Storage limitation — delete after purpose is achieved
- Integrity and confidentiality — protect from unauthorized access
Data Subject Rights
- Right of access to personal data
- Right to rectification
- Right to erasure (right to be forgotten)
- Right to restriction of processing
- Right to data portability
- Right to object
Penalties
- Up to 20 million euros or 4% of annual turnover for serious violations
- Up to 10 million euros or 2% of turnover for less serious violations
Applicability
GDPR applies to all companies processing EU residents' data, regardless of company location.