EU regulation governing the protection of personal data and privacy rights of individuals.
The General Data Protection Regulation (GDPR) is EU legislation establishing rules for collecting, processing, and storing personal data. Key requirements include lawful basis for processing, data minimisation, individual rights (access, erasure, portability), breach notification within 72 hours, and privacy by design. GDPR applies to organisations processing EU residents' data, regardless of where the organisation is based. Maximum fines are €20 million or 4% of global annual turnover.
Why It Matters
The DSC Perspective:
GDPR applies to any organisation handling EU personal data. Non-compliance carries significant penalties. Beyond compliance, GDPR requirements often represent good data protection practice.
