The General Data Protection Regulation (GDPR), which came into effect on May 25, 2018, introduced several significant changes compared to previous data protection regulations, such as the 1995 Data Protection Directive. Key changes include:
Extended Territorial Scope: GDPR applies to all companies processing the personal data of individuals residing in the EU, regardless of the company’s location. This extraterritorial applicability ensures that non-EU businesses are also subject to GDPR if they offer goods or services to, or monitor the behavior of, EU residents.
Stronger Consent Requirements: Consent must be freely given, specific, informed, and unambiguous. Pre-ticked boxes and implied consent are no longer acceptable. Businesses must provide clear and plain language explanations of how personal data will be used.
Enhanced Data Subject Rights: GDPR grants individuals more control over their personal data, including the right to access, rectification, erasure (the right to be forgotten), data portability, and the right to object to processing.
Accountability and Compliance: Organizations must demonstrate compliance with GDPR principles. This includes maintaining records of data processing activities, conducting data protection impact assessments (DPIAs), and implementing data protection by design and by default.
Breach Notification: GDPR mandates that data breaches likely to result in a risk to individuals’ rights and freedoms must be reported to the relevant supervisory authority within 72 hours of becoming aware of the breach. Affected individuals must also be informed without undue delay.
Increased Penalties: Non-compliance can result in significant fines. Penalties can reach up to €20 million or 4% of the company’s global annual turnover, whichever is higher.
Data Protection Officers (DPOs): Organizations engaged in large-scale monitoring or processing of sensitive data must appoint a DPO to oversee GDPR compliance and act as a point of contact for supervisory authorities and data subjects.