Standards & Compliance
GDPR (General Data Protection Regulation)
European regulation on personal data protection
GDPR (General Data Protection Regulation) is a European Union regulation on personal data protection that came into force on May 25, 2018. It applies to all organizations processing EU citizens' data.
Key Data Subject Rights
- Right of access — obtain a copy of your data
- Right to rectification — correct inaccurate data
- Right to erasure — "right to be forgotten"
- Right to portability — receive data in machine-readable format
- Right to object — refuse processing
- Right not to be subject to automated decisions
Organization Obligations
- Appoint DPO (Data Protection Officer)
- Notify breaches within 72 hours
- Conduct DPIA (impact assessment)
- Privacy by Design and Privacy by Default
- Maintain processing records
Fines
- Up to 20 million euros
- Or up to 4% of annual turnover
- Whichever is greater
External Links
Category
ISO 27001, PCI DSS, GDPR, SOC 2, regulatory requirements