Standards & Compliance

GDPR (General Data Protection Regulation)

European regulation on personal data protection

GDPR (General Data Protection Regulation) is a European Union regulation on personal data protection that came into force on May 25, 2018. It applies to all organizations processing EU citizens' data.

Key Data Subject Rights

  • Right of access — obtain a copy of your data
  • Right to rectification — correct inaccurate data
  • Right to erasure — "right to be forgotten"
  • Right to portability — receive data in machine-readable format
  • Right to object — refuse processing
  • Right not to be subject to automated decisions

Organization Obligations

  • Appoint DPO (Data Protection Officer)
  • Notify breaches within 72 hours
  • Conduct DPIA (impact assessment)
  • Privacy by Design and Privacy by Default
  • Maintain processing records

Fines

  • Up to 20 million euros
  • Or up to 4% of annual turnover
  • Whichever is greater

External Links

Category

ISO 27001, PCI DSS, GDPR, SOC 2, regulatory requirements