The European Parliament adopted GDPR in April 2016, replacing a data protection directive approved in 1995. The new law carries requires businesses to protect the personal data and privacy of EU citizens for all data transactions. The GDPR also regulates the export of personal data outside the EU zone.
It applies to any organization that collects and processes data of EU citizens, even if the processing is done outside of the EU. GDPR classifies organization as ‘controllers’ or ‘processors.’
Article 83(5) of GDPR, DPAs would be able to impose fines of up to €20M or 4% of the offending company’s total worldwide annual turnover of the preceding financial year, whichever is higher.
Developing a framework to ensure your organization is complaint with GDPR is a must. Like many large-scale initiatives, go with a phased approach.