GDPR resources

GDPR data protection legislation went into effect in May 2018. Are you compliant?

Answers to key GDPR questions

GDPR is a regulation by which the European Parliament, the Council of the European Union and the European Commission strengthened and unified data protection for EU residents. This legal framework replaced the EU Data Protection Directive (95/46/EC) with additional requirements that you need to be aware of. The EU data protection regime extends the scope of the EU data protection law to all companies even outside the EU when they process data of EU residents.

GDPR makes no distinction between B2B (business-to-business) and B2C (business-to-consumer) interactions and applies to both of them.

GDPR has officially applied since 25th May 2018 and companies or organizations in non-compliance may be subject to fines.

GDPR applies to persons and entities of all sizes that process personal data of EU residents, regardless of where they are based. These regulations apply to both data controllers and data processors, including third parties such as cloud providers.

It applies to all 27 EU member states and to entities and organizations outside the EU when processing the data of citizens within it.

No. Brexit did not change the GDPR itself. Now that the UK has left the EU, it has its own regime where data protection is governed by the UK GDPR and the Data Protection Act 2018.

The maximum penalty for organizations in non-compliance with GDPR can be up to €20 million or 4% of annual global turnover, whichever is greater. There is a tiered approach to fines e.g. a company can be fined 2% for not having their records in order (article 28), not notifying the supervising authority and data subject about a breach or not conducting impact assessment.