General Data Protection Regulation (GDPR)

ˈdʒɛnərəl ˈdeɪtə prəˈtɛkʃən ˌrɛɡjʊˈleɪʃən

The General Data Protection Regulation (GDPR) is a comprehensive data protection law enacted by the European Union in May 2018. It aims to give individuals greater control over their personal data and to simplify the regulatory environment for international business by unifying data protection regulations across the EU. The GDPR outlines specific rights for individuals, such as the right to access, rectify, and erase their personal data. It also imposes strict obligations on organizations regarding data processing, requiring them to implement adequate security measures and report data breaches promptly. Non-compliance can result in substantial fines, making GDPR a critical consideration for businesses handling personal data.