General Data Protection Regulation(GDPR)
Definition
The European Union's data-protection law, effective 2018, governing how organizations collect, process, and store EU residents' personal data.In-Depth Explanation
GDPR took effect on 25 May 2018 and applies to any organization worldwide that handles the data of EU residents. It rests on principles such as lawfulness, purpose limitation, data minimization, and accountability, and grants individuals rights to access, erase, and port their data. Controllers must report breaches within 72 hours, and vendors typically provide a Data Processing Agreement (DPA). Fines reach up to 20 million euros or 4% of global annual revenue, whichever is higher.
Real-World Example
An AI tool serving EU users publishes a DPA and lets users request deletion of their data to comply with GDPR.