The EU General Data Protection Regulation (GDPR)
What is the GDPR?
The EU GDPR (General Data Protection Regulation) is a pan-European data protection law, which superseded the EU’s 1995 Data Protection Directive and all member state law based on it, including the UK’s DPA 1998 (Data Protection Act 1998), on 25 May 2018.
The EU GDPR extends the data rights of individuals (data subjects) and places a range of new obligations on organisations that process EU residents’ personal data.
The UK DPA (Data Protection Act) 2018 modifies the EU GDPR by filling in the sections of the Regulation that were left to individual member states to interpret and implement.
It also applies a “broadly equivalent regime” – known as “the applied GDPR” – to certain types of processing that are outside the EU GDPR’s scope, including processing by public authorities, and sets out data processing regimes for law enforcement processing and intelligence processes.
The EU GDPR and DPA 2018 should therefore be read together.
Find out more about the DPA 2018 >>
The GDPR will be enacted in UK law after Brexit under section 3 of the European Union (Withdrawal) Act 2018.
Help with every stage of your GDPR compliance journey
For many organisations, achieving EU GDPR compliance is a long and complicated journey.
If your organisation is not fully compliant with the law yet, you should prioritise addressing those areas where a lack of action leaves you exposed. Where an infringement occurs, demonstrating you have made a start should help reduce potential EU GDPR fines and penalties.
We are here to help
Whatever stage of your compliance journey you are at, IT Governance can help you. Speak to one of our experts today to find out how your organisation can become GDPR compliant.
Speak to an expert
EU GDPR summary video
When the EU GDPR came into effect on 25 May 2018, it was the first major update to European data protection law for over 20 years. The Regulation gives individuals (known as data subjects) much greater control over how organisations process their personal data.
Watch our 7-minute video for a comprehensive overview of the EU GDPR.
Who does the GDPR apply to?
- All EU organisations that collect, store or otherwise process the personal data of individuals residing in the EU, even if they’re not EU citizens.
- Organisations based outside the EU that offer goods or services to EU residents, monitor their behaviour, or process their personal data.
Find out how your organisation can start its journey to becoming GDPR-compliant today >>
Click to expand some key changed introduced by the Regulation:
- Public authorities;
- Organisations involved in high-risk processing; and
- Organisations processing special categories of data.
A DPO has set tasks:
- Inform and advise the organisation of its obligations.
- Monitor compliance, including awareness raising, staff training and audits.
- Cooperate with data protection authorities and act as a contact point.
Find out more about the DPO role under the EU GDPR >>
Find out more about the key changes introduced by the EU GDPR and how you can comply by downloading our free green paper >>
What is personal data?
Personal data is any information relating to an identified or identifiable natural person (data subject). The Regulation places much stronger controls on the processing of special categories of personal data than the DPA 1998 did. The inclusion of genetic and biometric data is new.
- Email address
- IP address
- Location data
- Online behaviour (cookies)
- Profiling and analytics data
Special categories of personal data
- Political opinions
- Trade union membership
- Sexual orientation
- Health information
- Biometric data
- Genetic data
How will Brexit affect the GDPR?
The GDPR, like all EU regulations, applies directly in the UK with all the authority of a domestic law.
When the UK leaves the EU, the EU GDPR will no longer directly apply. However, its requirements will still be part of UK law.
Find out what will happen to data protection law in the UK after Brexit >>
Find out how your organisation can start its journey to becoming EU GDPR compliant today >>
The benefits of the GDPR
There are great advantages to EU GDPR compliance. The new law promotes greater transparency and accountability and aims to increase public trust by giving individuals more control over their data. By getting data protection right, organisations will enhance their reputation, and build better, trusted relationships with existing and potential customers.
The business benefits of the EU GDPR include:
- Build customer trust
- Improve brand image and reputation
- Improve data governance
- Improve information security
- Improve competitive advantage
Start your journey to EU GDPR compliance today >
How IT Governance can help you comply with the EU GDPR
IT Governance, a leading global provider of IT governance, risk management and compliance solutions, is at the forefront of helping organisations globally address the challenges of EU GDPR compliance.
Browse our wide range of products that can help you meet your EU GDPR compliance objectives.
Speak to a GDPR expert
If you’re looking for help with your EU GDPR project, get in touch with our experts, who can advise you on which of our products and services are best suited to your needs.