GDPR

The GDPR (General Data Protection Regulation) is the European Union’s data-protection law, in force since May 2018. It governs how organizations anywhere in the world collect, use and store personal data about people in the EU and EEA.

Also called: General Data Protection Regulation, EU GDPR, UK GDPR

The regulation applies to any organization processing personal data of people in the EU, whether or not the organization is based there. Personal data means anything relating to an identifiable person; a voice recording, a phone number and a call transcript all qualify. Processing needs one of six lawful bases, consent, contract, legal obligation, vital interests, public task or legitimate interests, and must respect principles of purpose limitation, data minimization, accuracy, storage limitation and security.

It distinguishes controllers, who decide why and how data is processed, from processors, who act on a controller’s instructions; a processor must be bound by a written data-processing agreement (Article 28) that mirrors the role of HIPAA’s business associate agreement. People have rights of access, correction, erasure and objection, and breaches must be reported to the supervisory authority within 72 hours where they pose a risk. Fines can reach €20 million or 4% of worldwide annual turnover, whichever is higher.

The United Kingdom kept the regulation as “UK GDPR” after leaving the EU. A US business with no EU customers is generally outside its scope, but one that handles calls from Europe is not.