Skip to content

Questions about General Data Protection Regulation

Short answers, pulled from the story.

When did the GDPR come into effect?

The GDPR became directly applicable in all EU member states on the 25th of May 2018, two years after it entered into force on the 24th of May 2016. It was adopted by the European Parliament on the 14th of April 2016 and extended to EEA countries Iceland, Liechtenstein, and Norway on the 20th of July 2018.

What is the maximum fine under GDPR?

The most serious GDPR violations can result in fines of up to €20 million or up to 4% of annual worldwide turnover of the preceding financial year, whichever is greater. Less severe breaches carry fines of up to €10 million or 2% of annual worldwide turnover.

What rights does GDPR give individuals over their personal data?

The GDPR gives individuals the right to access their personal data (Article 15), the right to have inaccurate data corrected, the right to erasure under certain conditions (Article 17), the right to data portability between electronic systems (Article 20), and the right to object to processing for marketing purposes (Article 21). Individuals also have the right to compensation for material or non-material damage caused by a GDPR breach, under Article 82.

Does GDPR apply to companies outside the European Union?

Yes. Article 3(2) extends the GDPR to any organisation outside the EEA that offers goods or services to individuals located within the EEA, or that monitors their behaviour, regardless of where processing takes place. Such organisations must also designate an EU Representative under Article 27, and failure to do so is itself a violation subject to fines.

How has GDPR influenced privacy laws in other countries?

The GDPR has been cited as a model for laws in Brazil, Japan, Singapore, South Africa, South Korea, Sri Lanka, Thailand, and Turkey. In the United States, California's Consumer Privacy Act (adopted the 28th of June 2018), Virginia's Consumer Data Privacy Act (the 2nd of March 2021), and Colorado's Privacy Act (the 8th of July 2021) all draw on similar principles. China's 2021 Personal Information Protection Law was also modelled on the GDPR framework.

What is a GDPR data protection officer and who is required to appoint one?

A data protection officer (DPO) is a person with expert knowledge of data protection law and practices, responsible for monitoring an organisation's internal compliance with the GDPR. Under Article 37, a DPO must be appointed by public authorities, organisations that carry out large-scale regular or systematic monitoring of individuals, and organisations that process large volumes of special categories of data. The DPO's contact details must be published and registered with the supervisory authority.