Overview
The GDPR, formally known as Regulation (EU) 2016/679, establishes strict guidelines for the collection, processing, storage, and transfer of personal data. It emphasizes transparency, accountability, and the rights of data subjects, including rights to access, rectification, and erasure of data ('right to be forgotten'). Key principles include data protection by design, explicit consent for data processing, and mandatory reporting of data breaches. The regulation also introduces significant penalties for non-compliance and applies to organizations globally that process data of EU residents. The GDPR became effective on May 25, 2018, replacing Directive 95/46/EC.