Data protection regulation
European data protection for the digital era
Better protection for personal data
- Clear consent required to process data
- Limits on the use of automated processing of data to make decisions, for example in the case of ‘profiling’
- Right to rectify and remove data, including the ‘right to be forgotten’ for data collected as a child
- Right to notification if data is compromised
- More and clearer information about processing
- Right to move data from one service provider to another
- Easier access to personal data
- Stricter safeguards for transfers of personal data outside the EU
More opportunities for business
- Level playing field for all EU and non-EU businesses offering goods and services to persons in the EU
- One set of rules for the whole EU
- Rules that allow businesses, especially SMEs, to get the most out of the Digital Single Market
- Risk-based approach, matching obligations of controllers to the level of risk of the processing
More consistent application and effective enforcement
- Individuals and businesses can have their cases dealt with by a data protection authority and a court close to them
- A one-stop shop for individuals and businesses in cross-border cases thanks to the cooperation of national data protection authorities
Fines
- up to €20 million or
- 4% of global annual turnover
The data protection regulation sets out the rights of the individuals and establishes the obligations of those processing and those responsible for the processing of the data.
For more information, visit the following page: