The European Union’s General Data Protection Regulation (GDPR) changed global data privacy compliance. Effective since May 2018, the regulation applies to any organization worldwide that processes the personal data of individuals inside the EU.
Core Principles of Data Protection
The GDPR requires data processing systems to build their technical controls around seven core principles:
- Lawfulness, Fairness, and Transparency: Personal data must be processed legally, fairly, and with full transparency toward the individual.
- Purpose Limitation: Data can only be collected for specified, explicit, and legitimate purposes. It cannot be used for unrelated secondary tasks.
- Data Minimization: Organizations can only collect and process the minimum amount of data necessary to achieve the stated purpose.
- Accuracy: Systems must maintain accurate data and ensure incorrect records are updated or deleted without delay.
- Storage Limitation: Personal data must be deleted or anonymized once it is no longer needed for the processing purpose.
- Integrity and Confidentiality: Organizations must use appropriate technical and organizational measures (such as encryption and access controls) to protect data from unauthorized access or accidental loss.
- Accountability: The organization must document and prove its compliance with all six preceding principles during regulatory audits.
The Two Tiers of Statutory Fines
+---------------------------------+
| GDPR Penalty Framework |
+---------------------------------+
|
+----------------------------+----------------------------+
| |
+--------------------------------+ +--------------------------------+
| Tier 1: General Breaches | | Tier 2: Core Violations |
| - Broken record keeping | | - Privacy principle breaches |
| - Missing processor contracts | | - Violating data subject rights|
| - Up to 2% global turnover | | - Up to 4% global turnover |
+--------------------------------+ +--------------------------------+
Â