GDPR (General Data Protection Regulation)
The GDPR (General Data Protection Regulation) is the EU-wide regulation in force since May 2018 that governs how personal data is handled, obliging companies among other things to be transparent, to minimise data, to have a legal basis for each processing activity and to keep data appropriately secure.
In practice
For websites the GDPR touches practically every area involving personal data: contact forms, tracking, newsletter sign-ups or server logs. The fines come in two tiers. Article 83(4) GDPR goes up to €10 million or 2 per cent of worldwide annual turnover, Article 83(5) up to €20 million or 4 per cent, whichever amount is higher. The higher tier covers breaches of the principles, the legal basis and data subject rights; the lower one covers security, notification and documentation duties.