The General Data Protection Regulation (GDPR) is a comprehensive data privacy law enacted in the EU, designed to enhance individuals' control over their personal data.
1. Consent: Organizations must obtain clear consent to process personal data.
2. Data Subject Rights: Individuals have rights to access, rectify, and erase their data.
3. Data Breach Notification: Companies are required to notify authorities and affected individuals of data breaches within 72 hours.
Failure to comply with GDPR can result in severe penalties, emphasizing the importance of robust data protection measures to avoid risks.