info@nexoprivacy.com +254 768200243 Mon - Sat | 24 Hours
Home Policies General Data Protection Regulation (GDPR)
Europe · European Union

General Data Protection Regulation (GDPR)

The cornerstone of modern data protection - governs how organisations collect, process and protect personal data of EU residents, anywhere in the world.

Quick facts

  • Code: GDPR
  • Jurisdiction: European Union
  • Region: Europe
  • Enforcement:
    Fines up to Ôé¼20M or 4% of global annual turnover
  • Official source

The General Data Protection Regulation (Regulation (EU) 2016/679) is the most influential privacy law in the world. It applies to any organisation that offers goods or services to people in the EU, or monitors their behaviour, regardless of where the organisation is based.

NexoPrivacy operationalises the GDPR through readiness assessments, Records of Processing Activities (RoPA), DPIAs, vendor due diligence, cross-border transfer mechanisms (SCCs, BCRs, TIAs) and a programme of continuous monitoring.


Key principles & obligations

Lawfulness, fairness & transparency
Purpose limitation
Data minimisation
Accuracy
Storage limitation
Integrity & confidentiality
Accountability
More in Europe

Related frameworks.

United Kingdom

UK GDPR & Data Protection Act 2018

The UK's post-Brexit data protection regime - closely mirrors the EU GDPR with UK-specific nuances.

Read summary