The General Data Protection Regulation (GDPR) is the European Union’s (EU) data privacy and security law. The EU put GDPR into effect on May 25, 2018. The law was designed to give European citizens and residents more control over how their personal data is collected, used and protected online.
GDPR applies to any organization (large or small) that handles data belonging to EU citizens and residents, regardless of where the organization is located.¹ Under GDPR, a personal data breach is any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.