The EU has now reached political agreement on the General Data Protection Regulation; formal adoption is expected in early 2016 and the Regulation should come into force in 2018.
This is the biggest shake-up to privacy regulation in 20 years. Whilst the core principles of the law remain broadly the same, there are a number of significant changes. It will:
• apply to companies such as Google Inc. or Wikipedia that are based outside the EU but deal with EU citizens;
• impose new obligations to notify regulators and individuals of serious data breaches; and
• grant individuals new rights such as the right to be forgotten and the right to data portability.
These more prescriptive requirements will be backed by a step change in sanctions. The most serious breaches will be punishable with fines of up to 4% of annual worldwide turnover.
Olivier Reisch, Counsel, Litigation/IP TMT at Linklaters LLP said ”The regulation with new rights such as the right to be forgotten or the right to data portability and a whole new range of significant sanctions will put data protection on board level agendas of many businesses dealing with EU citizens, including those based outside the EU”.