O Oluma Cyber Security Framework Files · No. 08 Regulation · Data Protection GDPR Europe’s landmark privacy law — and the one that rewrote the global rulebook on how organizations everywhere handle personal data. In force May 2018 7 Principles Fines to 4% of turnover Global reach GDPR EU · personal data How we’ll read this 01 The Problem02 Why It Exists03 The Story04 How It Works05 Example06 Who Uses It07 Career08 Strengths & Challenges09 Takeaway 01 The Problem An old law, a borderless internet, and no real teeth Europe’s privacy rules dated back to 1995 — before social media, smartphones, or cloud computing. Worse, they were implemented differently in every member state, so a company faced a patchwork of conflicting rules, and regulators had little power to punish misuse. Meanwhile, personal data had become the fuel of the digital economy — collected, traded, and shared at a scale ordinary people couldn’t see or control. 02 Why It Was Created One strong law, real control for people GDPR replaced the patchwork with one harmonized regulation across the EU — and gave individuals genuine, enforceable rights over their personal data, backed by fines large enough to make the biggest companies pay attention. The core ideaPersonal data belongs to the person. Organizations may only use it with a lawful reason, for clear purposes, and must protect it — and people can demand to see, correct, or delete it. 03 The Story Behind It A four-year build, then a global ripple 1995The old DirectiveThe EU’s Data Protection Directive set early principles, but was applied unevenly and lacked enforcement muscle. 2012–2016Drafting & adoptionAfter years of negotiation, the EU adopted the General Data Protection Regulation in 2016, with a two-year runway. 25 May 2018Enforcement dayGDPR took effect across the EU and EEA — instantly the world’s most influential privacy law. SinceRecord fines & global copiesRegulators have issued penalties in the hundreds of millions to over a billion euros, and dozens of countries modeled new laws on it. 04 How It Works Principles, lawful bases, and rights At its heart are seven principles every use of personal data must satisfy: Lawfulness, fairness & transparencyPurpose limitationData minimizationAccuracyStorage limitationIntegrity & confidentialityAccountability To process data at all, you need one of six lawful bases (such as consent or contract). And individuals get powerful rights: to access their data, correct it, port it elsewhere, object — and the famous “right to be forgotten.” Serious breaches must be reported within 72 hours, and many organizations must appoint a Data Protection Officer and run impact assessments (DPIAs). 05 Real-World Example A US startup with European users A software startup in the US picks up customers in Germany and France. Even with no EU office, GDPR applies the moment it handles those residents’ data. What it has to get rightReach extends across the ocean Identify a lawful basis for every use of personal data Publish a clear, honest privacy notice Honor access and deletion requests from users Report any serious breach within 72 hours Put data-processing agreements in place with vendors That extraterritorial reach is exactly why GDPR reshaped privacy far beyond Europe. 06 Who Uses It Any organization touching EU data 🇪🇺EU/EEA organizationsEvery business and public body operating in the bloc. 🌍Global companiesAnyone, anywhere, processing EU/EEA residents’ data. ⚖️RegulatorsNational Data Protection Authorities, coordinated by the EDPB. Its influence is global — it became the template for privacy laws worldwide, from Brazil’s LGPD to California’s CCPA. inspired LGPDCCPAenforced by DPAs / EDPB 07 Career Relevance The cornerstone of privacy work GDPR effectively created the modern privacy profession. Data Protection Officers, privacy analysts, and GRC specialists all build on its concepts — lawful basis, data subject rights, DPIAs. Because so many laws now echo it, learning GDPR gives you a mental model that transfers to privacy regimes across the globe — a high-value, future-proof skill. 08 Strengths & Challenges Honest trade-offs ✦ StrengthsStrong, enforceable individual rightsHarmonized across the EU/EEAReal penalties that drive complianceThe global template for privacy law ⚠ ChallengesComplex and resource-intensive to implementInterpretation varies between regulatorsCross-border data transfers are a minefieldHeavy documentation and accountability burden 09 Final Takeaway GDPR rewrote the global rulebook on personal data.It turned privacy from a footnote into a board-level concern and gave ordinary people real control over their information. Learn its principles and rights, and you’ve learned the language that privacy laws around the world now speak.