The European regulation governing personal data processing, with fines of up to 4 percent of worldwide turnover.
The General Data Protection Regulation, applicable since May 2018, is the European reference framework for the processing of personal data. It imposes on organizations that collect or process such data a set of principles, lawfulness, minimization, purpose limitation, security, together with rights for data subjects, access, rectification, erasure, portability. It also provides for an obligation to notify data breaches to the supervisory authority, generally within seventy-two hours, and where appropriate to the affected individuals. Fines can reach 20 million euros or 4 percent of annual worldwide turnover, whichever is higher, which makes it a first-order financial risk. For cyber insurance, the GDPR is central, because a data breach triggers at once notification costs, crisis-management expenses, a risk of administrative fine and exposure to liability claims. The question of whether the administrative fines themselves are insurable remains legally debated and varies by country, some jurisdictions holding that insuring a punitive sanction would be contrary to public policy.
Following a breach exposing the data of millions of customers, a company must notify the supervisory authority within seventy-two hours, inform the affected individuals and provision for the risk of a fine of up to 4 percent of its worldwide turnover.
RGPD, GDPR, règlement général sur la protection des données