Back to glossaryLaw & regulation

GDPR (General Data Protection Regulation)

The European regulation governing personal data processing, with fines of up to 4 percent of worldwide turnover.

Definition

The General Data Protection Regulation, applicable since May 2018, is the European reference framework for the processing of personal data. It imposes on organizations that collect or process such data a set of principles, lawfulness, minimization, purpose limitation, security, together with rights for data subjects, access, rectification, erasure, portability. It also provides for an obligation to notify data breaches to the supervisory authority, generally within seventy-two hours, and where appropriate to the affected individuals. Fines can reach 20 million euros or 4 percent of annual worldwide turnover, whichever is higher, which makes it a first-order financial risk. For cyber insurance, the GDPR is central, because a data breach triggers at once notification costs, crisis-management expenses, a risk of administrative fine and exposure to liability claims. The question of whether the administrative fines themselves are insurable remains legally debated and varies by country, some jurisdictions holding that insuring a punitive sanction would be contrary to public policy.

Example

Following a breach exposing the data of millions of customers, a company must notify the supervisory authority within seventy-two hours, inform the affected individuals and provision for the risk of a fine of up to 4 percent of its worldwide turnover.

Related terms
Also known as

RGPD, GDPR, règlement général sur la protection des données