General Data Protection Regulation: Key Requirements (2018)

McDermott Will & Schulte, a global law firm

ARTICLE / REPORT

The General Data Protection Regulation: Key Requirements and Compliance Steps for 2018

January 2018

Read time: 2 min

Overview

Enforceable in all EU member states on 25 May 2018, the General Data Privacy Regulation will require action by organisations both inside and outside the European Union to ensure compliance with this far-reaching privacy legal framework. Compliance is even more urgent given that the GDPR provides for large penalties in cases of infringement. As some entities are not yet aware of the extent to which GDPR may be applicable to them, the GDPR expressly applies to organisations established outside the European Union that offer paid or free goods or services to EU data subjects or monitor EU data subjects’ behaviour. Within this article, we review steps for a risk based, prioritization approach to GDPR compliance and how companies can adjust their policies and practices on a pragmatic basis to help ensure compliance.

This Special Report includes contributions from Leon C.G. Liu and Jared T. Nelson from MWE China Law Offices.

Sabine Naugès

Partner

Paris

Mark E. Schreiber

Counsel

Boston

Michael G. Morgan

Partner

Los Angeles, Silicon Valley

More Insights