This chapter presents the General Data Protection Regulation (GDPR) approved for the European Union, which has consequences not only for all the stakeholders of the information technology industry, but also for all of those engaged in industrial or commercial activities in the European Union.
The concepts and principles of the GDPR are presented and discussed as well as the implications of this regulation in data protection and in organisational cyber security practices. The financial implications for companies are discussed and an overview of the history of recent fines and recent trends is presented.
Conclusions are drawn on the importance of compliance and a recommendation is made that organisations choose to hire the services of multidisciplinary companies specialized in GDPR compliance.