On May 25, the European Union implemented a sweeping data privacy law in the form of the General Data Protection Regulation.

Among other provisions, the GDPR mandates that companies notify data-holders of a breach within 72 hours and also gives EU citizens the “right to be forgotten” by having their personal data wiped off a company’s servers.