On May 25, more than two years’ worth of anticipation concluded when the European Union’s General Data Protection Regulation (GDPR) finally reached full enforcement status. Passed by the EU Parliament on April 14, 2016 [(EU) 2016/679], it was decided to give everyone affected by the dramatic changes more than two years to prepare for the new requirements.

GDPR replaces the 1995 Data Protection Directive (the directive) and applies to all current 28 EU member states. If the UK goes through with Brexit, the GDPR consequences are a little unclear, but that won’t be an issue until early 2019.[FN1] And penalties for violations are not for the faint of heart with maximums of 4 percent of a year’s gross revenue or €20 million, whichever is greater.