- Home
- Insights
- The revenue lexicon
- General Data Protection Regulation
Glossary
General Data Protection Regulation (GDPR)
Data and infrastructure
The GDPR (General Data Protection Regulation, EU Reg. 2016/679) is the law that has governed the use of data about identifiable people across the European Union since May 2018.
It applies today, with no phase-in, so it also covers the personal data an employee pastes into an artificial intelligence service nobody in the company chose. Article 22 gives anyone subject to an automated decision three rights: human intervention, the chance to state their case, and the right to contest the outcome. It replaced Directive 95/46/EC, which each country had transposed in its own way, with a single law valid throughout the Union, and it also applies to non-European companies processing data of people located in Europe: that is why it became a model copied around the world. It rests on a few principles: lawfulness, fairness and transparency; purpose limitation; data minimisation, collecting only the data needed; accuracy; storage limitation; security; accountability, under which the company must prove it complies. Fines reach up to 20 million euros or 4% of worldwide annual turnover (Article 83). In Italy the supervisory authority is the Garante per la protezione dei dati personali.
An example
Screening job applications with a personal tool produces effects on real people with no oversight and no audit trail. The AI Act (the European regulation on artificial intelligence, EU Reg. 2024/1689) obligations for the Annex III high-risk systems, job screening among them, arrive on 2 December 2027, while the data protection regulation has applied for eight years: the question for the board is who in the company can state the origin, the owner and the legal basis of every field a model reads.
What are your business challenges?
Tell us about your priorities and the objectives you want to reach.
You will receive a free, targeted answer within one working day.