The personal information protection framework developed by the European Parliament, the European Council and the European Commission. "EU General Data Protection Regulation". The EU General Data Protection Regulation (GDPR) replaces the Data Protection Directive 95/46/EC, which aims to coordinate data privacy laws across Europe, protect and authorize the data privacy of all EU citizens, and reshape the privacy of the organization's data processing methods throughout the region .
GDPR is the biggest change in data protection law in 30 years. It updates the current laws promulgated before the advent of Facebook, LinkedIn and the cloud, and unifies the data protection laws of all 28 EU member states.
The regulations enjoy extraterritoriality, which means that the GDPR will affect all companies that access or process the personal data of EU residents, regardless of where the company is located and how the data is collected.
Such as restaurants, hotels, travel agencies, taxis, e-commerce shopping platforms, etc., with customer credit card information and membership information
Employees, suppliers, third parties, partners, you may have their insurance information, salary records, contact information, etc.
Volunteers, members, sponsors, donors, consultants of the organization... are EU citizens. If you have their contact information, tax information, etc., they are subject to the GDPR
The fine is the total annual global turnover of 4%, up to 20 million euros
For example, if you set up a branch or sales office in the European Union and hire local employees as employees, you need to take measures to protect employees' personal data in accordance with the GDPR. Many companies have developed personal information protection management measures in accordance with the EU Data Protection Directive enacted in 1995. Therefore, prior to the implementation of GDPR in 2018, stricter correspondence education is necessary.
In addition, even if you do not have an overseas base, EU residents will enter the name, phone number, credit card number, etc. when purchasing products from the Chinese and Taiwanese websites, which must also meet the GDPR.
The GDPR has caused a lot of discussion because of the data that will be used in the digital advertising ecosystem, such as cookies, IP, device identification codes (including Google Advertising ID (AAID) for Android, advertising ID for iOS devices (IDFA), Device Fingerprint is counted), geographic location (GPS coordinates, or geographic area known by IP reverse inference), etc. are all classified as personal privacy data of EU citizens. Therefore, in order to meet GDPR regulations, the website owner must inform and seek the consent of the website visitors.
GDPR is known as the most stringent personal privacy information protection law in history, which means that the EU will fully open the era of personal privacy protection in legal form.