Practices

Cyber/Data/Privacy

General Data Protection Regulation (GDPR) Resources

In the past several years, privacy regulations in the European Union and the UK have undergone significant changes, which affect companies worldwide. 

The EU’s General Data Protection Regulation (GDPR), which came into force in 2018, impacts not only EU companies but also any company that operates an EU-facing website to market goods or services to EU-based individuals and/or monitors EU-based individuals (e.g., with cookies or other similar technologies).

The EU GDPR’s far-reaching effects on companies with a real-life or online presence in EU have required numerous changes to the way businesses handle personal information. The UK has retained the GDPR and incorporated it into UK law following Brexit.

The EU and UK GDPRs impose significant obligations on businesses, including:

  • A strict definition of consent, making it difficult to obtain.
  • Requirements around profiling, sensitive data handing, data retention and use, which restrict what companies may do with the data they collect – and how they store and handle it.
  • Obligations on and liabilities for data processors.
  • Breach notification requirements.
  • Sanctions for failure to comply, which could result in fines of up to 4% of annual turnover or 20 million euros/17.5 million pounds (whichever is higher).

EU and UK GDPR compliance encompasses more than having correct policies; for many companies, it may affect business operations and require new technology or changes to configurations of existing technology. Becoming and staying EU and UK GDPR compliant should be a multi-stakeholder process, involving internal company resources across the organization and external advisers.

Cooley has a team of experienced practitioners who understand what it takes to comply with the EU and UK GDPRs in a way that complements your business priorities. If you would like further information on what you should be doing to ensure that you are compliant, please contact us – we are here to help.

Cooley GO

Other resources

Blog posts

cyber/data/privacy insights

Videos and webinars

AI Shorts and Talks

Privacy Talks

This content is provided for general informational purposes only, and your access or use of the content does not create an attorney-client relationship between you or your organization and Cooley LLP, Cooley (UK) LLP, or any other affiliated practice or entity (collectively referred to as "Cooley"). By accessing this content, you agree that the information provided does not constitute legal or other professional advice. This content is not a substitute for obtaining legal advice from a qualified attorney licensed in your jurisdiction, and you should not act or refrain from acting based on this content. This content may be changed without notice. It is not guaranteed to be complete, correct or up to date, and it may not reflect the most current legal developments. Prior results do not guarantee a similar outcome. Do not send any confidential information to Cooley, as we do not have any duty to keep any information you provide to us confidential. When advising companies, our attorney-client relationship is with the company, not with any individual. This content may have been generated with the assistance of artificial intelligence (Al) in accordance with our Al Principles, may be considered Attorney Advertising and is subject to our legal notices.