
On 25 May 2018, EU Regulation No. 2016/679, known as the GDPR (General Data Protection Regulation) – concerning the protection of natural persons with regard to the processing and free movement of personal data – will become directly applicable in all Member States.
The GDPR stems from the need for legal certainty, harmonisation, and greater simplicity in the rules governing the transfer of personal data from the EU to other parts of the world.
The European Commission's primary objectives are to return control of personal data to citizens and to simplify the regulatory environment for international business by unifying and standardising privacy legislation across the various EU Member States.
In summary, the General Data Protection Regulation:
The rules also apply to businesses located outside the European Union that offer services or products within the EU market. All companies, regardless of where they are established, must therefore comply with the new rules. Businesses and organisations will have greater responsibilities and face heavy penalties in the event of non-compliance.
To assist businesses, particularly SMEs, in preparing for the entry into force of the new regulation, the European Commission has set up a new dedicated portal containing all the information required to comply with the new rules and avoid penalties.
At present, Italy is among the countries that have yet to adapt to the new rules. Although it is a regulation, which is self-executing by nature, there are still aspects left to the discretion of national legislators, such as the age threshold for defining a minor.
Commissioner for Justice Jourová has confirmed that the Commission is in constant contact with Member States to provide assistance in accelerating implementation.