The EU General Data Protection Regulation (the “Regulation”) came into effect on 25 May 2018, replacing the Data Protection Act 1998. The GDPR requirements largely repeat the security principles set out in the DPA, although with a much tougher regime and more severe sanctions for breach.
This change has brought about business challenges for which there is little, if any, legislative or regulatory clarity at present.
1. How does controllerand processorliability work in practice?