Europe’s data privacy regulation, the General Data Protection Regulation (GDPR), was enacted to harmonize data privacy laws across the European Union. In an increasingly globalized society, the GDPR has an undeniably expansive reach, forcing companies outside the EU to consider their obligations under the regulation. We work alongside innovative companies to help them achieve GDPR compliance and mitigate the risks associated with the collection and use of consumer data.
Home » Practices » Privacy & Data Security » GDPR
The GDPR applies to all member states of the European Union and the European Economic Area. As such, this law could impact all companies that engage with European consumers, even if those companies are not located in the European Union themselves. This could also be true for companies that are based in the United States but attract European visitors to their websites.
How Can We Help? Let's Talk
Uncertainty about the meaning of certain terms included in the GDPR is one of the largest hurdles to compliance. Vaguely defined terms such as “undue delay” and “reasonable level or protection” leave room for interpretation by regulators and courts. This ambiguity poses major challenges to companies that wish to mitigate the risk of noncompliance.
A processor, on the other hand, engages in data processing on behalf of the controller. Since processors act on behalf of the controller, they serve the controller’s interests instead of their own and operate under the authority of the controller. Data processors face their own set of compliance standards and must take appropriate measures to process data in line with GDPR rules and regulations.
The European Union’s GDPR Checklist for US Companies can be a helpful first resource for many American companies starting their GDPR compliance journey, but the complexity of EU guidelines and the ways in which the European regulatory system differs from that prevailing in the United States makes it advisable to work with experienced counsel offering targeted guidance and assistance in creating a comprehensive compliance program designed to satisfy both European consumers and regulatory authorities. Developing –– and demonstrating –– a strict protocol for maintaining GDPR compliance is one of the most important and effective strategies for American businesses to minimize unnecessary legal exposure.