New EU Data Protection Regulation Close to Adoption


On December 15, the European Commission, European Parliament, and Council of the EU reached agreement on the text of a new law governing the protection of personal data. The new General Data Protection Regulation will replace the 1995 EU Data Protection Directive and will have significant bearing for all companies doing business in the EU or offering products or services – including even free online services – to individuals in the EU. Although the new Regulation will not be formally adopted until the first quarter of 2016, and compliance with its provisions won’t be required until early 2018, companies should begin to familiarize themselves with the new obligations, compare these new requirements to existing practices, and develop a compliance plan. Penalties for non-compliance can be severe.

Brief Overview of General Data Protection Regulation

New or increased obligations appear in bold; reduced obligations and other positive features appear in italics.

Background Terminology

Scope of Application

Rights of Data Subjects

Principles Applicable to Processing of Personal Data

Privacy Impact Assessments (PIAs) and Privacy by Design (PbD)

Data Protection Officers (DPOs)

Record-keeping; DPA Reporting & Consultation Requirements

Breach Notification

International Transfers

Liability and Sanctions for Non-Compliance


© 2025 Faegre Drinker Biddle & Reath LLP. All Rights Reserved.
National Law Review, Volume V, Number 352