Remove eu-eea-regulatory
article thumbnail

GDPR compliance checklist

IBM Journey to AI blog

The General Data Protection Regulation (GDPR) is a European Union (EU) law that governs how organizations collect and use personal data. Any company operating in the EU or handling EU residents’ data must adhere to GDPR requirements. The EEA includes all 27 EU member states plus Iceland, Liechtenstein and Norway.

article thumbnail

How to implement the General Data Protection Regulation (GDPR)

IBM Journey to AI blog

Yet many organizations still struggle to meet compliance requirements, and EU data protection authorities do not hesitate to hand out penalties. The GDPR puts forth a litany of rules for how organizations in and outside of Europe handle the personal data of EU residents. The company has employees in the EEA.