The GDPR replaces the 1995 EU Data Directive ( The GDPR replaces the 1995 EU Data Directive ("Directive") and will apply to organizations involved in the "processing" of the "personal data" of individual EU citizens. (Photo: Shutterstock)

When finally effective on May 25, 2018, the European Union's long-anticipated General Data Protection Regulation (GDPR) will dramatically expand the scope of entities covered by the European data protection framework, imposing EU regulation on a wide range of U.S. companies that utilize the personal information of EU individuals in their businesses but were not previously subject to EU data protection protocols.

While many U.S. companies have recognized and are prepared to meet this considerable new compliance challenge, others remain unaware of the obligations it will impose (or, in some cases, of the GDPR's very existence) or have simply forgotten. This is true despite the fact that many of these entities' are generally aware of privacy protection-related risk, and maintain privacy and network security ("cyber") insurance coverage to protect against such risk.

Given the GDPR's newly imposed 72-hour deadline for notifying regulators of a known data breach, the need to quickly respond to data breaches once improper disclosure of "personal data" is discovered, other new and/or enhanced compliance obligations imposed by the GDPR with respect to personal data, and the stiff fines associated with non-compliance, lack of GDPR-awareness poses obvious and serious risks for these companies, as well as for cyber carriers eventually tasked with resulting claims.

Want to continue reading?
Become a Free PropertyCasualty360 Digital Reader

  • All PropertyCasualty360.com news coverage, best practices, and in-depth analysis.
  • Educational webcasts, resources from industry leaders, and informative newsletters.
  • Other award-winning websites including BenefitsPRO.com and ThinkAdvisor.com.
NOT FOR REPRINT

© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.