The General Data Protection Regulation (2018) is the EU's comprehensive data protection law, and it applies to any organization processing the personal data of people in the EU — regardless of where the organization itself is based.
It is built on principles like lawfulness, purpose limitation, and data minimization, and grants individuals enforceable rights including access, erasure ("right to be forgotten"), and data portability. Organizations must report qualifying breaches within 72 hours, and many are required to appoint a Data Protection Officer.
Max fine of global revenue
European Commission
Regulation (EU) 2016/679, Arts. 5, 32-34, 83