Pablo Meles, Of Counsel, Espinosa Martinez

GDPR provides for fines up to 20M Euro or up to 4 percent of global turnover for the previous 12 months, whichever is greater. In some instances, GDPR also provides for warnings, reprimands, or temporary suspension of data processing. Worse yet, violations of GDPR can cause brand and reputation damage from customers complaining.

In practical terms, GDPR applies to personal data or a broader form of what is known as personal identifiable information (PII). In the context of GDPR, personal data can include any data associated to an individual such as names, IP, social media, email, or home addresses, cookies, personal photographs, etc. Controllers and processors have a responsibility to protect and not abuse personal data collected. A controller determines the purposes and means of use of personal data. A processor acts on the instructions of the controller and processes the personal data on behalf of the controller. Processing under GDPR has a very broad definition and can include just merely storing the data.