General Data Protection Regulation (GDPR)

The European Union’s (EU) General Data Protection Regulation (GDPR) signals a comprehensive, consumer-oriented approach to data privacy. It replaces and significantly expands the Data Protection Directive 95/46/EC which only applied to organizations with an EU physical presence. As a regulation, GDPR is legally binding on all EU member countries and does not require individual member legislation to enact.

One of the key drivers behind creating this new regulation was to harmonize data-protection laws throughout Europe, where the requirements are generally more strict than those in the United States. GDPR may apply to certain personal data collected by UW‑Madison where we engage in business activities that collect or process the personal data of individuals physically located in the EU. Accordingly, UW‑Madison is establishing a GDPR compliance program for the campus community. Answers to questions most commonly asked about GDPR and the UW–‍Madison are below.

University Usage Standards

FAQs

This is an accordion element with a series of buttons that open and close related content panels.

Disclaimer

The information contained in this FAQ is for informational purposes and does not constitute legal advice. Each situation is unique and advice may vary depending on the specific facts. Further, the law and policy considerations may change as GDPR is implemented and analyzed a legal setting, and the information contained herein may not be updated as needed to maintain accuracy in a changing legal landscape. UW‍–‍Madison employees who have questions about this or any other legal issue, should contact the Office of Legal Affairs as noted above.