GDPR In The Travel Industry
The General Data Protection Regulation 2016/679 is a regulation in EU law on data protection and privacy in the European Union and the European Economic Area. It also addresses the transfer of personal data outside the EU and EEA areas. The purpose of GDPR is to give people easier access to their personal data and give the companies clear responsibility to obtain consent from the people whose information they collect. Any data that can identify the person directly or indirectly is personal data such as IDs/ passport details, contact information, HR records, Payment information and such. The GDPR enforces extremely high penalties divided into two broad categories: Upper level – up to €20 million or 4 percent of total worldwide annual global revenue for the latest financial year for major breaches. Compare this penalty amount with the corresponding data breach in 2012, which can be considered a major one as 1,163,996 debit and credit card records we...