The General Data Protection Regulation is the European Union’s comprehensive data protection law that came into force on May 25, 2018. It establishes strict rules for how organizations collect, process, store, and transfer personal data of EU residents. Key provisions include requiring explicit consent for data processing, mandatory data breach notifications within 72 hours, right to data portability, right to erasure (“right to be forgotten”), privacy by design and by default, and appointment of Data Protection Officers for certain organizations. The GDPR applies extraterritorially to any organization processing EU residents’ data, regardless of location. It imposes significant penalties of up to €20 million or 4% of global annual turnover, whichever is higher. For Indian companies serving EU customers or processing EU data, GDPR compliance is mandatory and has influenced India’s DPDP Act framework.
Health Data Management Policy (under Ayushman Bharat Digital Mission)
ABDM participants must comply with the Health Data Management Policy. Healthcare laws include the Clinical Establishments Act, National Medical Commission Act provisions requiring physician confidentiality,