The EU General Data Protection Regulation (GDPR) harmonizes data privacy laws across Europe, replacing the previous directive to protect citizens' personal data. Key changes include wider applicability to non-EU companies processing data of EU citizens, requirements for clear consent, and rights for individuals regarding their data, such as the right to be forgotten. Organizations found in breach of GDPR can face fines up to 4% of annual global turnover or €20 million, emphasizing the importance of compliance for both data controllers and processors.