The EU General Data Protection Regulation (GDPR) replaces the previous data privacy directive and takes effect in 42 days. It gives individuals more control over their personal data and shifts the burden to organizations to demonstrate compliance [with individuals' data privacy rights]. The GDPR has wider scope and applies to any organization that processes personal data. It establishes greater rights for individuals and the potential for much larger fines for noncompliance. To prepare, organizations should undertake an information audit, update their policies and procedures, conduct staff training, and implement security measures to ensure proper processing and protection of personal data.