This document discusses key aspects of the General Data Protection Regulation (GDPR) which takes effect in the European Union on May 25, 2018. It begins with an overview that the GDPR is a regulation, not a directive, and will have worldwide influence and consequences for companies and the public sector. It then provides definitions for important GDPR terms like personal data, processing, controller, and processor. The main principles of the GDPR are outlined, including accountability, consumer rights, privacy by design, security, and penalties for noncompliance. The document stresses that companies must be prepared to comply with the GDPR to avoid penalties and reputational risks.