The General Data Protection Regulation (GDPR) is a comprehensive reform of the EU's 1995 data protection regulation that strengthens and unifies online privacy rights and data protection for EU citizens. Key changes include stricter rules around data breaches, higher fines of up to 4% of global turnover for non-compliance, and a single law across the EU instead of different national laws. Organizations must notify breaches to authorities within 72 hours and encrypt personal data to avoid notifying individuals affected in high risk breaches. The GDPR takes effect in 2018.