The General Data Protection Regulation–commonly referred to as GDPR–is a privacy law pertaining to the collection of online data enacted by the European Union (EU) that took effect May 25, 2018. The law affects organizations regardless of geographic location, since EU residents may visit the websites of governments, private companies, nonprofits, or other organizations providing goods and services, and those websites likely collect and analyze online data related to those website visitors originating in the EU (regardless of whether a transaction occurred).