The document discusses the EU's General Data Protection Regulation (GDPR) which takes effect in May 2018. It outlines key aspects of GDPR including what constitutes personal data, the financial penalties for noncompliance, data subject rights, and the responsibilities of data controllers and processors. Organizations must design and implement their systems and processes with privacy in mind based on GDPR's principles in order to avoid penalties that could impact their revenues and reputation.