Companies that do not do business in Europe or in any jurisdiction that works with the EU don’t need to comply with the EU General Data Protection Regulation (GDPR). If your company, or any company you provide services for, works in a country with GDPR compliance requirements, any data you manage or handle has to meet GDPR (Regulation [EU] 2016/679) requirements as of May 25, 2018, when the GDPR will be fully implemented. Do not think that this will not affect you post-Brexit if you only have UK customers, either, as the UK government will have implemented the Data Protection Bill, which brings UK data-protection law into line with the EU regulation.

The question you need to ask yourself is “What does my company need to do to protect itself?”
GDPR 2018: The Clock Is Ticking with image of hand holding stopwatch surrounded by stars.
To Care or Not to Care: That Is the Question!