
At Sungrow, we maintain a robust global compliance framework that aligns with international standards and regional regulatory requirements across key markets.
The General Data Protection Regulation (GDPR) is a comprehensive data protection law of the European Union, which entered into force on 24 May 2016 and has applied since 25 May 2018, replacing the Data Protection Directive of 1995. Its core objectives are to strengthen individuals’ control over their own data, improve transparency and accountability of data processing, and harmonise data protection rules across EU Member States. Scope of Application: The Regulation governs two categories of entities, covering both controllers (who determine the purposes and means of data processing) and processors (entities that process data on behalf of controllers): ● Entities within the region: all organisations located in the EU/EEA that carry out personal data processing activities; ● Overseas entities with EU-related business: organisations outside the EU are bound by this Regulation if they offer goods or services to residents of the EU/EEA, or monitor the behaviour of such residents within the region and process associated personal data. Key Provisions: ● Data processing principles: all data processing activities shall abide by the core principles of lawfulness, fairness, transparency, data minimisation, accuracy, storage limitation, integrity and confidentiality. ● Informed consent of data subjects: data processing must be based on the voluntary, specific and unambiguous informed consent of data subjects. ● Data subjects’ rights: individuals have the right of access, the right to data portability (to obtain data in a standard machine-readable format), and the right to erasure (right to be forgotten). ● Compliance controls: Data Protection Impact Assessments (DPIA) are required for high-risk data processing operations, and certain organisations must appoint a Data Protection Officer (DPO) to oversee compliance. ● Cross-border data controls: cross-border transfers of personal data are strictly regulated to ensure that overseas data protection standards are equivalent to those in the EU. Penalties: Non-compliant organisations may face severe administrative fines, up to the higher of EUR 20 million or 4% of worldwide annual turnover. Consequences may also include reputational damage and legal claims brought by data subjects. Sungrow products have obtained the Verification of Compliance for GDPR Should you require the detailed report, please contact our sales team.