Yes, any company who is processing personal data of the EU citizens, must comply with the General Data Protection Regulation.

Why Every Organisation Needs a Solid GDPR Foundation: Lessons from the SportAdmin Breach
Lesson 1: Privacy Isn’t Optional — It’s a Safety Issue In the SportAdmin breach, attackers gained access to a database containing personal information from over