GDPR
The General Data Protection Regulation (GDPR) is the European Union law governing the processing of personal data, granting individuals rights over their data and imposing accountability obligations on organizations.
The GDPR took effect in 2018 and applies to organizations that process the personal data of individuals in the EU, regardless of where the organization is based. It is built on principles including lawfulness, purpose limitation, data minimization, accuracy, storage limitation, integrity, and accountability.
The regulation grants data subjects rights such as access, rectification, erasure, restriction, portability, and objection. Organizations must be able to respond to these requests within defined timeframes and to demonstrate compliance through documentation such as a Record of Processing Activities.
Key operational obligations include maintaining a lawful basis for processing, conducting a Data Protection Impact Assessment for high-risk activities, reporting qualifying personal-data breaches within 72 hours, and applying appropriate technical and organizational security measures.
Related terms
- DPIAA Data Protection Impact Assessment (DPIA) is a structured process for identifying and minimizing the data-protection risks of a project or processing activity.
- RoPAA Record of Processing Activities (RoPA) is an inventory of how an organization processes personal data, maintained to demonstrate GDPR accountability.
- Vendor Risk ManagementVendor risk management (VRM) is the process of identifying, assessing, and monitoring the security and compliance risks introduced by third-party suppliers and service providers.
- Continuous ComplianceContinuous compliance is the practice of monitoring controls and collecting evidence on an ongoing basis, so an organization remains audit-ready at all times rather than only before an audit.