Overview
Direct Answer
The General Data Protection Regulation is EU legislation that establishes comprehensive rules for the collection, processing, and storage of personal data belonging to residents of EU member states and the EEA. It grants individuals enforceable rights over their data and imposes legal obligations on organisations that handle such information.
How It Works
The regulation operates through a consent and lawful basis framework requiring organisations to document processing activities, conduct data protection impact assessments, and implement privacy-by-design principles. It establishes roles including data controllers (who determine processing purposes) and processors (who handle data on behalf of controllers), with documented contracts mandating specific safeguards and breach notification protocols within 72 hours of discovery.
Why It Matters
Non-compliance carries fines up to €20 million or 4% of global annual turnover, creating substantial financial and reputational risk. Organisations operating across borders or handling EU resident data must embed compliance into operations, affecting data architecture, consent management, and vendor selection decisions.
Common Applications
Manufacturing firms collecting employee data, e-commerce platforms processing customer information, cloud service providers handling EU resident records, and financial institutions managing customer databases all fall under its scope. Healthcare organisations and marketing agencies managing personal data are particularly heavily regulated.
Key Considerations
The regulation applies extraterritorially to non-EU organisations processing EU resident data, creating compliance obligations regardless of organisational location. Balancing legitimate business interests with individual rights requires ongoing legal interpretation, as enforcement approaches vary across member state authorities.
Referenced By1 term mentions GDPR
Other entries in the wiki whose definition references GDPR — useful for understanding how this concept connects across Governance, Risk & Compliance and adjacent domains.
More in Governance, Risk & Compliance
Data Privacy
Compliance & RegulationThe proper handling of personal data including collection, storage, processing, and sharing in compliance with regulations.
Information Governance
GovernanceThe overarching strategy for managing an organisation's information assets, balancing the need for data availability with security, privacy, compliance, and lifecycle management.
Information Classification
GovernanceThe process of categorising data based on its sensitivity level and the impact of unauthorised disclosure.
Acceptable Use Policy
GovernanceA document defining the permitted use of an organisation's IT resources and networks.
AI Audit
Compliance & RegulationAn independent assessment of an AI system's compliance with regulatory requirements, ethical standards, and organisational policies, examining data, models, outputs, and governance.
Regulatory Technology
Compliance & RegulationTechnology solutions designed to help companies comply with regulations efficiently and cost-effectively.
Third-Party Risk Management
Risk ManagementThe process of identifying and mitigating risks associated with outsourcing to third-party vendors.
Model Risk Management
GovernanceThe governance framework for identifying, measuring, and mitigating risks arising from AI and analytical models.