What is General Data Protection Regulation (GDPR)?
General Data Protection Regulation (GDPR) is the European Union's primary data protection law, in force since May 2018, that sets rules for how organizations collect, store, process, and delete personal data of EU residents. It applies to any organization worldwide that handles EU resident data, regardless of where that organization is based.
What it is
GDPR is a regulation, not a product or tool category. It is a binding legal framework that replaced the EU Data Protection Directive of 1995. Key obligations include:
- Lawful basis for processing: Organizations must have a documented legal reason to process personal data, such as consent, contract, or legitimate interest.
- Data subject rights: Individuals can request access to their data, correction, deletion, or portability. Organizations must respond within 30 days.
- Data Protection Officer (DPO): Certain organizations must appoint a DPO to oversee compliance.
- Records of Processing Activities (RoPA): Organizations must maintain a written inventory of what personal data they hold and why.
- Breach notification: A personal data breach must be reported to the relevant supervisory authority within 72 hours of discovery.
- Data Protection Impact Assessments (DPIAs): Required before starting high-risk processing activities.
- Third-party contracts: Data processors must sign Data Processing Agreements (DPAs) with controllers.
Fines can reach 4% of global annual turnover or 20 million euros, whichever is higher.
Why it matters
GDPR affects security programs directly. Security teams must implement technical controls such as encryption, access controls, and pseudonymization. They must also support privacy teams with breach detection, incident response timelines, and vendor risk reviews. A security incident that exposes personal data is also a potential GDPR breach.