CyberGlossary

Compliance & Frameworks

GDPR

Also known as: General Data Protection Regulation, Regulation (EU) 2016/679

Definition

The European Union's General Data Protection Regulation governing the processing of personal data of individuals in the EU and EEA.

The General Data Protection Regulation (Regulation (EU) 2016/679) is the European Union's comprehensive data-protection law, in force since 25 May 2018. It applies to any organization processing personal data of individuals in the EU or EEA, regardless of where the organization is based, and codifies principles such as lawfulness, purpose limitation, data minimization, and accountability. GDPR grants data subjects rights including access, rectification, erasure, portability, and objection, and requires controllers to perform Data Protection Impact Assessments for high-risk processing. Supervisory authorities can impose administrative fines of up to 4% of global annual turnover or €20 million, whichever is higher.

Examples

  • A U.S. e-commerce site offering goods to EU consumers must publish a GDPR-compliant privacy notice.
  • A French employer responding to an employee's right-of-access request within one month.

Related terms