GDPR

Also known as: General Data Protection Regulation

framework · governance and compliance · regulatory-standard

EU regulation on data protection and privacy applicable to processing of EU residents' personal data.

The General Data Protection Regulation is the European Union's comprehensive data protection law, applicable since May 2018, governing processing of personal data of EU residents. The regulation's substantial extraterritorial reach — applying to non-EU organizations that process EU residents' data — has made it a de facto global standard for many multinational organizations. GDPR is built around principles including lawfulness, purpose limitation, data minimization, and accountability, and grants data subjects rights including access, rectification, erasure, and portability. Enforcement is by national data protection authorities with fines up to 4% of global annual revenue, which has produced multi-hundred-million-euro penalties against major technology companies.

Originators

European Parliament and Council of the European Union high

Year / Decade

2016 (adopted); 2018 (effective) high

Primary sources

Regulation (EU) 2016/679 (GDPR), Official Journal of the European Union high

Band notes

Has substantial extraterritorial reach; non-EU organizations processing EU residents' data must comply.

Core components

Primary use case

Data protection compliance for organizations processing EU residents' personal data; foundation for many subsequent privacy regimes globally; basis for privacy-by-design and privacy engineering practices.

Common criticisms

Lineage

Child of
FIPPs
Siblings
CCPA, HIPAA, Privacy by Design, FIPPs
Derived from
FIPPs