GDPR (General Data Protection Regulation)
The GDPR (General Data Protection Regulation) is the EU regulation on the protection of personal data. It has applied directly in all member states since May 2018 and to all organizations that process data of persons in the EU – regardless of where the organization is based.
Core principles are lawfulness, purpose limitation, data minimization, storage limitation and accountability: whoever processes data must be able to demonstrate compliance. Data subjects receive far-reaching rights, including access, rectification, erasure and data portability. Data breaches must be reported to the supervisory authority within 72 hours; violations can be punished with fines of up to 20 million euros or 4 percent of global annual turnover.
Technically, the GDPR requires appropriate protective measures – the operational implementation overlaps strongly with Data Protection, while responsibilities, retention rules and evidence processes are anchored in Data Governance. For IT and security managers, the GDPR is thus a permanent basic requirement, not a one-off project.