Standards & Compliance

What is GDPR?

Also known as: General Data Protection Regulation

Definition

The General Data Protection Regulation (GDPR) is an EU law that governs the processing of personal data and applies to any organization worldwide that handles data of EU residents.

The General Data Protection Regulation (GDPR) is a comprehensive data privacy regulation enacted by the European Union that took effect on May 25, 2018. It replaces the 1995 Data Protection Directive and establishes a unified legal framework for personal data processing across all EU member states. The regulation applies to any organization, regardless of location, that processes personal data of individuals residing in the EU, giving it significant extraterritorial reach.

The GDPR defines personal data broadly as any information relating to an identified or identifiable natural person. It imposes strict requirements on data controllers and processors, including the need for explicit consent, data minimization, purpose limitation, and transparency. Individuals are granted rights such as the right to access their data, the right to rectification, the right to erasure (the right to be forgotten), and the right to data portability. Organizations must implement appropriate technical and organizational measures to protect personal data and must report certain data breaches to supervisory authorities within 72 hours.

Noncompliance with the GDPR can result in administrative fines of up to 20 million euros or 4 percent of the organization's annual global turnover, whichever is higher. The regulation has become a global benchmark for data protection, influencing similar laws in other jurisdictions such as Brazil's LGPD and California's CCPA. It operates alongside other EU digital regulations like the ePrivacy Directive and the Digital Services Act, forming a broader framework for digital rights and data governance.

Key facts

  • Effective May 25, 2018, replacing the 1995 Data Protection Directive.
  • Applies to any organization processing personal data of EU residents, regardless of location.
  • Fines up to 20 million euros or 4 percent of annual global turnover for violations.
  • Grants individuals rights including access, rectification, erasure, and data portability.
  • Requires breach notification to supervisory authorities within 72 hours.

How it works in practice

A US-based ecommerce company that sells products to customers in France must comply with the GDPR. It must obtain explicit consent before collecting email addresses for marketing, allow customers to request deletion of their accounts, and report any data breach involving French customer data to the French data protection authority (CNIL) within 72 hours.

Related terms

Data Protection Impact Assessment (DPIA) Data Subject Access Request (DSAR) Data Protection Officer (DPO) ePrivacy Directive California Consumer Privacy Act (CCPA) Lei Geral de Proteção de Dados (LGPD)

References

More in Standards & Compliance

BCP 14

BCP 14 defines the normative meaning of MUST, SHOULD, MAY, and related keywords used in RFCs to specify requirement levels in Internet standards.

BCP 38

BCP 38 (RFC 2827) is a Best Current Practice that defines ingress filtering to prevent packets with spoofed source IP addresses from leaving a network.

HIPAA

HIPAA is a 1996 US federal law that sets national standards for protecting sensitive patient health information from disclosure without consent or knowledge.

IANA

IANA is the function that coordinates global IP address allocation, manages the DNS root zone, and assigns protocol numbers used in Internet standards, ensuring unique identifiers across the network.

ICANN

ICANN is a nonprofit organization that coordinates the Domain Name System (DNS) root zone, accredits registrars, and oversees the Internet Assigned Numbers Authority (IANA) functions for global unique identifiers.

IETF

The Internet Engineering Task Force (IETF) is an open international community of network designers, operators, vendors, and researchers that develops voluntary internet standards, primarily through working groups and the RFC document series.

ISO 27001

ISO 27001 is an international standard specifying requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).

ITU-T

ITU-T is the United Nations agency that sets global telecommunications standards, including X.509 certificates and G-series video codecs.

PCI DSS

PCI DSS is the mandatory security standard for any organization that stores, processes, or transmits credit card data, enforced by the payment card brands.

Regional Internet Registry

A Regional Internet Registry (RIR) is an organization that manages the allocation and registration of Internet number resources (IP addresses and Autonomous System Numbers) within a specific geographic region.

Who Is Online

In total there are 65 users online: 0 registered, 57 guests and 8 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Other Bot Other Crawler PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 369