GDPR
acronymprivacygovernance & risk
Stands for: General Data Protection Regulation
The European Union's comprehensive data protection law, in force since 2018.
The General Data Protection Regulation sets rules for handling personal data, consent, purpose limits, access and deletion rights, with real penalties, and applies to anyone processing EU residents' data. Brazil's LGPD is closely modeled on it.
The GDPR is the European data protection regulation that reset global expectations, and its influence comes as much from reach as from content. It applies to processing the personal data of people in the EU regardless of where the processor sits, so companies with no European office found themselves in scope, and many chose to apply it everywhere rather than run two systems.
The core mechanic is that processing requires a lawful basis, and consent is only one of six. That surprises people who equate compliance with cookie banners: legitimate interests, contract, and legal obligation cover a great deal of ordinary processing, and reaching for consent where another basis applies creates an obligation to honour withdrawal that the business may not actually want.
The obligations that bite operationally are the ones with clocks attached. Breach notification to a supervisory authority within seventy-two hours of becoming aware, data subject requests answered within a month, and records of processing maintained rather than reconstructed under pressure. Fines are calculated against global turnover, which is what moved data protection from a legal footnote to a board-level topic.
Also known as: gdpr, lgpd, data protection regulation