General Data Protection Regulation (GDPR)
An EU regulation that sets comprehensive rules for protecting personal data of individuals in the European Union.
The General Data Protection Regulation (GDPR) is a European Union regulation governing how organizations collect, use, and safeguard personal data about individuals in the EU.
It introduces concepts like lawful bases for processing, data subject rights, privacy by design, and accountability. Many organizations outside the EU are subject to GDPR when they handle EU residents’ data.
Compliance often requires updates to policies, contracts, technical controls, and internal processes for handling data subject requests and incidents.