Back to Frameworks
Frameworks

GDPR (General Data Protection Regulation)

Framework Name

General Data Protection Regulation (GDPR)

Type

Mandatory

Region / Jurisdiction

European Union (applies to any organization worldwide that offers goods or services to, or monitors, individuals in the EU, regardless of where the company itself is based)

Enforcing Body / Certifying Party

National Data Protection Authorities in each EU member state, coordinated through the European Data Protection Board (EDPB). Cross-border cases are typically handled through a "one-stop-shop" mechanism, with one lead authority coordinating enforcement across the EU

Penalty / Consequence of Non-Compliance

Up to €20 million or 4% of global annual turnover, whichever is higher, for the most serious violations. Lower penalty tiers apply to less severe breaches of the law's requirements

What It Is & Why It Matters

GDPR is the European Union's core data protection law, in force since 2018. It gives individuals a defined set of rights over their personal data, including the right to access what's held about them, correct it, have it deleted, and receive a copy in a portable format. It requires organizations to have a lawful basis before processing personal data at all, to report serious data breaches to regulators within 72 hours, and, for higher-risk processing, to conduct formal assessments of privacy impact before starting.

It matters because it fundamentally changed how the world thinks about data protection law, well beyond the EU itself. Its extraterritorial reach means a company with no EU office can still fall fully under it, and its penalty structure was the first of its scale, which is why laws like India's DPDPA and many US state privacy laws borrow concepts directly from it. For most companies handling personal data internationally, GDPR compliance has become the practical floor, meeting other countries' privacy laws is usually easier once GDPR compliance is already in place, not the other way around.

Who Needs It

  • You offer goods or services to individuals located in the EU, even without a physical presence there
  • You monitor the behavior of individuals in the EU, including through tracking, analytics, or profiling
  • You process personal data of EU residents as part of running your business, including as a vendor processing data on another company's behalf
  • You're already navigating other privacy laws (CCPA, DPDPA, PIPEDA) and want the reference point most of them were modeled against
Book A Demo