General Data Protection Regulation
The GDPR is a European Union data protection law that governs how organizations collect, process, store, and transfer personal data about individuals. It establishes legally binding protections for the privacy and security of that data. Because it applies to organizations well beyond Europe's borders when they handle the data of people in the EU, its requirements affect businesses around the world.
The General Data Protection Regulation, formally Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, is a binding EU regulation on the protection of natural persons with regard to the processing of personal data. As a regulation it has direct legal force across the EU, distinguishing it from voluntary frameworks or standards. It forms part of the broader body of EU data protection legislation and treats data protection as a fundamental right under EU law; the European Commission identifies it alongside other instruments such as the Law Enforcement Directive. Its scope generally extends beyond the EU to organizations outside the territory that process the personal data of individuals in the EU, though the precise conditions of this extraterritorial reach and its application to particular circumstances should be verified against the current official text and assessed with professional judgment.
Why it matters
The GDPR is one of the most consequential data protection regimes in force because it treats the protection of personal data as a fundamental right under EU law and gives that protection direct legal effect across the European Union. Unlike voluntary frameworks or standards such as ISO/IEC 27001 or SOC 2, which apply only through contract or self-selection, the GDPR is binding law. Organizations that fall within its scope must comply as a legal obligation, not as a matter of best practice, and its requirements shape how personal data is collected, processed, stored, and transferred.
Its significance extends well beyond Europe's borders. The GDPR can apply to organizations established outside the EU when they process the personal data of individuals in the EU, meaning that businesses in the United States, the United Kingdom, and elsewhere may be subject to it depending on their activities. This extraterritorial reach has made the regulation a reference point in global discussions of data protection, and many organizations align their practices to it even where they are uncertain whether it strictly applies. The precise conditions triggering this reach are fact-specific and should be assessed against the current official text.
Because the GDPR forms part of a broader body of EU data protection legislation—which the European Commission identifies as including other instruments such as the Law Enforcement Directive—readers should not treat it as the sole source of data protection obligations. Its interpretation continues to evolve through guidance and enforcement practice, and application to particular circumstances requires professional judgment.
Who it's relevant to
Inside GDPR
Common questions
Answers to the questions practitioners most commonly ask about GDPR.

