Skip to main content
Promotional banner for the pentest readiness checklist
Category: Governance & Controls

General Data Protection Regulation

Also known as: GDPR, Regulation (EU) 2016/679, EU General Data Protection Regulation
Simply put

The GDPR is a European Union data protection law that governs how organizations collect, process, store, and transfer personal data about individuals. It establishes legally binding protections for the privacy and security of that data. Because it applies to organizations well beyond Europe's borders when they handle the data of people in the EU, its requirements affect businesses around the world.

Formal definition

The General Data Protection Regulation, formally Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, is a binding EU regulation on the protection of natural persons with regard to the processing of personal data. As a regulation it has direct legal force across the EU, distinguishing it from voluntary frameworks or standards. It forms part of the broader body of EU data protection legislation and treats data protection as a fundamental right under EU law; the European Commission identifies it alongside other instruments such as the Law Enforcement Directive. Its scope generally extends beyond the EU to organizations outside the territory that process the personal data of individuals in the EU, though the precise conditions of this extraterritorial reach and its application to particular circumstances should be verified against the current official text and assessed with professional judgment.

Why it matters

The GDPR is one of the most consequential data protection regimes in force because it treats the protection of personal data as a fundamental right under EU law and gives that protection direct legal effect across the European Union. Unlike voluntary frameworks or standards such as ISO/IEC 27001 or SOC 2, which apply only through contract or self-selection, the GDPR is binding law. Organizations that fall within its scope must comply as a legal obligation, not as a matter of best practice, and its requirements shape how personal data is collected, processed, stored, and transferred.

Its significance extends well beyond Europe's borders. The GDPR can apply to organizations established outside the EU when they process the personal data of individuals in the EU, meaning that businesses in the United States, the United Kingdom, and elsewhere may be subject to it depending on their activities. This extraterritorial reach has made the regulation a reference point in global discussions of data protection, and many organizations align their practices to it even where they are uncertain whether it strictly applies. The precise conditions triggering this reach are fact-specific and should be assessed against the current official text.

Because the GDPR forms part of a broader body of EU data protection legislation—which the European Commission identifies as including other instruments such as the Law Enforcement Directive—readers should not treat it as the sole source of data protection obligations. Its interpretation continues to evolve through guidance and enforcement practice, and application to particular circumstances requires professional judgment.

Who it's relevant to

Data Protection Officers and privacy specialists
Those responsible for privacy programs need to understand the GDPR as a binding legal instrument that establishes protections for the privacy and security of personal data. It is central to determining how personal data is lawfully collected, processed, stored, and transferred, and how those obligations map onto an organization's operations.
Organizations outside the EU handling EU residents' data
Businesses established outside the EU may fall within the GDPR's scope when they process the personal data of individuals in the EU. Such organizations should assess whether their activities trigger this extraterritorial reach, verifying the precise conditions against the current official text, as the regulation's requirements can affect businesses around the world.
Legal counsel and compliance officers
Because the GDPR is a regulation with direct legal force—distinct from voluntary frameworks or standards—legal and compliance teams must treat it as an enforceable obligation rather than an optional benchmark. They also need to situate it within the broader body of EU data protection legislation, which includes other instruments such as the Law Enforcement Directive.
Information security professionals
The GDPR establishes protections for both the privacy and the security of personal data, so security teams have a role in supporting compliance. Security measures alone do not satisfy the regulation's full range of requirements, but they form part of how organizations protect personal data across its lifecycle.

Inside GDPR

Material and territorial scope
The GDPR is a binding EU regulation governing the processing of personal data of individuals in the EU/EEA. It applies to organizations established in the EU and, on an extraterritorial basis, to organizations outside the EU that offer goods or services to, or monitor the behavior of, individuals in the EU. Scope determinations are fact-specific; verify against the current text and guidance from supervisory authorities.
Controller and processor roles
The regulation distinguishes the controller (which determines the purposes and means of processing) from the processor (which processes personal data on the controller's behalf). These roles carry different obligations and should not be conflated; a single organization may act as controller for some processing and processor for other processing.
Data protection principles
Processing is generally required to adhere to principles such as lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability. These principles underpin the more specific obligations and inform how requirements are interpreted.
Lawful basis for processing
Processing generally requires a valid lawful basis (for example, consent, contract, legal obligation, vital interests, public task, or legitimate interests). Additional conditions typically apply to special categories of data. The appropriate basis depends on the context and purpose of the processing.
Data subject rights
The GDPR grants individuals rights that may include access, rectification, erasure, restriction, data portability, and objection, subject to conditions and exemptions. The availability and scope of each right depends on the lawful basis and circumstances of the processing.
Accountability and governance measures
Organizations are generally expected to demonstrate compliance through measures that may include records of processing, data protection impact assessments for higher-risk processing, data protection by design and by default, and, in certain cases, appointment of a data protection officer. Applicability often depends on risk level, scale, and the nature of processing.
Security and breach handling
The regulation requires appropriate technical and organizational security measures proportionate to risk, and includes obligations relating to personal data breaches, which may involve notification to a supervisory authority and, in higher-risk cases, communication to affected individuals within timeframes set by the regulation. Verify specific timeframes against the current official text.
International data transfers
Transfers of personal data outside the EU/EEA are generally permitted only where appropriate safeguards or other transfer mechanisms apply. The available mechanisms and their conditions evolve over time and should be checked against current guidance.
Supervision and enforcement
Enforcement is carried out by national supervisory authorities, coordinated at the EU level. The regulation provides for administrative fines and other corrective measures. Enforcement practice can diverge from the text, and penalty outcomes are fact-specific; consult current authoritative sources for details.

Common questions

Answers to the questions practitioners most commonly ask about GDPR.

Does the GDPR apply only to organizations based in the European Union?
No. This is a common misconception. The GDPR has extraterritorial reach: it can apply to organizations established outside the EU where they offer goods or services to individuals in the EU, or where they monitor the behavior of individuals in the EU. Territorial scope is fact-specific and depends on the nature of the processing and the targeting of EU-based individuals rather than solely on where the organization is located. The related EU EEA context and the separate UK GDPR regime should also be considered, and readers should verify applicability against the current official text and relevant regulatory guidance.
Is achieving 'GDPR certification' the same as being GDPR compliant?
No. Compliance and certification are distinct concepts. Compliance with the GDPR is a legal obligation arising from the regulation itself, whereas certification refers to voluntary schemes that may be established under the regulation's provisions to help demonstrate adherence to particular requirements. A certification, seal, or mark can support accountability but does not by itself establish full compliance, is generally limited in scope to what it covers, and does not substitute for meeting the regulation's obligations. Certification schemes and their availability vary and change over time, so readers should confirm the status and scope of any specific scheme against authoritative sources.
How do controller and processor roles affect who bears which obligations?
The allocation of obligations generally depends on whether an organization acts as a controller, which determines the purposes and means of processing, or as a processor, which processes personal data on behalf of a controller. These roles carry different responsibilities, and the same organization may act as a controller for some processing and a processor for other processing. Determining the correct role is fact-specific and typically shapes the contractual arrangements between the parties. Application to particular circumstances requires professional judgment, and readers should verify current requirements against the official text.
When is a data protection impact assessment generally expected?
A data protection impact assessment is generally expected where a type of processing is likely to result in a high risk to the rights and freedoms of individuals, often in connection with new technologies or large-scale or systematic processing. Whether the threshold is met is fact-specific and depends on the nature, scope, context, and purposes of the processing. Supervisory authorities may publish lists indicating processing operations that do or do not require such an assessment, and these can differ across jurisdictions. Readers should consult the current official text and applicable regulatory guidance.
What is generally required when transferring personal data outside the EU or EEA?
Transfers of personal data to recipients outside the EU or EEA are generally subject to conditions intended to ensure that the level of protection is not undermined. These may rely on mechanisms such as adequacy determinations, appropriate safeguards, or specific derogations, depending on the circumstances. The available mechanisms and their conditions can evolve in response to legal developments, and separate rules may apply under the UK regime. Because transfer arrangements are fact-specific and interpretations continue to develop, readers should verify current requirements against authoritative sources and apply professional judgment.
When must a personal data breach be notified, and to whom?
Notification obligations generally depend on the nature and severity of the breach. In many cases a personal data breach must be notified to the relevant supervisory authority, and where the breach is likely to result in a high risk to affected individuals, communication to those individuals may also be required. Timing expectations and thresholds are set out in the regulation and may be elaborated in regulatory guidance, and enforcement practice can diverge from the text. Because the assessment is fact-specific, readers should confirm the applicable requirements against the current official text and seek professional judgment for particular incidents.

Common misconceptions

The GDPR applies only to organizations located in the EU.
The GDPR has extraterritorial reach. It can apply to organizations established outside the EU where they offer goods or services to, or monitor the behavior of, individuals in the EU. Location of the organization is not the sole determinant of applicability.
Complying with the GDPR is the same as obtaining a certification.
The GDPR is a binding legal regulation, not a certification scheme. Compliance is an ongoing legal obligation demonstrated through accountability measures, whereas certification (where available) is a separate, generally voluntary mechanism that does not by itself prove full compliance.
Consent is always required to process personal data under the GDPR.
Consent is only one of several possible lawful bases. Processing may instead rely on grounds such as contract, legal obligation, or legitimate interests, depending on the context. Choosing the appropriate basis is fact-specific.

Best practices

Determine and document your role for each processing activity (controller, processor, or joint controller), since obligations differ and a single organization may hold different roles for different activities.
Identify and record an appropriate lawful basis for each processing purpose before processing begins, and apply the additional conditions that may be required for special categories of data.
Maintain accountability documentation, such as records of processing activities and, where higher-risk processing is involved, data protection impact assessments, so compliance can be demonstrated.
Assess whether the extraterritorial provisions apply to your organization if you serve or monitor individuals in the EU from outside the EU, and confirm scope against current supervisory authority guidance.
Implement risk-proportionate technical and organizational security measures and establish breach detection and response procedures, verifying applicable notification timeframes against the current official text.
Review international data transfer arrangements against current transfer mechanisms and guidance, and periodically re-verify all obligations against the latest authoritative sources, as the regulation and related guidance are subject to change.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps