General Data Protection Regulation (GDPR)
The European Union regulation, applicable since 25 May 2018, that governs the processing of personal data of individuals in the EU, setting principles, legal bases, individual rights and obligations for controllers and processors.
GDPR, formally Regulation (EU) 2016/679, applies to organisations established in the EU and to organisations elsewhere that offer goods or services to, or monitor the behaviour of, individuals in the EU. Its principles are lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. Processing needs a legal basis such as consent, contract, legal obligation or legitimate interests, and individuals have rights including access, rectification, erasure, restriction, portability and objection.
For security teams, Article 32 requires appropriate technical and organisational measures, such as pseudonymisation, encryption and regular testing of their effectiveness, while Articles 33 and 34 govern notification of personal data breaches to supervisory authorities and affected individuals. Data protection by design and by default, data protection impact assessments for high-risk processing and records of processing activities shape how systems are designed and documented.
Supervisory authorities in each member state enforce the regulation, with fines of up to 20 million euros or 4 per cent of worldwide annual turnover, whichever is higher, for the most serious infringements. Transfers of personal data outside the European Economic Area require mechanisms such as adequacy decisions or standard contractual clauses. Interpretation depends on context, so organisations rely on qualified legal and data protection advice.
Key points
- Applies to EU organisations and to others targeting or monitoring people in the EU.
- Article 32 requires appropriate technical and organisational security measures.
- Qualifying breaches must be notified to the authority within 72 hours where feasible.
- Fines can reach 20 million euros or 4 per cent of worldwide annual turnover.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.
Related terms
- Digital Personal Data Protection Act, 2023 (DPDP Act)Cybersecurity & Compliance
- Encryption at Rest and in TransitCybersecurity & Compliance
- Incident ResponseCybersecurity & Compliance
- EU Artificial Intelligence Act (AI Act)Cybersecurity & Compliance
- NIS2 DirectiveCybersecurity & Compliance
- Compliance Gap AnalysisCybersecurity & Compliance