Terminology Index
Glossary
33 terms starting with "G"
Showing 1-32 of 33 terms
GDPR
The European Union's General Data Protection Regulation, a comprehensive privacy law governing how organizations collect, process, and protect the personal data of people in the EU, with strict obligations and significant penalties for non-compliance.
The GDPR sets baseline rules for handling personal data: lawful basis for processing, transparency, data-subject rights (access, erasure, portability), breach notification, and accountability, and it applies to any organization handling EU residents' data regardless of location. Its large potential fines have made it a global reference point for privacy. In a governance context, it is a major regulatory driver shaping policy, controls, and program priorities.
Introduced in: Security Governance and Program Foundations
Examples
- Establishing a lawful basis before processing EU residents' personal data.
- Honoring an EU individual's right to erasure of their data.
- Notifying authorities of a qualifying breach within the required time.
No related terms linked yet.
