Terminology Index

Glossary

33 terms starting with "G"

Open concept maps

Showing 1-32 of 33 terms

G
32

GDPR

The European Union's General Data Protection Regulation, a comprehensive privacy law governing how organizations collect, process, and protect the personal data of people in the EU, with strict obligations and significant penalties for non-compliance.

The GDPR sets baseline rules for handling personal data: lawful basis for processing, transparency, data-subject rights (access, erasure, portability), breach notification, and accountability, and it applies to any organization handling EU residents' data regardless of location. Its large potential fines have made it a global reference point for privacy. In a governance context, it is a major regulatory driver shaping policy, controls, and program priorities.

Introduced in: Security Governance and Program Foundations

Examples

  • Establishing a lawful basis before processing EU residents' personal data.
  • Honoring an EU individual's right to erasure of their data.
  • Notifying authorities of a qualifying breach within the required time.

No related terms linked yet.