Back to Frameworks
Privacy

GDPR

The General Data Protection Regulation (2018) is the EU's comprehensive data protection law, and it applies to any organization processing the personal data of people in the EU — regardless of where the organization itself is based.

It is built on principles like lawfulness, purpose limitation, and data minimization, and grants individuals enforceable rights including access, erasure ("right to be forgotten"), and data portability. Organizations must report qualifying breaches within 72 hours, and many are required to appoint a Data Protection Officer.

See how LumiGRC handles GDPR

Get a Demo
4%

Max fine of global revenue

0%
Typical certification profile
Audit Rigor62%
Time to Certify44%
Surveillance Burden63%
Issued & Enforced By

European Commission

Regulation (EU) 2016/679, Arts. 5, 32-34, 83

Key Points

  • Applies extraterritorially to anyone processing EU residents' data
  • Enforceable individual rights: access, erasure, portability
  • 72-hour breach notification requirement
  • Fines up to €20M or 4% of global revenue