The EU General Data Protection Regulation, the comprehensive law governing how personal data of individuals in the EU may be processed.
The General Data Protection Regulation (GDPR) governs the processing of personal data of people in the European Union. It rests on principles such as lawfulness, purpose limitation, data minimization, and accountability, and it grants individuals rights over their data.
It applies to organizations inside and outside the EU that process EU residents' data, and breaches can lead to significant fines. In German it is known as the Datenschutz-Grundverordnung (DSGVO).
Related frameworks