General Data Protection Regulation
GDPRThe EU's comprehensive personal-data law. It governs how any organization collects, uses, stores, and shares personal data about people in the EU/EEA — and it applies even if your company sits outside Europe, as long as you handle Europeans' data (extraterritorial reach).
Anyone processing EU residents' personal data. It splits roles into the controller (decides why/how data is used) and the processor (handles it on the controller's behalf). Larger operations must appoint a Data Protection Officer (DPO).
- A lawful basis for every use of data (consent, contract, legal obligation, legitimate interests, etc.).
- Core principles: purpose limitation, data minimization, accuracy, storage limitation, security, accountability.
- Data-subject rights: access, correction, erasure (“right to be forgotten”), portability, objection, and a right not to be subject to solely automated decisions (Art. 22).
- Breach notification to the regulator within 72 hours; a DPIA for high-risk processing.
Fines up to €20 million or 4% of global annual turnover, whichever is higher.
It set the global template — most modern privacy laws copy it. For AI, Art. 22 (automated decisions) collides directly with the AI Act: an AI that auto-rejects a loan triggers both. You can't govern AI without GDPR in the room.