Praeferre/Frameworks/GDPR
Privacy & Data Protection · European Union / EEA

General Data Protection Regulation

The EU's foundational data protection law, giving individuals rights over their personal data and requiring organisations to have a lawful basis for processing it. It applies extraterritorially to any organisation handling the data of EU or EEA residents, regardless of where that organisation is based.

REGULATOREuropean Data Protection Board (EDPB) & national DPAs REGIONEuropean Union / EEA EFFECTIVE25 May 2018

Who it applies to

  • Any organisation processing personal data of people in the EU/EEA
  • Both data controllers and data processors
  • Public authorities and private businesses of any size

Key requirements

  • A documented lawful basis for every processing activity
  • Data Protection Officer where processing meets Article 37 thresholds
  • 72-hour breach notification to the supervisory authority
  • Data Protection Impact Assessments for high-risk processing
  • Data subject rights: access, rectification, erasure, portability

Maximum penaltyUp to €20 million or 4% of global annual turnover, whichever is higher

Go to the source

Official resources

Praeferre's summary is a starting point, not legal advice. For the authoritative text and current guidance, go directly to the governing body.

Start your compliance journey

See how Praeferre automates GDPR compliance

Continuous monitoring, evidence and reporting for GDPR — alongside every other framework you need to satisfy.