Governance. Risk. Compliance. Cybersecurity.

Regulators & Laws

GDPR

Acronym: General Data Protection Regulation

EU/EEA regulation governing the processing of personal data.

GDPR applies extraterritorially to organisations offering goods or services to EU data subjects or monitoring their behaviour. Maximum fines reach 4% of global turnover or €20m, whichever is higher. Article 32 security and Article 30 records are the operational backbone.