GDPR
General Data Protection Regulation
Europe's landmark data-protection law — and the global benchmark for privacy.
Regulation
EU 2016/679
Region
EU / EEA
In force
25 May 2018
Max penalty
€20M or 4% turnover
Overview
What is GDPR?
The General Data Protection Regulation (EU 2016/679) governs how organizations collect and process the personal data of people in the EU and EEA. In force since 25 May 2018, it applies to any company worldwide that offers goods or services to, or monitors, EU residents.
It is principle-based rather than a checklist, anchored on seven data-protection principles and a strong set of data-subject rights. Penalties reach up to €20 million or 4% of global annual turnover, whichever is higher.
Who needs it: Any organization that handles the personal data of people in the EU or EEA — regardless of where the company itself is based.
Inside the framework
The seven data-protection principles
Lawfulness, fairness & transparency
Process personal data legally, fairly, and in a way people can understand.
Purpose limitation
Collect data for specified, explicit, and legitimate purposes only.
Data minimisation
Collect only what you actually need for those purposes.
Accuracy
Keep personal data correct and up to date.
Storage limitation
Don't keep data in identifiable form longer than necessary.
Integrity & confidentiality
Secure data with appropriate technical and organizational measures.
Accountability
Be able to demonstrate compliance with all of the above — the principle RegShield is built for.
With RegShield
Get GDPR-ready in a fraction of the time
AI evidence mapping
Upload a policy, screenshot, or config and RegShield maps it to the right GDPR controls in seconds — with confidence scores you can defend in front of an auditor.
Reuse across frameworks
Evidence you collect for GDPR is automatically reused across every other framework you've activated — so the work compounds instead of repeating.
Gaps & audit-ready reports
See your GDPR readiness score, the exact gaps that remain, and concrete remediation steps — then export an audit-ready report.
FAQ
Common questions
Does GDPR apply to non-EU companies?
Yes, if you offer goods or services to, or monitor the behaviour of, people in the EU/EEA — the regulation's territorial scope is extraterritorial.
What rights do data subjects have?
Access, rectification, erasure (the 'right to be forgotten'), restriction, portability, and objection, among others.
When must we report a breach?
To the supervisory authority within 72 hours of becoming aware where feasible, and to affected individuals if there's a high risk to their rights.