What is GDPR Framework?
The European Union General Data Protection Regulation (EU GDPR) is not a framework, but a European Union regulation.
For a quick summary of this regulation:
- GDPR went into effect in 2018 and affects companies that store, process and/or transmit personal data of EU citizens.
- GDPR governs the collection, processing, storage and transfer of personal data of EU residents;
- GDPR emphasizes individual rights;
- GDPR requires “data protection by design”.
While not a traditional framework like NIST 800-53 or ISO 27001, GDPR is a global benchmark for privacy regulations, since it influenced data protection practices worldwide. GDPR’s global reach forces organizations to adopt strong data privacy governance and accountability mechanisms.