Privacy & Consumer Data
What Is GDPR?
A plain-language overview of GDPR as a European data protection framework, including personal data, lawful basis, rights, controllers, processors, and cross-border relevance.
Quick answer
GDPR stands for the General Data Protection Regulation. It is a European Union data-protection law that sets rules for how personal data is collected, used, stored, shared, and protected.
Where the term appears
- personal data processing
- privacy notices
- data subject rights
- controllers and processors
- international services
Digital compliance in real systems
Digital compliance topics often involve several layers at once: user-facing notices, back-end records, security controls, vendor tools, retention rules, consent settings, and internal escalation. Readers should distinguish what a user sees on a screen from what an organization must manage behind the scenes.
| Visible layer | Operational layer | Governance layer |
|---|---|---|
| Forms, notices, account screens, dispute pages | Logs, checks, workflow queues, retention settings | Policies, review duties, accountability, audit trails |
Operational relevance
Digital and privacy obligations usually touch notices, consent or lawful-use decisions, data inventories, vendors, access controls, retention, incident handling and rights-request workflows. A public-facing statement is only one part of the operating system behind it.
What it does not establish by itself
- It is not the only privacy law in the world.
- It does not apply the same way to every organization.
- This article is not a compliance checklist or legal opinion.
Key records and decision points
- Role as controller, joint controller or processor
- Purposes and lawful bases for processing
- Data-subject rights and response workflow
- Processor contracts, transfers, security and breach handling
Common confusion
GDPR is a broad data-protection framework. Applicability and required measures depend on role, location, processing and facts.
Official-source check
For current rules, forms, deadlines, eligibility, or filing instructions, always check official sources. This article is an educational overview, not a substitute for official guidance.
Related reference pages
- What Is Data Protection Compliance?
- What Is a Privacy Impact Assessment?
- How to Read a Privacy Notice
- What Is a Record Retention Policy?