Definition
The General Data Protection Regulation (GDPR) is a European Union regulation defining rules for processing and protecting personal data and the rights of data subjects.
Human Explanation
It defines how organisations may collect, use, store and protect personal data.
Why it Matters
Correct application strengthens privacy protection, reduces the Risk of data breaches and supports Trust.
Conceptual Boundary
GDPR is not a Cybersecurity standard. It governs personal data processing, although many requirements involve Information Security.
Practical Perspective
Compliance requires both suitable technical Controls and appropriate organisation of personal data processing.