Skip to content
Mandatory · lawEuropean UnionEUv2016/679

GDPR

General Data Protection Regulation (EU 2016/679)

The EU regulation governing the processing of personal data. Its security and accountability articles (notably Art. 5, 25, 30, 32–35) map directly onto technical and organizational controls in security frameworks.

Official source ↗

Who it applies to

Any sectorEU / EEAProcesses personal data

Any organization, anywhere in the world, that processes the personal data of individuals in the EU/EEA — whether established in the EU or offering goods and services to, or monitoring the behaviour of, people there.