GDPR (General Data Protection Regulation)
The General Data Protection Regulation (GDPR) is the European Union's comprehensive data privacy law governing how organizations collect, use, and protect the personal data of people in the EU. It sets requirements for consent, transparency, data rights, and security, with significant penalties for violations.
The GDPR applies to any organization processing the personal data of EU residents, regardless of where the organization is based. It establishes principles like lawful basis, purpose limitation, and data minimization.
It also grants individuals rights over their data, including access, correction, and deletion. First-party data collected transparently and with consent aligns naturally with its principles. This is general information, not legal advice.
Go deeper
Put the vocabulary to work on your data
Get a free First-Party Data Readiness Review, or browse the full glossary and guide library.