The General Data Protection Regulation (GDPR, EU 2016/679) is the global legal benchmark for personal data protection. It applies to any organization that processes personal data of individuals in the European Union, regardless of where the organization is based.
Key principles
Lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; accountability.
Key obligations
- Record of processing activities (RoPA)
- Data Protection Impact Assessments (DPIAs) for high-risk processing
- Data breach notification within 72 hours
- Data subject rights (access, rectification, erasure, portabilityβ¦)
- DPO appointment where required
ermine and GDPR
ermine manages the record of processing activities, DPIAs, the breach register and data subject rights response deadlines, with automatic alerts to prevent regulatory deadline breaches.