PrivacyRegulation

GDPR

General Data Protection Regulation

The General Data Protection Regulation (GDPR) is a comprehensive data protection law enacted by the European Union to harmonize privacy regulations across member states. It governs the processing of personal data by organizations operating within the EU and those outside the EU that target EU residents.

Overview

The GDPR, formally known as Regulation (EU) 2016/679, establishes strict guidelines for the collection, processing, storage, and transfer of personal data. It emphasizes transparency, accountability, and the rights of data subjects, including rights to access, rectification, and erasure of data ('right to be forgotten'). Key principles include data protection by design, explicit consent for data processing, and mandatory reporting of data breaches. The regulation also introduces significant penalties for non-compliance and applies to organizations globally that process data of EU residents. The GDPR became effective on May 25, 2018, replacing Directive 95/46/EC.

Related in Privacy

PrivacyLaw

Anti-Discrimination Act 1991 (Qld) — Queensland Anti-Discrimination Act 1991

The Anti-Discrimination Act 1991 is legislation enacted by the Queensland Government to promote equality of opportunity, prohibit discrimination, and encourage tolerance in the state of Queensland, Australia. It covers areas such as work, education, and the provision of goods and services.

Queensland Government • Queensland

View details
PrivacyRegulation

CR code v2.1 — Privacy (Credit Reporting) Code 2014 (Version 2.1)

The Privacy (Credit Reporting) Code 2014 (Version 2.1) provides a framework for credit reporting practices under Australia's Privacy Act. It outlines obligations for Credit Reporting Bodies (CRBs), Credit Providers (CPs), and other affected entities to ensure compliance with privacy regulations.

Australian Government • Australia • v2.1

View details
PrivacyLaw

POPIA — Protection of Personal Information Act

The Protection of Personal Information Act (POPIA) is South African legislation that governs the lawful processing of personal information. It establishes principles and rights for data subjects, conditions for processing, obligations for responsible parties, and enforcement mechanisms.

Government of South Africa • South Africa

View details
PrivacyRegulation

FCA BCOBS — Banking: Conduct of Business Sourcebook (BCOBS)

The FCA's Banking: Conduct of Business Sourcebook (BCOBS) applies to firms accepting deposits from banking customers, focusing on protecting retail customers in banking and payment services. It includes key recordkeeping requirements, such as notifications of cancellation rights.

Financial Conduct Authority (FCA) • United Kingdom • vFebruary 2026

View details

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks — automatically.

Book your strategy call