Data protection defines principles, organizational rules and technical controls to safeguard personal and sensitive data from misuse, loss, or unauthorized access. It includes legal bases, roles and responsibilities, endpoint and lifecycle controls, and measurable audits to reduce risk and ensure regulatory compliance across systems and processes.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What you need to understand to reason about a domain.
Data protection is the regulated handling of personal and sensitive data so that access, use, and sharing remain lawful, purpose-bound, and protected.
In the European legal context, data protection emerged from the problem that ever larger amounts of personal data were being collected and combined in government, business, and digital services without clear limits on purpose, access, or sharing. The current framework is anchored primarily in EU law, especially the GDPR and complementary rules for law enforcement and EU institutions; it combines fundamental-rights protection with demonstrable organizational controls.
Think of data protection as a protective layer across the data life cycle. First, it must be clear whether processing is permitted at all. Then purpose, scope, and access are constrained, risks are reduced through technical and organizational measures, and sharing is controlled. At the end, deletion, access, correction, and auditability show whether the rules are not only written down but actually effective in practice.
Information relating to an identified or identifiable person.
Processing needs an allowed legal ground and a clearly stated purpose.
Data may be used only for the specific, legitimate purposes for which it was collected.
Protection requirements are built into processes, products, and systems from the start.
Access, correction, deletion, and similar rights give people control over their data.
Access, storage, and sharing are safeguarded through concrete controls and procedures.
Data protection matters for new products, data sharing, outsourced processing, analytics initiatives, and audits. It helps limit legal and reputational risk, but it can also require extra documentation and stricter process discipline. Without clear ownership, minimization, and traceable controls, processing remains vulnerable to challenge.
Where this building block is located in the topic model.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.