The General Data Protection Regulation (GDPR) is an EU regulation that governs the protection of personal data and the rights of data subjects. It defines obligations for controllers and processors, establishes legal bases for processing, and requires technical and organizational measures to ensure data protection and accountability.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What you need to understand to reason about a domain.
The General Data Protection Regulation (GDPR) is the EU legal framework for handling personal data. It defines when processing is lawful, what rights data subjects have, and what duties controllers and processors must meet.
The GDPR emerged from the need to harmonize data protection across the EU and strengthen individuals' rights over the processing of their data. The European Parliament and the Council of the European Union adopted it in 2016 as Regulation (EU) 2016/679; it has applied directly since 25 May 2018 and replaced the earlier Data Protection Directive 95/46/EC.
Think of the GDPR as a control loop: every processing activity needs a valid legal basis and a clear purpose. Controllers then have to minimize data, protect it, document decisions, and give people rights such as access, rectification, or erasure. Technical and organizational measures, plus processor contracts, turn those rules into day-to-day operating practice.
Processing is lawful only when it relies on one of the permitted grounds, such as consent, contract, or legal obligation.
Individuals can request access, rectification, erasure, restriction, and object to processing in defined cases.
The controller decides the purposes and means; the processor handles data on the controller's behalf and under instruction.
Purpose limitation, data minimization, accuracy, storage limitation, and integrity structure lawful handling in practice.
Security, access control, documentation, and operational processes are used to reduce risks to rights and freedoms.
Organizations must not only claim compliance but be able to demonstrate it in a traceable way.
The GDPR is central for products, processes, and contracts that process personal data in the EU or target EU residents. It helps with design choices, procurement, data architecture, and incident handling, but it also adds documentation and coordination overhead. Clear roles, purposes, and legal bases matter especially for international transfers, marketing, AI, and tracking features.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.