The General Data Protection Regulation (GDPR) is a comprehensive data protection and privacy law enacted by the European Union that governs the collection, processing, storage, and transfer of personal data for individuals within the EU and EEA. It establishes a strict regulatory framework based on principles like lawfulness, fairness, transparency, and purpose limitation, granting data subjects enforceable rights over their information. The regulation imposes significant compliance obligations on data controllers and data processors, with severe financial penalties for violations.
