Chapter 06 · Governance & regulationGovernance, Ethics & Risk
GDPR
Definition
GDPR is the European Union General Data Protection Regulation, a legal framework governing the processing and protection of personal data.
References
This reference provides supporting context for how “GDPR” is defined and used.
Overview
What it means in practice
GDPR should be read as a governance, ethics and risk term. Its meaning depends on the legal context, responsible actor, control design and evidence of operation.
In practice, users should state the boundary, source, evidence and decision context. That keeps gdpr specific enough for review without overstating what the term proves.
Why it matters
GDPR matters because governance language determines accountability, controls and escalation. Clear definitions help readers see whether a process exists, works and is evidenced.
Common misconception
A common error is to treat GDPR as proof of effective governance. The stronger approach is to state ownership, criteria, evidence, monitoring and limits.
Review questions
What scheme, rule or control gives the term meaning? What exact scope is covered? What evidence or limitation would change how a reader interprets it?
How it is used
Policymakers, regulators, legal teams, boards and organisations use “GDPR” in legislation, policies, governance systems, contracts, oversight and compliance decisions. In each case, the user should state the applicable jurisdiction, legal or policy text, effective date, scope and responsible actor; otherwise, the same term may be applied to materially different situations.
In this context, it refers to the European Union General Data Protection Regulation, a legal framework governing the processing and protection of personal data.