EU Regulatory Center

GDPR — the EU’s data-protection framework

The foundational EU framework for how personal data must be collected, processed, secured and disclosed in the event of a breach.

Status

Law in force
Regulation (EU) 2016/679
The GDPR has applied since 25 May 2018 and remains the EU’s core data-protection framework, setting principles for lawful processing, individual rights, and mandatory breach notification, and applying extraterritorially to organizations that process EU residents’ personal data.
Reviewed 2026-06 · Source: Official Journal of the European Union

Scope at a glance

QuestionAnswer
WhoAny organization processing the personal data of individuals in the EU, regardless of where the organization is based.
WhatLawful-basis, data-minimization and purpose-limitation principles, plus individual rights (access, erasure, portability and more).
ReportingPersonal-data breaches likely to risk individuals’ rights must be reported to the supervisory authority within 72 hours.
GovernanceMany organizations are required to appoint a Data Protection Officer (DPO) and maintain records of processing.

Core obligations

General guidance, not legal advice
This page summarizes publicly available regulatory status for general guidance only. Confirm applicability, scope and deadlines with qualified legal counsel before making compliance decisions.
How CYRKIL helps

The Privacy / DPO role view reads GDPR obligations against the same asset, access and vendor data used across the platform.

See the Privacy / DPO view
How CYRKIL tracks this

Every regulatory page here runs through the Regulatory Truth Pipeline — official source, human and legal review, then publish, with the source, version and review date always shown.

See the pipeline

Get a readiness review against this regulation.