General Data Protection Regulation
The General Data Protection Regulation (GDPR) is a European Union data protection law that governs how organizations collect, process, store, and transfer the personal data of individuals in the EU and European Economic Area. It became applicable on May 25, 2018, and was designed to harmonize privacy laws across the EU and strengthen the protection of individuals' personal data. Organizations that handle the personal data of people located in the EU may fall within its scope, even if the organization itself is based elsewhere.
The General Data Protection Regulation (Regulation (EU) 2016/679) is a European Union regulation on information privacy applicable across the EU and the European Economic Area (EEA), in effect as of May 25, 2018. It establishes harmonized requirements for the lawful collection, processing, storage, and transfer of personal data relating to individuals located in the EU. In practice, a virtual or fractional CISO engagement may support an organization's GDPR readiness and governance posture, advising on data handling practices, risk management, and program development, but such support does not itself constitute a guarantee of compliance, nor does it transfer legal accountability for data protection obligations, which typically remains with the client organization and its officers unless a contract specifies otherwise. The precise applicability, controller and processor obligations, and required safeguards depend on the specific processing activities and should be assessed against the regulation's authoritative legal text.
Why it matters
GDPR represents one of the most significant data protection regimes affecting organizations worldwide, because its scope can extend beyond the borders of the European Union. An organization based outside the EU may still fall within its reach if it handles the personal data of individuals located in the EU or European Economic Area. For security and privacy leaders, this means GDPR is often a governance and risk consideration rather than a purely technical one, and it frequently shapes how data handling, retention, and transfer practices are designed and documented.
For buyers and providers of virtual or fractional CISO services, GDPR matters because it defines a set of legal obligations around personal data that must be understood, governed, and integrated into an organization's broader security program. A virtual or fractional CISO engagement may support an organization's GDPR readiness, advising on data handling practices, risk management, and program development, but it is important to recognize that such support does not itself guarantee compliance. Legal accountability for data protection obligations typically remains with the client organization and its officers unless a contract specifies otherwise.
A common and important distinction to preserve is that supporting readiness is not the same as asserting compliance. GDPR's precise applicability and the specific obligations of controllers and processors depend on the actual processing activities involved, and these should be assessed against the regulation's authoritative legal text, often with qualified legal counsel. Treating a security leadership engagement as a substitute for that assessment is a mistake experienced professionals would insist on correcting.
Who it's relevant to
Inside GDPR
Common questions
Answers to the questions practitioners most commonly ask about GDPR.