- Full name
- General Data Protection Regulation (Regulation (EU) 2016/679)
- Region
- European Union (extraterritorial)
- Applies to
- Any organisation processing personal data of individuals in the EU, regardless of where the organisation is established. Extraterritorial reach via Article 3.
GDPR has been in force since 25 May 2018 and remains the reference regime for personal-data protection. Most identity programmes treat it as a CIAM concern, but the data-protection principles (Article 5), security-of-processing duty (Article 32), and breach-notification regime (Articles 33-34) all touch identity directly — both customer-facing and workforce.