General Data Protection Regulation
The General Data Protection Regulation (GDPR) is a European Union law that sets rules for how organizations protect the privacy and security of personal data about individuals. It applies to organizations both inside and outside the EU that handle such data, and it took effect on May 25, 2018.
The GDPR is Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data. It forms part of EU data protection legislation and establishes obligations governing how organizations within and outside the EU handle the personal data of individuals. The regulation was put into effect on 25 May 2018. Note that GDPR is a general data protection law and is distinct from payment-specific standards such as PCI DSS; where both apply, organizations should confirm their obligations against the current published text of each and applicable guidance rather than assuming one satisfies the other.
Why it matters
The GDPR establishes obligations for how organizations protect the privacy and security of personal data about individuals, and its reach extends beyond the EU to organizations outside the EU that handle such data. For payment security, compliance, and fraud teams, this matters because the personal data processed during payment flows, fraud investigations, and customer onboarding can fall within the scope of the GDPR when it relates to individuals in the EU. That makes the regulation a standing consideration for any organization whose transaction or risk-management activity touches EU personal data, regardless of where the organization itself is located.
It is important to distinguish the GDPR from payment-specific standards such as PCI DSS. The GDPR is a general data protection law governing personal data broadly; PCI DSS is a payment card security standard. Where both apply, satisfying one does not automatically satisfy the other. Cardholder data protected under PCI DSS may also constitute personal data under the GDPR, but the two frameworks impose distinct obligations, use different terminology, and are maintained by different bodies. Organizations should confirm their obligations against the current published text of each and applicable guidance rather than treating compliance with one as evidence of compliance with the other.
Because the GDPR took effect on 25 May 2018 and forms part of a broader body of EU data protection legislation, teams responsible for compliance mapping should treat it as one input among several that may govern how personal data is handled, rather than the sole authority. The precise scope of any given control, and how it interacts with payment security requirements, depends on the specific processing activity and the applicable legal text.
Who it's relevant to
Inside GDPR
Common questions
Answers to the questions practitioners most commonly ask about GDPR.