What is GDPR?
The European Union's General Data Protection Regulation — the global benchmark for data privacy, applying to any organisation processing EU citizens' data.
Definition
The European Union's General Data Protection Regulation — the global benchmark for data privacy, applying to any organisation processing EU citizens' data.
The General Data Protection Regulation (GDPR) is the European Union's comprehensive data protection regulation that sets a global benchmark for privacy. GDPR applies to any organisation processing EU citizens' data, regardless of where the organisation is based. Key requirements include lawful processing, data protection impact assessments, breach notification within 72 hours, appointment of Data Protection Officers, and penalties of up to 4% of global annual turnover.
For African enterprises with European customers, subsidiaries, or operations, GDPR compliance is mandatory. Many African data protection laws — including POPIA, NDPA, and Kenya's DPA — are modelled on GDPR principles, meaning GDPR compliance provides a strong foundation for meeting local requirements.
Talk to Our AI Governance & GRC Specialists
Our ISACA-certified professionals help enterprises navigate POPIA, NDPA, ISO 42001, and AI compliance frameworks across Africa.
