// Security
The GDPR is the European Union regulation governing the processing of personal data and the rights of individuals in that processing. It applies to controllers and processors established in the EU and, in defined circumstances, to organisations outside the EU that offer goods or services to people in the EU or monitor their behaviour there. Personal data is information relating to an identified or identifiable person; processing includes activities such as collecting, using, sharing, storing, altering, and deleting it.
Why it matters: Website compliance starts with mapping the personal data processed, purposes, recipients, locations, retention, security, and the controller–processor roles involved. Identify and document an appropriate lawful basis for each purpose; consent is one basis, not the default for all processing. Give required information in clear language, support applicable rights such as access, rectification, erasure, restriction, portability, and objection, and establish processes for processor contracts, breaches, high-risk assessments, and international transfers where relevant. Cookie and similar-technology rules also depend on the ePrivacy framework and national law. A privacy notice, banner, or automated scan alone does not establish compliance; obtain qualified advice for the organisation's facts and jurisdictions.
Explore related checks and guidance for gdpr (general data protection regulation) on your own site.
Open Cookie & Privacy AgentLooking for practical context? Start with the guidance behind these checks and definitions.
Read WebEnture's security guidance