GDPR
The General Data Protection Regulation (EU 2016/679), in force since 25 May 2018. Establishes EU-wide rules for processing personal data, with extraterritorial reach to any organisation offering goods or services to EU residents.
What GDPR covers
GDPR regulates the processing of personal data — defined broadly as any information relating to an identified or identifiable natural person. Six lawful bases for processing exist: consent, contract, legal obligation, vital interests, public interest, legitimate interests. Special-category data (health, biometric, genetic, ethnic origin, political opinion, religious belief, trade-union membership, sexual orientation) requires explicit consent or one of nine specific exceptions.
Penalties
Two tiers: up to €10M or 2% of global annual turnover (whichever is higher) for procedural violations; up to €20M or 4% for substantive violations. Enforcement has been substantial — Meta, Google, Amazon, and others have received nine-figure penalties.
The Schrems II problem
GDPR allows international transfers under Standard Contractual Clauses, Binding Corporate Rules, or adequacy decisions. The 2020 Schrems II ruling tightened SCC use: transferring to a third country with weaker surveillance protections requires Transfer Impact Assessment and supplementary measures. See Schrems II →
Data subject rights
Data subjects have rights of access, rectification, erasure ("right to be forgotten"), restriction, portability, and objection. Erasure under GDPR includes the obligation to delete from backups within reasonable time — making cryptographic erasure (rotating the wrap key) a practical approach.
How SkyeConnex maps
The GDPR compliance preset pack encodes EU residency policy, signed audit-log retention, and data-subject-access tooling. The architecture makes Erasure under Article 17 a cryptographic operation (rotate the wrap key; previous data becomes unreachable). Multi-cloud RAID with EU-only jurisdictional spread satisfies the "essentially equivalent" requirement post-Schrems II without depending on the survival of the EU-US Data Privacy Framework.
UK-GDPR
The Data Protection Act 2018 incorporates GDPR into UK domestic law (UK-GDPR), in force post-Brexit. Substantially equivalent but procedurally separate. SkyeConnex's GDPR pack handles both regimes.
Related terms
See also
Posts that mention GDPR
Schrems II two years on: what actually changed for EU-US data transfers
The 2020 CJEU ruling invalidated Privacy Shield. Five years and one EU-US Data Privacy Framework later, the underlying problem remains. Here…
Read → Regulation · 8 min readThe CLOUD Act and why data residency isn't enough
The CLOUD Act extends US legal reach to data held by US-controlled cloud providers anywhere in the world. Choosing a Frankfurt or Toronto re…
Read → Regulation · Canada · 7 min readPIPEDA and cloud storage: what most providers get wrong
PIPEDA predates the cloud. Applying it to multi-cloud workloads requires architectural thinking that most providers don't do. Here's the gap…
Read →