GDPR (General Data Protection Regulation)
The European Union's data-protection law, in force since 2018, whose Article 3 reaches organizations outside the EU that offer goods or services to, or monitor, people in the Union. The GDPR established the reach-not-address principle that the AI Act's Article 2 now carries into the AI domain. (Data-protection law is treated in depth elsewhere; it is referenced here for the shared reach logic.)
Defined in 4 GAGE programs, which carry 10 distinct definitions of it. The wording above is taught in AI Governance: Applied Mastery.
How each discipline defines it
The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.
The European Union's data-protection law, in force since 2018, whose Article 3 reaches organizations outside the EU that offer goods or services to, or monitor, people in the Union. The GDPR established the reach-not-address principle that the AI Act's Article 2 now carries into the AI domain. (Data-protection law is treated in depth elsewhere; it is referenced here for the shared reach logic.)
The European Union's data-protection law, which can require a lawful basis to contact individuals and carries penalties reaching millions of euros or a percentage of global revenue; sets a higher bar than U.S. anti-spam law for prospecting that touches people in covered regions. (Deep treatment in Module 3 and Topic 12.4.)
The European Union's comprehensive data protection law (Regulation (EU) 2016/679, enforceable since May 2018), applying to any organization processing personal data of people in the EU regardless of where the organization is based, and requiring privacy-by-design under Article 25.
The UK and EU data protection law that governs the processing of personal data, including interview notes that identify a named individual and describe their conduct. Requires a lawful basis under Article 6 and adherence to the purpose-limitation principle in Article 5(1)(b).
The EU's comprehensive data protection law, in force since May 25, 2018, governing how organizations collect, use, and protect personal data of individuals in the EU.
Where it is taught
The exact lessons this term appears in. The first 7 topics of every program are free with a free account.
- AI for Business Development: Lead Generation and Prospect Research · Bonus: SMB AI Adoption Path, AI Literacy & Professional Conduct
- The interview sweep: what the humans know about the data that the systems do not · The Estate Survey, AI Data Governance: The Data Chair
- Lawful basis, spelled out: consent, contract, legitimate interest, and which one actually covers each dataset · Consent, Purpose, and the Law of Data, AI Data Governance: The Data Chair
- Article 10 executed: the EU AI Act's data governance duty for the system your organization ships · Lineage Under Audit, AI Data Governance: The Data Chair
- Notification decisions: who must be told, when, and in which jurisdiction · Data Incidents, AI Data Governance: The Data Chair
- The two gates: is it an AI system, and does the Act apply to your organization at all · The EU AI Act: The Executive Map, AI Governance: Applied Mastery
- China, the UK, and the divergence problem: one product, three rulebooks · The World's Rulebooks, AI Governance: Applied Mastery
- The agent audit trail: logging actions so you can reconstruct any decision it made · Agents Under Command, AI Governance: Applied Mastery
- The DPIA and FRIA, run jointly: one assessment, two regimes, no duplicate work · Evidence Engineering, AI Governance: Applied Mastery
Terms it appears with
Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.