Skip to content
← All terms

Glossary · Privacy & regulation

GDPR

The GDPR (General Data Protection Regulation, EU 2016/679) is the European Union’s data protection law, in force since 25 May 2018, governing how personal data of people in the EU/EEA is collected, processed, and transferred.

The GDPR applies to any organization that processes the personal data of people in the EU/EEA, regardless of where the organization itself is based — a US or Swiss company with EU users is in scope. It sets out principles (lawfulness, purpose limitation, data minimization, storage limitation), a set of legal bases for processing (consent, contract, legitimate interest, and others), and individual rights including access, rectification, erasure, portability, and objection.

Organizations that determine why and how data is processed are data controllers; those processing on a controller’s behalf are data processors, and the regulation requires a data processing agreement between them. Cross-border transfers outside the EU/EEA need a safeguard — an adequacy decision, standard contractual clauses, or a certified framework such as the EU-US Data Privacy Framework. Fines can reach 4% of global annual turnover or €20 million, whichever is higher.

Ciphera processes personal data under GDPR for EU/EEA users and stores it on Swiss infrastructure (Exoscale, Zurich), which the European Commission recognizes as offering adequate protection — so no additional transfer mechanism is needed for that flow.

See also

Related terms