General Data Protection Regulation (GDPR)
The General Data Protection Regulation (GDPR) was passed by the European Union (EU) in 2016 to protect the privacy and personal data of individuals within the EU.
The General Data Protection Regulation (GDPR) is the European Union’s comprehensive data protection law that took effect in May 2018.
What is the general data protection regulation (gdpr)?
The General Data Protection Regulation (GDPR) was passed by the European Union (EU) in 2016 to protect the privacy and personal data of individuals within the EU. It came into effect on May 25th, 2018. The GDPR replaces the 1995 EU Data Protection Directive and strengthens EU data protection laws by giving individuals more control over their data and its use.

It applies to any organization that processes the personal data of EU residents, regardless of whether the organization is located within the EU. The GDPR also requires organizations to appoint a Data Protection Officer (DPO) if they are a public authority, if their core activities involve large-scale processing of certain types of personal data, or if they are a personal data processor. Organizations that fail to comply with the GDPR can face significant fines, up to 4% of their annual global revenue or €20 million (whichever is greater). HBR’s technology research identifies GDPR compliance as a competitive advantage as well as legal requirement : organizations that implement privacy-by-design build customer and employee trust that creates measurable business value beyond mere compliance.
Rights of individuals under gdpr:
The GDPR sets out several rights for individuals regarding their personal data, including:
- The right to be informed: individuals have the right to be informed about collecting and using their personal data.
- The right of access: Individuals can access their data and receive a copy.
- The right to rectification: individuals have the right to have inaccurate personal data rectified.
- The right to erasure: individuals have the right to have their personal data erased in certain circumstances.
- The right to restrict processing: individuals have the right to restrict the processing of their personal data in certain circumstances.
- The right to data portability: individuals have the right to receive their personal data in a format that allows them to move it to another service provider.
- The right to object: individuals have the right to object to their personal data being processed in certain circumstances.
What is a data protection officer (dpo)?
A Data Protection Officer (DPO) is an individual who is responsible for overseeing an organization’s compliance with the General Data Protection Regulation (GDPR) and other data protection laws. The DPO is responsible for advising the organization on its obligations under the GDPR and monitoring its compliance with the regulation.
The GDPR requires organizations to appoint a DPO if they are a public authority, if their core activities involve large-scale processing of certain types of personal data, or if they are a personal data processor.
The DPO role is independent and not influenced by any other internal roles or departments; this means that DPO can act as an advisor to the management, monitor compliance with GDPR, internal policies, and procedures, and maintain a record of data processing activities. SHRM’s HR data privacy guidance provides detailed frameworks for GDPR-compliant employee data processing, including lawful basis identification, data subject rights responses, and transfer mechanism documentation.
GDPR compliance shapes how HR systems collect, store, and process employee and candidate data. Organizations using pre-employment assessments ensure every hire is grounded in verified skills. A data-driven hiring plan reduces mis-hire risk, while strong talent acquisition practices focused on skills-based hiring help organizations attract and retain top talent.
Frequently asked questions
The General Data Protection Regulation (GDPR) is the European Union’s comprehensive data protection law that took effect in May 2018. It regulates how organizations collect, process, store, and use personal data of EU/EEA residents. It applies globally : any organization that processes data of EU residents must comply, regardless of where the organization is based. Violations can result in fines up to €20 million or 4% of global annual revenue.
Cite this page
Copy a ready-made citation for this page in your preferred style.
- APA
Testlify. (2023). General Data Protection Regulation (GDPR). https://testlify.com/hr-glossary/general-data-protection-regulation-gdpr/
- MLA
"General Data Protection Regulation (GDPR)." Testlify, 16 January 2023, https://testlify.com/hr-glossary/general-data-protection-regulation-gdpr/.
- Chicago
Testlify. "General Data Protection Regulation (GDPR)." Testlify. Last modified September 14, 2026. https://testlify.com/hr-glossary/general-data-protection-regulation-gdpr/.
- HTML link
<a href="https://testlify.com/hr-glossary/general-data-protection-regulation-gdpr/">General Data Protection Regulation (GDPR)</a>, Testlify (2023)
Related terms
General agents
General agents (GAs) are individuals or organizations that act as intermediaries between insurance companies and insurance agents or brokers.
General manager
A General Manager (GM) is a high-level executive responsible for a business or organization’s overall operations and performance.
Generation X
Generation X, also known as Gen X, refers to the demographic cohort of individuals born between the mid-1960s and the early-1980s.
Generation Y
Generation Y, also known as Gen Y or the Millennial generation, refers to the demographic cohort of individuals born between the early 1980s and the mid-1990s to early 2000s.
Generation Z
Generation Z, born mid-1990s to mid-2010s, is tech-savvy, politically aware, diverse, and open to mental health discussions.
Genetic-Based Discrimination
Genetic-based discrimination refers to the unfair treatment of individuals based on their genetic makeup, particularly in regards to inherited diseases or risk of developing them.
Get started.
Hire on proof, not resumes.
Run your first skills-based assessment free — no credit card required.