Glossary · Compliance and data protection

GDPR

GDPR is the General Data Protection Regulation, the EU and UK data-protection framework that governs how personal data is collected, processed, shared and protected.

Full definition

GDPR is defined as: GDPR is the General Data Protection Regulation, the EU and UK data-protection framework that governs how personal data is collected, processed, shared and protected.

GDPR sets out lawful bases for processing personal data, gives individuals rights over their data and requires organisations to demonstrate accountability through documentation, policies and technical controls.

In supplier relationships GDPR most commonly surfaces as the requirement for a data processing agreement whenever the supplier handles personal data on your behalf, and as the trigger for a DPIA where processing is likely to be high-risk.

Questions and answers

Put it into practice

Manage gdpr in Credbase.

Credbase brings every supplier document into one workspace, tracks expiry dates for you and turns the whole set into a shareable evidence pack. Free to start, no card required.