← All terms

GDPR

The GDPR is the EU's data protection law. Its security, training, and 72-hour breach notification duties make employee behavior a compliance matter.

The General Data Protection Regulation (GDPR) is the European Union's data protection law, in force since 25 May 2018. It governs how organizations collect, process, and secure the personal data of people in the EU and EEA, applies to any organization worldwide that processes such data, and carries fines of up to €20 million or 4% of global annual turnover, whichever is higher.

How it works

The GDPR is built on principles — lawfulness, purpose limitation, data minimization, integrity and confidentiality — enforced through concrete obligations. Article 32 requires "appropriate technical and organisational measures" to secure personal data, a phrase regulators consistently read to include trained, security-aware staff. Article 39 makes staff awareness-raising and training an explicit duty of the data protection officer. Article 33 requires notifying the supervisory authority of a personal data breach within 72 hours of becoming aware of it, and Article 34 requires telling affected individuals when the risk is high. Because the regulation defines a breach broadly — including accidental disclosure — a misdirected email, a phishing-harvested mailbox, or personal data pasted into an unapproved AI tool can each trigger the full notification machinery.

How to defend against violations

Most GDPR breaches begin as human error or social engineering, not exotic exploits, which puts workforce behavior at the center of compliance. Practical measures include role-based security awareness training with documented completion (regulators ask for evidence, not intentions), phishing simulations that measure and reduce susceptibility, clear internal reporting paths so the 72-hour clock starts early rather than late, and data handling rules that cover modern leak paths such as shadow AI. Our guide to GDPR and security awareness training covers what the law requires of a training program in detail.

Full guide
Read the deep dive on this attack →

Related terms

NIS2 DirectiveThe NIS2 Directive (EU 2022/2555) is the EU cybersecurity law for 18 critical sectors, mandating risk management, training and 24-hour incident reporting.Digital Operational Resilience Act (DORA)DORA (EU 2022/2554) is the EU regulation making financial entities manage ICT risk — with compulsory security awareness training for all staff and management.Data BreachA data breach is an incident where confidential data is accessed, stolen or exposed by an unauthorized party — most often starting with a human mistake.HIPAAHIPAA sets US rules for protecting health information — including a required security awareness and training program for the entire workforce.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo