The global data protection standard.
The world's most comprehensive data protection framework, setting the global standard for privacy rights. Neostra provides end-to-end GDPR compliance with automated data subject rights management, consent tracking and breach response.
What is the GDPR?
The General Data Protection Regulation (GDPR) is the European Union's landmark data protection law that came into effect on 25 May 2018. It harmonises data privacy laws across all EU member states and imposes strict requirements on how organisations collect, process, store and share personal data.
The GDPR has become the de facto global standard for data protection, influencing privacy laws worldwide including India's DPDPA, Brazil's LGPD and California's CCPA.
Who must comply?
The GDPR has broad extraterritorial reach, applying to any organisation worldwide that processes personal data of EU residents, regardless of where the organisation is headquartered.
- Any organisation established in the EU or EEA
- Non-EU companies offering goods or services to EU residents
- Organisations monitoring the behaviour of EU individuals
- Both data controllers and data processors
- Public authorities and government bodies in EU member states
What the law requires.
Data subject rights under GDPR
The GDPR establishes comprehensive rights for individuals regarding their personal data.
- 1Right of access (Art. 15)Individuals can obtain confirmation of whether their data is being processed, access to their personal data, and information about how it is used.
- 2Right to rectification (Art. 16)Data subjects can request correction of inaccurate personal data and completion of incomplete data without undue delay.
- 3Right to erasure (Art. 17)Also known as the right to be forgotten. Individuals can request deletion of their personal data when it is no longer necessary or consent is withdrawn.
- 4Right to data portability (Art. 20)Individuals can receive their personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
- 5Right to object (Art. 21)Data subjects can object to processing based on legitimate interests or for direct marketing purposes. Controllers must stop processing unless compelling grounds exist.
- 6Right to restrict processing (Art. 18)Individuals can request restriction of processing when accuracy is contested, processing is unlawful, or data is no longer needed but required for legal claims.
How Neostra covers GDPR.
The platform automates the complex requirements of the EU's data protection regulation.
Run one program across both regimes.
Most Indian companies with EU customers need DPDPA and GDPR at once. One tenant covers both.