Regulation · European Union

The global data protection standard.

The world's most comprehensive data protection framework, setting the global standard for privacy rights. Neostra provides end-to-end GDPR compliance with automated data subject rights management, consent tracking and breach response.

2018
Enforcement date
450M+
Citizens protected
€20M
Or 4% global revenue
6
Core data subject rights

What is the GDPR?

The General Data Protection Regulation (GDPR) is the European Union's landmark data protection law that came into effect on 25 May 2018. It harmonises data privacy laws across all EU member states and imposes strict requirements on how organisations collect, process, store and share personal data.

The GDPR has become the de facto global standard for data protection, influencing privacy laws worldwide including India's DPDPA, Brazil's LGPD and California's CCPA.

EUGeneral Data Protection Regulation (EU) 2016/679

Who must comply?

The GDPR has broad extraterritorial reach, applying to any organisation worldwide that processes personal data of EU residents, regardless of where the organisation is headquartered.

  • Any organisation established in the EU or EEA
  • Non-EU companies offering goods or services to EU residents
  • Organisations monitoring the behaviour of EU individuals
  • Both data controllers and data processors
  • Public authorities and government bodies in EU member states
Extraterritorial scope · worldwide
Obligations

What the law requires.

Lawfulness and transparency
Processing must have a valid legal basis (consent, contract, legitimate interest and others) and individuals must be clearly informed about how their data is used.
Purpose limitation
Personal data must be collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes.
Data minimisation
Only collect and process personal data that is adequate, relevant and limited to what is necessary for the stated purpose. No excessive data collection.
Storage limitation
Personal data should be kept in identifiable form only for as long as necessary. Implement retention policies and automated deletion schedules.
Integrity and confidentiality
Ensure appropriate security measures protect personal data against unauthorised access, accidental loss, destruction or damage, through technical and organisational measures.
Accountability
Controllers must demonstrate compliance with GDPR principles. Maintain records of processing activities, conduct DPIAs and implement data protection by design.
Rights

Data subject rights under GDPR

The GDPR establishes comprehensive rights for individuals regarding their personal data.

  1. 1
    Right of access (Art. 15)
    Individuals can obtain confirmation of whether their data is being processed, access to their personal data, and information about how it is used.
  2. 2
    Right to rectification (Art. 16)
    Data subjects can request correction of inaccurate personal data and completion of incomplete data without undue delay.
  3. 3
    Right to erasure (Art. 17)
    Also known as the right to be forgotten. Individuals can request deletion of their personal data when it is no longer necessary or consent is withdrawn.
  4. 4
    Right to data portability (Art. 20)
    Individuals can receive their personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
  5. 5
    Right to object (Art. 21)
    Data subjects can object to processing based on legitimate interests or for direct marketing purposes. Controllers must stop processing unless compelling grounds exist.
  6. 6
    Right to restrict processing (Art. 18)
    Individuals can request restriction of processing when accuracy is contested, processing is unlawful, or data is no longer needed but required for legal claims.
The platform

How Neostra covers GDPR.

The platform automates the complex requirements of the EU's data protection regulation.

Cookie consent management
GDPR-compliant cookie consent banners with granular category controls, prior consent blocking and full audit logs for every consent interaction.
DSAR fulfilment
Automate the entire rights request lifecycle: intake, identity verification, cross-department routing and response delivery within 30 days.
Data mapping and discovery
Discover personal data across databases, cloud storage and SaaS applications. Build Records of Processing Activities required under Article 30.
DPIAs
Conduct Data Protection Impact Assessments for high-risk processing with built-in templates, risk scoring and mitigation tracking, as required under Article 35.
72-hour breach notification
Streamline breach detection, risk assessment and supervisory authority notification within the mandatory 72-hour window under Article 33.
Compliance dashboard
Monitor GDPR posture in real time: DSAR response times, consent rates, RoPA completeness and overall compliance scores.

Run one program across both regimes.

Most Indian companies with EU customers need DPDPA and GDPR at once. One tenant covers both.