The General Data Protection Regulation (GDPR) is a European Union law, in force since 2018, that governs how organizations collect, process, and protect the personal data of people in the EU.
GDPR applies to any organization handling the data of EU residents, no matter where the company itself is based, which gives it global reach. It grants individuals rights such as access, correction, erasure (the right to be forgotten), and data portability. It also requires a lawful basis for processing, breach notification to the supervisory authority (generally within 72 hours), and, for some organizations, a designated Data Protection Officer.
A US company selling to EU customers still falls under GDPR, and fines can reach a share of global annual revenue, so the regulation is treated as a board-level risk. A common exam trap is confusing the roles. The data controller decides why and how personal data is processed, while the processor acts on the controller’s instructions. Both carry legal obligations, and a weak contract between them is a frequent gap.
How is GDPR tested on the CISSP?
GDPR appears in Domain 1, Security and Risk Management, under legal, regulatory, and privacy requirements. Questions focus on scope, individual rights, and breach timelines rather than legal minutiae. Review it within Domain 1 Security and Risk Management.