GDPR is the primary EU regulation governing the protection of personal data. It applies to any organisation processing data of EU residents, regardless of where the organisation is located.
Key requirements include lawful basis for processing, data subject rights (access, rectification, deletion), data protection impact assessments, and breach notification within 72 hours.