Home > Glossary > CCSP > General Data Protection Regulation (GDPR)

📖 What is General Data Protection Regulation (GDPR)?

General Data Protection Regulation (GDPR) is a comprehensive data privacy law in the European Union that regulates how the personal data of EU citizens is collected, processed, and stored. It grants individuals significant control over their data and imposes strict penalties for non-compliance.

🥋 Sensei Says:

"For the CCSP, remember that GDPR applies to any organization handling EU citizen data, regardless of where the organization is physically located."

📚 Certification: CCSP (CCSP)

🔑 What are the Key Concepts of General Data Protection Regulation (GDPR)?

  • Extraterritorial Application: GDPR applies to any organization processing the personal data of EU residents, regardless of where the organization is physically headquartered or located.
  • Data Controller vs. Processor: The Controller determines the purpose of data processing, while the Processor (often the CSP) processes data based on the Controller's instructions.
  • Data Subject Rights: Individuals possess specific legal rights, including the right to be forgotten (erasure), the right to data portability, and the right of access.
  • Privacy by Design and Default: This requires that data protection is integrated into the system architecture from the start and that only necessary data is collected.
  • Breach Notification Timeline: Organizations must notify the relevant supervisory authority of a personal data breach within 72 hours of becoming aware of the incident.

🎯 How does General Data Protection Regulation (GDPR) appear on the CCSP Exam?

You may be asked to distinguish between the roles of a cloud customer and a cloud service provider, identifying who acts as the Data Controller and who is the Data Processor.

A scenario might describe a user requesting that all their personal information be permanently deleted from a cloud environment; you must identify this as the 'Right to Erasure'.

Expect questions regarding the legal requirements for transferring EU personal data to a non-EU cloud region, focusing on 'adequacy decisions' or the use of Standard Contractual Clauses.

❓ Frequently Asked Questions

What is the primary difference between a Data Controller and a Data Processor in a cloud context?

The Controller defines the 'why' and 'how' of data processing. The Processor, typically the Cloud Service Provider, provides the technical means to execute those instructions. Liability and obligations differ significantly between these two roles.


How does the 'Right to Portability' specifically impact cloud architecture?

It requires that data be provided in a structured, commonly used, and machine-readable format. For cloud architects, this means avoiding proprietary formats that lock data in, ensuring customers can move their data between providers.

Related Terms from CCSP

📝 Related Study Guides

Comparison 8 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

Choose CISSP if you want broad technical security expertise across eight domains, including cryptography, network security, and software development. Choose CISM if you're focused on information security management, governance, and risk management from a leadership perspective. CISSP is ideal for hands-on security architects, while CISM is designed for security managers and directors.

Career Guide 9 min read

The IT Certification Roadmap: Where to Start in 2026

Start your IT certification journey in 2026 with CompTIA A+ for general IT foundations, then branch into networking (Network+), cybersecurity (Security+), or cloud computing (AWS Cloud Practitioner or Azure Fundamentals) based on your career goals. Each path leads to advanced certifications like CISSP, AWS Solutions Architect, or CISM within 2-3 years of focused progression.

Comparison 10 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

The CISSP is a broad, technical-to-managerial certification focusing on security operations and architecture across eight domains. In contrast, CISM is a specialized management certification centered on governance, risk management, and program development. Choose CISSP for comprehensive security expertise and CISM if you are pivoting specifically into security leadership and governance roles.

🧠

Test Your Knowledge

Think you understand General Data Protection Regulation (GDPR)? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium