Skip to main content
—
Framework library
Framework module · gdpr

GDPR

The EU's baseline for processing personal data — lawful basis, data-subject rights, controller and processor duties, and cross-border transfers.

Regulation (EU) 2016/679 · European Commission — EU data-protection legal framework · published 2016-05-04

Standing today
Directory entry

00Answer

from the registry record
What is GDPR?
The EU's baseline for processing personal data — lawful basis, data-subject rights, controller and processor duties, and cross-border transfers.
Who does GDPR apply to?
GDPR applies to all sectors, EU, EEA, per European Commission — EU data-protection legal framework.
What is the current version of GDPR?
The current edition is Regulation (EU) 2016/679, issued by European Commission — EU data-protection legal framework and published 2016-05-04. Source: https://commission.europa.eu/law/law-topic/data-protection/legal-framework-eu-data-protection_en.
What does an assessment under GDPR require?
No control catalog has been ingested for GDPR yet — the registry tracks it as roadmap (Modeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

GDPR is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Freely published; obligations not modelled as a control catalog.

02Registry record

checked 2026-09-06
Registry status
Roadmap · modelledModeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Lawfulness · Data subject rights · Controller obligations · Security of processing · International transfers
Applies to
all sectors · EU · EEA
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-09-06
Pending change
Regulation (EU) 2025/2518, adopted 2025-11-26 and published 2025-12-12, lays down additional procedural rules for cross-border GDPR enforcement; its main chapters apply 15 months after entry into force (2027-04-02). Confirmed directly against the regulation's own EUR-Lex text. Separately, the Commission's Digital Omnibus (Data track), proposed 2025-11-19, would amend Art. 5(1)(b), add a new Art. 33a single-entry-point breach notification, and add Art. 88a — it remains under Council/Parliament negotiation and is not enacted law at this check.Expected: 2027-04-02 (procedural regulation's main chapters apply)

03Version ledger

1 edition
Regulation (EU) 2016/679Current edition2016-05-04

05Change history

06Related frameworks

scored from registry facts
  1. UK GDPRUK GDPR + DPA 2018, as amended by DUAA 2025 (in force via Commencement No. 6, SI 2026/82)

    Also applies to all sectors · The UK's post-Brexit data protection regime, materially reshaped by the Data (Use and Access) Act 2025 — new recognised legitimate interests, narrower automated-decision protections, and a pausable DSAR clock. The core amending provisions were brought into force by the Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82), effective 2026-02-05.

  2. Also applies to all sectors · Privacy guidance for public-cloud providers acting as processors of personally identifiable information. It complements ISO/IEC 27001 and 27002; it is not a regulation, standalone certification, or claim that ControlFrame is certified.

  3. Texas Data Privacy and Security ActHB 4 (Texas Business and Commerce Code Chapter 541)

    Also applies to all sectors · Texas's comprehensive consumer-privacy statute, pulled out of the generic state-privacy bundle because of its own enforcement record — the Texas AG has reached the two largest single-state privacy settlements in US history — and because TRAIGA now amends it with AI-specific processor duties.

  4. CCPA/CPRA + US state privacyCCPA/CPRA with 2026 CPPA regulations

    Also applies to all sectors · California's consumer privacy regime and the state laws that followed it. The 2026 CPPA regulations add automated decision-making rules, mandatory risk assessments, and certified cybersecurity audits.

GDPR | ControlFrame