SOC 2 Type II
SOC 2General Data Protection Regulation
EU Regulation 2016/679 requiring appropriate technical and organisational safeguards for personal data, with direct implications for data residency and datacenter location decisions.
Full Definition
The General Data Protection Regulation (GDPR) came into force on 25 May 2018, replacing the EU Data Protection Directive 95/46/EC. It applies to any organisation processing personal data of EU/EEA residents regardless of where the organisation is established. Key obligations include: lawful basis for processing; data subject rights (access, erasure, portability); privacy by design and by default; data protection impact assessments (DPIAs); 72-hour breach notification; and cross-border transfer restrictions.
For datacentre operators and customers, GDPR creates direct requirements around data residency — EU personal data may only be transferred to third countries with adequate protections (adequacy decisions, Standard Contractual Clauses, or Binding Corporate Rules). This drives procurement decisions about which facilities and cloud regions can legally host regulated workloads. UK GDPR (post-Brexit) mirrors EU GDPR with minor variations. Fines can reach €20 million or 4% of global annual turnover, making compliance a board-level commercial risk.
Also Known As
Source Reference
Regulation (EU) 2016/679 of the European Parliament and of the Council