What GDPR is
GDPR — the General Data Protection Regulation — is the EU's data-protection regulation, in force since 25 May 2018. It replaced the 1995 Directive and harmonised data-protection law across the EU and the EEA, so a controller answering to Berlin answers to the same law as one answering to Madrid, Dublin, or Paris. The single keyword is 'personal data': any information relating to an identified or identifiable natural person. Most of what HIPAA calls PHI, what a SOC 2 reviewer calls PII, and what a marketing team calls 'user data' lands inside GDPR's personal-data definition — broadly scoped on purpose, narrower than a marketing database, broader than a clinical record.
Enforcement runs through the national data-protection authorities — the CNIL in France, the BfDI in Germany, the ICO in the UK, the AEPD in Spain, and one in every Member State — each independent of the government it sits alongside. For cross-border processing the European Data Protection Board (EDPB) coordinates a one-stop-shop mechanism: a single lead authority handles the case, the other cooperating authorities contribute, and the resulting decision lands in a single public order rather than twenty parallel ones. Each authority can fine up to the higher of €20 million or 4% of total worldwide annual turnover for the most serious infringements, and the orders are public — the published decisions list the controller, the Article breached, and the fine. The regulator-first framing is the same as OCR under HIPAA: a written policy without the corresponding artifact is the most common finding pattern.
Why a US analyst cares: GDPR is territorial. A US SaaS that targets EU customers, a US publisher that ships cookies into EU visitors, a US AI training pipeline that ingests data about EU residents — all of those land inside GDPR regardless of where the company is incorporated. The Art. 3(2) extra-territorial gate pulls in US-headquartered companies by the offering-goods-or-services and the monitoring-behaviour limbs of the Article. The regulation is now a standing line item on the SOC 2 vendor questionnaire, the BAA review packet, and the privacy-page citing list — a US analyst reading GDPR is reading the document the EU customer, the EU DPA, and the global procurement team will all open.