GDPR on Azure
Implement the technical measures required by GDPR on Azure — data residency, encryption at rest and in transit, right to erasure, and breach notification.
What Is GDPR?
The General Data Protection Regulation (GDPR) is a European Union regulation that governs how personal data of EU residents must be collected, stored, processed, and protected. It applies to any organisation worldwide that processes the personal data of people in the EU — not just companies based in Europe. GDPR violations can result in fines of up to €20 million or 4% of global annual revenue, whichever is higher.
Key GDPR Principles
GDPR is built on six data protection principles that must be applied to all personal data processing:
- Lawfulness, fairness, and transparency — have a legal basis for processing
- Purpose limitation — collect data only for specified purposes
- Data minimisation — collect only what is necessary
- Accuracy — keep data up to date
- Storage limitation — delete data when no longer needed
- Integrity and confidentiality — secure data against unauthorised access