GDPR is a regulation you comply with, not a certificate you earn. It governs the processing of the personal data of people in the EU and EEA, and it turns on a set of core building blocks: the seven principles in Article 5 (lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and — the one that ties it together — accountability), the six lawful bases in Article 6, and a strong bill of data-subject rights in Articles 15–22 (access, rectification, erasure, restriction, portability and objection).
It draws a sharp line between the controller (who decides why and how personal data is processed) and the processor (who processes on the controller's documented instructions), and it places concrete obligations on both: a Record of Processing Activities (Article 30), appropriate technical and organisational security measures (Article 32), a data-protection impact assessment for high-risk processing (Article 35), and a Data Protection Officer where Articles 37–39 require one. A personal-data breach must be notified to the supervisory authority within 72 hours (Article 33) and, where the risk to individuals is high, to the affected individuals too (Article 34).
It applies extraterritorially under Article 3 — to any organisation offering goods or services to, or monitoring the behaviour of, people in the EU, wherever that organisation is established. Transfers of personal data outside the EU are only allowed under the safeguards in Articles 44–49, most commonly an adequacy decision or the European Commission's Standard Contractual Clauses (SCCs) backed by a transfer impact assessment.