GDPR
Definition
GDPR is the European Union regulation governing how personal data about people in the EU may be collected, stored and used.
Its practical demands on a software vendor are a lawful basis for processing, a DPA with customers, a published sub-processor list, the ability to export and delete a person’s data, and breach notification. The UK retains an equivalent regime post-Brexit.