GDPR
General Data Protection Regulation. EU privacy law in force since 2018. Establishes user rights (access, rectification, erasure, portability) and obligations on controllers and processors. Identity systems must support data subject requests and granular consent.
GDPR shapes identity architecture more than any other privacy law because its rights map onto identity operations: access and portability require knowing every system holding a user's data, and erasure requires being able to delete it there. Purpose limitation is the one teams underestimate, since an identity graph assembled for authentication cannot be quietly reused for analytics. Consent records, retention windows, and lawful basis belong in the identity design, not bolted on.
See also: consent management, what is CIAM, compliance guides, identity regulations
Related on Start with Identity
- GuideGDPR for identity systems: what the regulation actually requires
GDPR confers user rights (access, rectification, erasure, portability, object). Identity systems are usually where those requests are routed because they hold t
- GlossaryAML
Anti-Money Laundering. The set of regulations and processes used to detect and report suspicious financial activity. AML programs sit on top of KYC and include
- GuideCustomer Identity Verification Guide: KYC, Document Verification, and Fraud Prevention
Implement customer identity verification with KYC processes, document verification, liveness detection, progressive profiling, and fraud prevention strategies.
- GlossaryFedRAMP
Federal Risk and Authorization Management Program. The US government cloud services authorization framework. Levels: Low, Moderate, High. Required for SaaS used
- GlossaryHIPAA
Health Insurance Portability and Accountability Act. US law governing the privacy and security of protected health information. Identity vendors serving healthc
- GuideIAM Audit Preparation Guide: SOX, SOC 2, and HIPAA Readiness
Prepare for identity and access management audits with complete evidence collection, access review documentation, and compliance frameworks for SOX, SOC 2, and