Start with Identity
← Glossary
Compliance

GDPR

General Data Protection Regulation. EU privacy law in force since 2018. Establishes user rights (access, rectification, erasure, portability) and obligations on controllers and processors. Identity systems must support data subject requests and granular consent.

GDPR shapes identity architecture more than any other privacy law because its rights map onto identity operations: access and portability require knowing every system holding a user's data, and erasure requires being able to delete it there. Purpose limitation is the one teams underestimate, since an identity graph assembled for authentication cannot be quietly reused for analytics. Consent records, retention windows, and lawful basis belong in the identity design, not bolted on.

See also: consent management, what is CIAM, compliance guides, identity regulations

Last reviewed By SWI Community TeamSuggest a correctionHow we research