Quick answerGPDP (General Personal Data Protection) is PrivIQ’s baseline privacy framework for organisations operating in countries without dedicated privacy regulation, or multinationals needing a common floor across jurisdictions. It applies recognised privacy principles – lawful basis, purpose limitation, data minimisation, retention, rights, accountability, breach response – without anchoring to any single regulator’s specific requirements.
Why GPDP exists
Many organisations operate across multiple jurisdictions where the privacy landscape is uneven – some countries have comprehensive privacy laws, others have sectoral regulations, others none at all. A pure ‘one regulation per jurisdiction’ approach is unmanageable. GPDP provides a baseline privacy framework drawn from globally recognised principles (OECD, APEC, GDPR-style essentials) that operates as a common floor – sometimes exceeding local minimums, sometimes sitting beneath specific regulations as a baseline.
What GPDP covers
- Lawful basis and purpose limitation
- Data minimisation and accuracy
- Retention and storage limitation
- Security and integrity of personal data
- Rights handling – access, correction, deletion, objection
- Breach response and incident management
- Processor oversight
- Accountability and evidence
- Stakeholder communications and policy distribution
When to use GPDP
GPDP suits three patterns:
- Organisations operating in countries without a comprehensive privacy law – typically using GPDP as the primary framework
- Multinationals needing a common floor across jurisdictions, where GPDP sits beneath the most stringent applicable regulation in any given country
- Organisations preparing for a privacy law that has been announced but not yet enacted – GPDP gives them a working baseline now
GPDP vs GDPR
GDPR is a binding regulation in the EU and UK. GPDP is a baseline framework, not law. GPDP draws heavily on GDPR’s structure – lawful basis, accountability, breach response, rights – but is operationally lighter, intended as a floor rather than as enterprise-grade EU compliance. Organisations subject to GDPR should run GDPR; GPDP is for the spaces GDPR doesn’t reach.
How PrivIQ supports GPDP
PrivIQ ships a configured GPDP framework with controls, criteria, policies, assessment templates and reporting. The same data map, ROPA and DSAR workflows that support GDPR or POPIA also support GPDP – the difference is in the control structure, not the underlying data.
- GPDP is a baseline privacy framework, not a regulation.
- It suits organisations in jurisdictions without dedicated privacy law, or multinationals needing a common floor.
- Organisations subject to GDPR or POPIA should run those frameworks – GPDP is for the spaces between.
PrivIQ helps organisations and consultants put this into practice — with policies, controls, evidence, tasks, registers and reporting that survive audit.
More on Privacy Compliance.
Is GPDP a regulation?
No. It is a framework drawn from globally recognised privacy principles, intended as a baseline where formal regulation is absent or as a common floor across jurisdictions.
Does GPDP replace GDPR or POPIA?
No. Where binding regulation applies, that regulation governs. GPDP is for situations where no binding regulation applies – or where a common baseline is needed across multiple jurisdictions.
Who created GPDP?
GPDP is maintained by PrivIQ as a configurable framework drawing from OECD privacy principles, APEC privacy framework principles, and the essential structure of mature privacy laws like GDPR and POPIA.
Can GPDP be customised?
Yes. Within PrivIQ, GPDP controls and criteria are configurable to organisation, sector and risk profile.
Will GPDP make me compliant with the next privacy law in my country?
It will give you a substantial head start. Most modern privacy laws share a common structure (lawful basis, rights, accountability, breach response). An organisation running GPDP is in materially better shape when a new local law arrives than one starting from zero.