What is GPDP? PrivIQ’s General Personal Data Protection framework

GPDP is PrivIQ’s baseline privacy framework for organisations in jurisdictions without dedicated privacy regulation, or where a baseline personal data protection programme is required as a common floor across multiple jurisdictions.
Quick answer

GPDP (General Personal Data Protection) is PrivIQ’s baseline privacy framework for organisations operating in countries without dedicated privacy regulation, or multinationals needing a common floor across jurisdictions. It applies recognised privacy principles – lawful basis, purpose limitation, data minimisation, retention, rights, accountability, breach response – without anchoring to any single regulator’s specific requirements.

Why GPDP exists

Many organisations operate across multiple jurisdictions where the privacy landscape is uneven – some countries have comprehensive privacy laws, others have sectoral regulations, others none at all. A pure ‘one regulation per jurisdiction’ approach is unmanageable. GPDP provides a baseline privacy framework drawn from globally recognised principles (OECD, APEC, GDPR-style essentials) that operates as a common floor – sometimes exceeding local minimums, sometimes sitting beneath specific regulations as a baseline.

What GPDP covers

  • Lawful basis and purpose limitation
  • Data minimisation and accuracy
  • Retention and storage limitation
  • Security and integrity of personal data
  • Rights handling – access, correction, deletion, objection
  • Breach response and incident management
  • Processor oversight
  • Accountability and evidence
  • Stakeholder communications and policy distribution

When to use GPDP

GPDP suits three patterns:

  • Organisations operating in countries without a comprehensive privacy law – typically using GPDP as the primary framework
  • Multinationals needing a common floor across jurisdictions, where GPDP sits beneath the most stringent applicable regulation in any given country
  • Organisations preparing for a privacy law that has been announced but not yet enacted – GPDP gives them a working baseline now

GPDP vs GDPR

GDPR is a binding regulation in the EU and UK. GPDP is a baseline framework, not law. GPDP draws heavily on GDPR’s structure – lawful basis, accountability, breach response, rights – but is operationally lighter, intended as a floor rather than as enterprise-grade EU compliance. Organisations subject to GDPR should run GDPR; GPDP is for the spaces GDPR doesn’t reach.

How PrivIQ supports GPDP

PrivIQ ships a configured GPDP framework with controls, criteria, policies, assessment templates and reporting. The same data map, ROPA and DSAR workflows that support GDPR or POPIA also support GPDP – the difference is in the control structure, not the underlying data.

Key takeaways
  • GPDP is a baseline privacy framework, not a regulation.
  • It suits organisations in jurisdictions without dedicated privacy law, or multinationals needing a common floor.
  • Organisations subject to GDPR or POPIA should run those frameworks – GPDP is for the spaces between.
PrivIQ

PrivIQ helps organisations and consultants put this into practice — with policies, controls, evidence, tasks, registers and reporting that survive audit.

Frequently asked questions

More on Privacy Compliance.

Is GPDP a regulation?

No. It is a framework drawn from globally recognised privacy principles, intended as a baseline where formal regulation is absent or as a common floor across jurisdictions.

Does GPDP replace GDPR or POPIA?

No. Where binding regulation applies, that regulation governs. GPDP is for situations where no binding regulation applies – or where a common baseline is needed across multiple jurisdictions.

Who created GPDP?

GPDP is maintained by PrivIQ as a configurable framework drawing from OECD privacy principles, APEC privacy framework principles, and the essential structure of mature privacy laws like GDPR and POPIA.

Can GPDP be customised?

Yes. Within PrivIQ, GPDP controls and criteria are configurable to organisation, sector and risk profile.

Will GPDP make me compliant with the next privacy law in my country?

It will give you a substantial head start. Most modern privacy laws share a common structure (lawful basis, rights, accountability, breach response). An organisation running GPDP is in materially better shape when a new local law arrives than one starting from zero.

Put this into practice.

Book a meeting, watch a self-guided walkthrough or take the free assessment to see where your programme stands.