The term’s scope varies: privacy regimes often include lawful processing and individual rights, while technical or operational usage may emphasize security, backup, recovery, and loss prevention.
A practical program connects purpose, responsibility, data quality, access, sharing, retention, security, resilience, and accountability. Requirements should be derived from applicable law, contracts, organizational commitments, and the needs and risks of affected people — not from a single control or label.
Key points
Lifecycle rulesDefine why data is collected, who may use or share it, how accuracy is maintained, how long it is kept, and how it is returned, archived, anonymized, or securely deleted.
People and obligationsProvide appropriate transparency, choices, access, correction, objection, or other rights where required, and document responsible decisions about data use.
Protection and recoveryApply proportionate administrative, physical, and technical safeguards, limit unnecessary access and copies, manage processors or suppliers, and prepare for incidents and restoration.
Important limitation“Data protection” has no single jurisdiction-neutral legal definition. Meeting one security standard, encrypting data, or passing an audit does not establish compliance with every applicable privacy or data-protection obligation; qualified legal review is necessary.