# What is Data Protection?

> Data protection is the coordinated governance and handling of data throughout its lifecycle so it is used for authorized purposes, safeguarded from harm, kept appropriately accurate and available, and retained or disposed of as required.

- Canonical URL: https://yellowcube.eu/glossary/data-protection/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The term’s scope varies: privacy regimes often include lawful processing and individual rights, while technical or operational usage may emphasize security, backup, recovery, and loss prevention.

A practical program connects purpose, responsibility, data quality, access, sharing, retention, security, resilience, and accountability. Requirements should be derived from applicable law, contracts, organizational commitments, and the needs and risks of affected people — not from a single control or label.

### Key points

- **Lifecycle rules:** Define why data is collected, who may use or share it, how accuracy is maintained, how long it is kept, and how it is returned, archived, anonymized, or securely deleted.
- **People and obligations:** Provide appropriate transparency, choices, access, correction, objection, or other rights where required, and document responsible decisions about data use.
- **Protection and recovery:** Apply proportionate administrative, physical, and technical safeguards, limit unnecessary access and copies, manage processors or suppliers, and prepare for incidents and restoration.
- **Important limitation:** “Data protection” has no single jurisdiction-neutral legal definition. Meeting one security standard, encrypting data, or passing an audit does not establish compliance with every applicable privacy or data-protection obligation; qualified legal review is necessary.

### Related terms

[Data privacy](<https://yellowcube.eu/glossary/data-privacy/>) · [Data security](<https://yellowcube.eu/glossary/data-security/>) · [Data governance](<https://yellowcube.eu/glossary/data-governance/>) · [General Data Protection Regulation (GDPR) security](<https://yellowcube.eu/glossary/general-data-protection-regulation-security/>) · [Data classification](<https://yellowcube.eu/glossary/data-classification/>) · [Digital rights management (DRM)](<https://yellowcube.eu/glossary/digital-rights-management/>)

### Sources

[OECD Guidelines Governing the Protection of Privacy and Transborder Flows of Personal Data](https://legalinstruments.oecd.org/public/doc/114/body-text.en.html) · [European Data Protection Board: Data Protection Basics](https://www.edpb.europa.eu/sme/learn-the-basics/data-protection-basics_en) · [NIST Privacy Framework 1.0](https://csrc.nist.gov/pubs/cswp/10/nist-privacy-framework-version-10/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

