Skip to content
Live12+ production solutions40+ clients deployeddirect + partner
Glossary · Compliance & Data

What is GDPR?

The EU's data-protection regulation — establishes consent, purpose-limitation, residency, breach-notification, and the data-subject rights regime.

Also known as

general data protection regulationeu gdpruk gdpr
Definition

GDPR — explained.

GDPR (General Data Protection Regulation, Regulation (EU) 2016/679) is the European Union's data-protection regulation, in force since 25 May 2018. It governs the processing of personal data of EU residents regardless of where the processor is located, with extra-territorial reach. The UK retains a near-identical regime as the 'UK GDPR' post-Brexit. The core principles: lawful basis for processing (consent, contract, legal obligation, vital interest, public task, or legitimate interest); purpose limitation (use data only for the stated purpose); data minimisation (collect no more than needed); accuracy; storage limitation (retain no longer than needed); integrity / confidentiality (security); accountability (be able to demonstrate compliance). The data-subject rights regime gives EU residents the right to access, rectify, delete (right to erasure), restrict processing, object, and data portability. Operators must respond to data-subject requests within one month. Breach notification to the supervisory authority is required within 72 hours of awareness. Fines are up to €20m or 4% of global annual revenue. The Schrems II ruling (2020) tightened residency by ruling that personal data transfers to the US under Privacy Shield are unlawful unless additional safeguards apply, which drove most EU controllers toward EU-only cloud regions or on-prem.

Why it matters

Why operators care about gdpr.

For any software touching EU resident data, GDPR is the baseline compliance regime — not an add-on. Practically: every Zeour deployment ships GDPR-ready primitives (consent, purpose, retention, subject-rights workflows, breach logging) and the admin includes a GDPR data-subject delete tool out of the box.

Solutions where gdpr applies

Zeour solutions that operate on this layer.

MediCare Clinic

medicare · clinic · management · system

Zeour MediCare — the multilingual on-premise clinic and EMR management system for small-to-mid healthcare practices. Covers patients (records, allergies, conditions, medications, body diagrams), appointments + visits with SOAP notes, prescriptions with drug-interaction checks, lab orders + samples + results, billing + payments + invoicing, inventory, expenses, referrals, medical certificates, refill requests, patient communications, telemedicine (WebRTC), an AI clinical assistant (OpenAI-powered with 7 modes), a patient self-service portal, and a full role-based access model across Admin, Doctor, Reception, and Lab Tech roles. Engineered multilingual — (with full RTL) as the production baseline, extensible to any locale — and runs locally on a single server.

See the solution

Self-Service Kiosks

digital · self · service · kiosk

Zeour builds bespoke self-service kiosks end-to-end — software and hardware engineered together for the exact service you need to digitize. Self-payment kiosks (utilities, fines, fees, tuition, taxes), self-ordering for restaurants and QSR, charity donation kiosks, airport taxi-booking kiosks, telecom SIM-dispenser kiosks, bank self-service (cash deposit / withdrawal / cheque), KYC kiosks with passport / national ID / face match / fingerprint, tender-participation kiosks for government procurement, utility payment kiosks, government self-service citizen portals, restaurant self-ordering + POS integration, and more. Every deployment is custom-fitted to your operation; every kiosk integrates with your existing systems; every transaction is auditable.

See the solution
Related terms

Adjacent definitions to read next.

PDPL

Compliance & Data

Personal Data Protection Law — the data-protection regime in Saudi Arabia (and equivalents in the UAE and several Gulf states).

Data Residency

Sovereign Deployment

A requirement that personal or regulated data is stored, processed, and backed up within a defined jurisdiction — usually a country or a treaty bloc.

Sovereign Deployment

Sovereign Deployment

Software that runs entirely inside the operator's perimeter — their hardware, their network, their backups, their keys — with no third-party dependency for continued operation.

HIPAA

Compliance & Data

The US healthcare-data-protection law governing Protected Health Information (PHI) — covers privacy, security, breach notification, and business-associate agreements.

PCI DSS

Compliance & Data

The Payment Card Industry Data Security Standard — the security baseline that any system handling card data must meet.

CCPA / CPRA

Compliance & Data

California's data-protection law — and the CPRA amendment in force since 2023 — establishing data-subject rights for California residents.

Cyber Essentials

Compliance & Data

The UK NCSC's baseline cybersecurity certification — a five-control posture (firewalls, secure config, access control, malware, patches) increasingly required for UK government contracts.

Data Subject Access Request (DSAR)

Compliance & Data

The data-subject's right to request a copy of all personal data an operator holds about them, plus deletion, correction and processing-restriction rights — under GDPR, PDPL and equivalent laws.

Want to discuss gdpr for your operation?

Talk to a Zeour engineer.

A 30-minute scoping call to walk your operational profile against where gdpr actually sits in your stack, then a fixed-fee Discovery price by the end of the call.