GDPR (General Data Protection Regulation)

Also known as: Regulation (EU) 2016/679, General Data Protection Regulation

GDPR (Regulation (EU) 2016/679) is the European Union regulation governing the processing of personal data of individuals in the EU. For telecom operators, GDPR applies alongside the ePrivacy rules and covers subscriber identifiers (IMSI, MSISDN, IMEI), location data, CDRs and any other information that can identify a person, requiring lawful basis, data minimisation, breach notification within 72 hours and rights of access, rectification and erasure.

Categories: Identity and SubscriberCloud and VirtualizationRegulation and Compliance

GDPR in context

Subscriber identifiers (IMSI, SUPI, MSISDN, IMEI) anchor authentication, charging and lawful interception. Any protocol that leaks a permanent identifier is treated as a privacy defect, which is why 5G introduced SUCI concealment on the air interface.

Moving network functions off dedicated hardware into NFV, Kubernetes and Open RAN reshapes the threat model. Isolation now depends on hypervisor, container and service-mesh controls plus image and Helm-chart supply-chain security.

To place GDPR in the wider telecom-security picture, review CSPM, Data Retention, 2G, AAA, ADSL and AKA — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.