GDPR
European regulation governing the processing of personal data, with extraterritorial reach and substantial penalties.
It applies to organizations outside Europe that offer goods or services to people in the EU or monitor their behavior, which catches many US businesses that assume it does not apply to them.
Beyond security, it grants individuals rights over their data including access, correction, and erasure, and those rights require a process to answer rather than a technology to buy.
Where this comes up
GDPR sits inside our compliance and frameworks work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.