Define minimum requirements for securing systems, protecting personal data, managing access, responding to incidents, and complying with data protection obligations.