General Data Protection Regulation (EU) 2016/679
The General Data Protection Regulation (GDPR) is a legal framework that sets guidelines for the collection and processing of personal information from individuals in the European Union. It exists to protect the fundamental privacy rights of EU citizens and to unify data protection laws across Europe.
Who it applies to
- Organizations established within the European Union (EU) or European Economic Area (EEA).
- Non-EU organizations that offer goods or services, whether paid or free, to individuals located in the EU/EEA.
- Non-EU organizations that monitor the behavior of individuals taking place within the EU/EEA.
- Third-party vendors (data processors) who handle personal data on behalf of a primary organization (data controller).
How it works
The GDPR is based on a set of core principles, including lawfulness, fairness, transparency, purpose limitation, and data minimization. It grants individuals specific rights over their data, such as the right to access, the right to be forgotten, and the right to data portability. Organizations must identify a valid legal basis—such as consent or legitimate interest—before processing any personal data.
Compliance is not achieved through a single government-issued certificate but through ongoing governance. Organizations demonstrate compliance by maintaining detailed documentation of their data activities, conducting Data Protection Impact Assessments (DPIAs) for high-risk processing, and appointing a Data Protection Officer (DPO) when required.
Enforcement is handled by national Data Protection Authorities (DPAs). These bodies have the power to investigate complaints, conduct audits, and issue administrative fines for non-compliance based on the severity of the infringement.
Getting started
- Perform a data discovery audit to identify what personal data is collected, where it is stored, and who has access to it.
- Create a Record of Processing Activities (ROPA) to document the purpose and legal basis for every data processing operation.
- Update privacy notices to ensure they are written in plain language and clearly explain how data is used.
- Establish a formal internal process for receiving and responding to Data Subject Access Requests (DSARs) within the statutory timeframe.
- Review contracts with third-party service providers to ensure mandatory Data Processing Agreements (DPAs) are in place.
Controls & requirements
- Art. 6 Lawful basis for processing
- Art. 7 Consent
- Ch. 3 Data subject rights and DSARs
- Art. 17 The right to erasure ('right to be forgotten')
- Art. 33 Personal data breach notification
- Art. 35 Data Protection Impact Assessments
- Art. 37 The Data Protection Officer
- Art. 30 Records of processing activities
- Ch. 5 International data transfers
- Art. 25 Data protection by design and by default
Common misconceptions
- It only applies to companies physically located in Europe; in reality, it has extraterritorial reach and applies to any entity targeting EU residents.
- Consent is the only way to legally process data; however, there are six lawful bases for processing, including contractual necessity and legal obligation.
- GDPR prohibits all data transfers outside the EU; instead, it allows them provided specific safeguards, such as Standard Contractual Clauses (SCCs), are implemented.