What is the GDPR?
The General Data Protection Regulation, or GDPR, is the European Union’s principal regulation governing the processing of personal data. It establishes principles, individual rights and obligations for controllers and processors. It also addresses security, accountability, data-protection officers, impact assessments, international transfers and regulatory enforcement.
The GDPR can apply to organisations established in the European Economic Area and, in defined circumstances, organisations elsewhere that offer goods or services to people in the EEA or monitor their behaviour. The official regulation is available on EUR-Lex.
What are the main GDPR principles?
The principles include lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. These principles apply across the lifecycle and should shape product design, operations and governance.
Compliance is not achieved through a privacy notice alone. The organisation should ensure that actual systems, contracts, access, retention and decisions align with the stated purposes and legal bases.
What rights does the GDPR provide?
Individuals may have rights of access, rectification, erasure, restriction, portability and objection, as well as rights connected to automated decision-making. The right available depends on the legal basis and circumstances, and rights can be subject to lawful limitations.
Organisations need accessible intake channels, proportionate identity verification and coordinated workflows across systems and processors. Responses should be clear and delivered within applicable deadlines.
How is GDPR compliance managed?
A mature programme includes records of processing, data mapping, lawful-basis assessments, notices, retention, security, vendor contracts, transfer safeguards, incident response and privacy impact assessments. Responsibilities should be assigned to business owners and supported by privacy, legal, security and data teams.
The GDPR requires risk-based judgement. Higher-risk processing needs stronger assessment, evidence and oversight. National law and sector requirements may add further obligations, so specific legal advice may be necessary.
Frequently asked questions
Does the GDPR apply only to EU companies?
No. It can apply to organisations outside the EEA when defined territorial conditions are met.
Is consent required for all processing?
No. Consent is one lawful basis. Contract, legal obligation, legitimate interests and other bases may apply depending on the activity.
What is personal data under the GDPR?
It is information relating to an identified or identifiable natural person, including direct, indirect, online and inferred identifiers.
Can GDPR fines be imposed for a data breach?
Potentially, but enforcement considers the underlying obligations, response, safeguards, harm and other circumstances rather than the existence of an incident alone.
Does GDPR compliance require appointing a DPO?
Only when the legal conditions are met, although organisations may appoint one voluntarily if the role’s requirements are respected.



