What is the GDPR?
The General Data Protection Regulation, usually called the GDPR, is the European Union’s principal law governing the processing of personal data. It is designed to protect individuals’ fundamental rights while creating a consistent data protection framework across Europe. The GDPR has applied since 25 May 2018 and affects how organisations collect, use, share, secure, retain and delete personal data.
The regulation is not only an IT or legal requirement. It affects product design, marketing, human resources, customer support, procurement, security, finance and every other team that handles information relating to an identifiable person. Effective compliance therefore depends on clear ownership, reliable records and repeatable workflows across the organisation.
Who does the GDPR apply to?
The GDPR applies to controllers and processors established in the EU or EEA when they process personal data in the context of their activities. It may also apply to organisations outside Europe when they offer goods or services to people in the EU or EEA, or monitor their behaviour there.
A controller decides why and how personal data is processed. A processor processes personal data on a controller’s behalf. An organisation can act as a controller for some activities and as a processor for others, so roles should be assessed for each processing operation and reflected in contracts and records.
Personal data includes any information relating to an identified or identifiable person. Names and email addresses are obvious examples, but identifiers, location data, online activity, device information and combinations of data may also identify someone. Special-category data, such as health information, biometric data used for identification, political opinions or religious beliefs, receives additional protection. Separate rules also apply to personal data relating to criminal convictions and offences.
The seven GDPR principles
The principles form the foundation of every GDPR obligation. Organisations must follow them and be able to demonstrate that they do so.
- Lawfulness, fairness and transparency: process data on a valid legal basis, treat people fairly and explain processing clearly.
- Purpose limitation: collect data for specified, explicit and legitimate purposes, and do not reuse it incompatibly.
- Data minimisation: limit personal data to what is adequate, relevant and necessary.
- Accuracy: keep personal data accurate and correct or delete inaccurate information without delay.
- Storage limitation: retain identifiable personal data only for as long as necessary.
- Integrity and confidentiality: use appropriate technical and organisational measures to protect data.
- Accountability: take responsibility for compliance and maintain evidence of decisions, controls and outcomes.
Lawful bases for processing
Most processing requires one of six lawful bases. The appropriate basis depends on the purpose and context and should be selected before processing begins.
- Consent: the person gives a freely given, specific, informed and unambiguous indication of agreement.
- Contract: processing is necessary to perform a contract with the person or take requested pre-contractual steps.
- Legal obligation: processing is necessary to comply with a legal duty.
- Vital interests: processing is necessary to protect someone’s life.
- Public task: processing is necessary for a task in the public interest or the exercise of official authority.
- Legitimate interests: processing is necessary for a legitimate interest unless the person’s interests, rights or freedoms override it.
The lawful basis influences transparency information, retention, individual rights and how the processing should be documented. Special-category data normally requires both an Article 6 lawful basis and a separate Article 9 condition.
Key GDPR obligations for organisations
Provide clear and accessible information
People should understand who is processing their data, why it is being used, the lawful basis, who receives it, how long it is retained, whether it is transferred internationally, and how they can exercise their rights. Privacy notices should be concise, easy to find and kept aligned with actual processing.
Maintain records of processing activities
Records of processing activities, commonly called a RoPA, create an operational inventory of processing across the organisation. Depending on the organisation’s role, records may include purposes, categories of individuals and personal data, recipients, international transfers, retention periods and security measures. Even where a limited exemption may apply, reliable records are often essential for accountability, risk management and responding to regulators or individuals.
Apply data protection by design and by default
Privacy should be considered when systems, products and processes are first planned—not added after launch. Default settings should limit collection, access, use, retention and disclosure to what is necessary for each purpose. Decisions should be documented throughout the lifecycle.
Manage processors, vendors and contracts
Controllers must use processors that provide sufficient guarantees and must put required contractual terms in place. Organisations should assess vendors before onboarding, understand data locations and subprocessors, control access, monitor changes and keep evidence of due diligence. Roles and responsibilities between controllers, joint controllers and processors should be clearly documented.
Protect personal data
Security measures should be appropriate to the risk and may include access controls, encryption or pseudonymisation, resilience, backups, monitoring, testing, incident response and staff training. The correct measures depend on the nature, scope, context and purposes of processing, as well as the potential impact on individuals.
Complete DPIAs for high-risk processing
A Data Protection Impact Assessment is required before processing that is likely to result in a high risk to people’s rights and freedoms. A DPIA should describe the planned processing, assess necessity and proportionality, identify risks and document measures to reduce them. It should be treated as a living assessment and reviewed when the processing or risk changes.
Appoint a Data Protection Officer when required
A DPO is required in certain circumstances, including where a public authority or body processes data, where core activities involve regular and systematic monitoring on a large scale, or where core activities involve large-scale processing of special-category or criminal-offence data. The DPO must be able to perform the role independently and receive appropriate access, resources and support.
Control international data transfers
Transfers of personal data outside the EEA require a valid transfer mechanism unless the destination benefits from an adequacy decision. Depending on the transfer, organisations may need contractual safeguards, a transfer impact assessment and supplementary technical or organisational measures.
Prepare for personal data breaches
Organisations should be able to detect, contain, assess and document security incidents involving personal data. A controller must notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a breach, unless it is unlikely to result in a risk to individuals. When a breach is likely to result in a high risk, affected people may also need to be informed without undue delay.
Data subject rights under the GDPR
The GDPR gives individuals meaningful control over their personal data. Rights include:
- the right to be informed about processing;
- the right of access to personal data and related information;
- the right to correct inaccurate or incomplete data;
- the right to erasure in applicable circumstances;
- the right to restrict processing;
- the right to data portability where the legal conditions are met;
- the right to object to certain processing, including direct marketing; and
- rights relating to decisions based solely on automated processing, including profiling.
Requests generally need to be handled without undue delay and within one month, although the period may be extended for complex or numerous requests when the individual is informed. Teams need a secure process for intake, identity verification, searching connected systems, coordinating responses, recording decisions and meeting deadlines.
GDPR enforcement and fines
Supervisory authorities have investigative and corrective powers, including warnings, reprimands, processing restrictions and administrative fines. The highest fine tier can reach €20 million or 4% of total worldwide annual turnover from the preceding financial year, whichever is higher. A lower tier of up to €10 million or 2% may apply to other infringements. The actual response depends on factors such as severity, duration, intent, mitigation, cooperation and previous infringements.
Financial penalties are only one risk. Poor privacy practices can also lead to operational disruption, claims, contract issues and loss of customer or employee trust.
A practical GDPR compliance checklist
- Assign clear ownership across privacy, legal, security, engineering, procurement and business teams.
- Map systems, vendors, data assets and personal-data flows.
- Maintain an accurate RoPA connected to real operational information.
- Document lawful bases, purposes, retention periods and transparency requirements.
- Review privacy notices and consent or preference mechanisms.
- Embed privacy reviews and DPIAs into project and vendor onboarding workflows.
- Put appropriate processor and international-transfer safeguards in place.
- Maintain a tested process for data subject requests and identity verification.
- Implement proportionate security, breach response and escalation procedures.
- Train relevant teams and keep evidence of reviews, approvals, risks and remediation.
- Monitor business and regulatory changes and update the programme continuously.
How TrustWorks supports GDPR operations
TrustWorks helps privacy teams convert policy requirements into connected operational workflows. Rather than maintaining separate spreadsheets, inboxes and documents, organisations can manage evidence, ownership and collaboration in one platform.
- Data mapping and discovery: identify internal systems, third-party tools, data assets and processing locations to improve visibility over personal-data flows.
- Processing activities and RoPA: maintain structured records, collaborate with business teams and identify missing or outdated information.
- DPIAs and privacy assessments: use centralised workflows, templates, intelligent surveys and risk mapping to assess new and changing processing.
- Data subject requests: consolidate intake channels, track deadlines, support identity checks and coordinate fulfilment across teams and systems.
- Vendor and risk oversight: connect vendor information, assessments and risks so privacy teams can prioritise action and maintain evidence.
- Cross-functional collaboration: assign owners, request input, document decisions and maintain an audit-ready history of privacy work.
TrustWorks supports the management of GDPR compliance workflows. It does not provide legal advice, and organisations should assess their specific obligations with qualified counsel and reference applicable regulator guidance.









