General Data Protection Regulation (GDPR)
A Practical Overview
1. What Is GDPR?
The General Data Protection Regulation (GDPR) is an EU law that governs how personal data
is collected, used, stored, and shared. It came into force on 25 May 2018 and applies across all
EU member states.
Its main goal is to:
• Protect individuals’ personal data
• Give people more control over how their data is used
• Hold organizations accountable for data protection
GDPR applies even to companies outside the EU if they process data of people located in the
EU.
2. What Counts as Personal Data?
Personal data is any information that can identify a person, directly or indirectly.
Examples:
• Name, email address, phone number
• IP addresses
• Location data
• ID numbers
• Online identifiers (cookies, device IDs)
Special category (sensitive) data includes:
• Health data
• Biometric data
• Racial or ethnic origin
• Political opinions
• Religious beliefs
Sensitive data has stricter rules.
3. Who Must Comply?
GDPR applies to:
• Businesses and organizations in the EU
• Non-EU companies that:
o Offer goods or services to people in the EU, or
o Monitor behavior of people in the EU (e.g., tracking, analytics)
This includes:
• Websites
• Apps
• SaaS platforms
• Marketing companies
• Employers
4. Core GDPR Principles
Organizations must follow these key principles:
1. Lawfulness, fairness, and transparency
Data must be processed legally and clearly explained to users.
2. Purpose limitation
Collect data only for specific, legitimate purposes.
3. Data minimization
Collect only what is necessary.
4. Accuracy
Keep data correct and up to date.
5. Storage limitation
Do not keep data longer than needed.
6. Integrity and confidentiality
Protect data with appropriate security.
7. Accountability
Be able to prove compliance.
5. Legal Bases for Processing Data
You must have a valid legal reason to process personal data. Common bases include:
• Consent (freely given, informed, and revocable)
• Contract (necessary to fulfill a contract)
• Legal obligation
• Legitimate interests (balanced against individual rights)
Consent must be:
• Explicit
• Easy to withdraw
• Not bundled or forced
6. Rights of Individuals (Data Subjects)
GDPR gives people strong rights, including:
• Right to access their data
• Right to rectification (fix incorrect data)
• Right to erasure (“right to be forgotten”)
• Right to restrict processing
• Right to data portability
• Right to object
• Rights related to automated decision-making
Organizations generally have one month to respond to requests.
7. Data Breaches
A personal data breach is a security incident that leads to accidental or unlawful access, loss, or
disclosure of data.
If a breach occurs:
• Notify the supervisory authority within 72 hours
• Notify affected individuals if there is high risk
• Document the breach internally
8. Penalties for Non-Compliance
GDPR fines can be severe:
• Up to €20 million, or
• 4% of global annual turnover (whichever is higher)
Authorities may also issue:
• Warnings
• Audits
• Processing bans
9. Practical Compliance Steps
To comply with GDPR, organizations should:
• Maintain a privacy policy
• Map data flows and processing activities
• Minimize data collection
• Secure systems and access controls
• Train staff
• Use GDPR-compliant vendors
• Appoint a Data Protection Officer (DPO) if required
10. Disclaimer
This document is for general informational purposes only and does not constitute legal
advice. GDPR compliance requirements may vary depending on jurisdiction, industry, and
specific use cases. Always consult a qualified legal professional for advice.
Next steps
If you want, I can:
• Turn this into a designed PDF (cover page, icons, layout)
• Shorten it into a 1-page executive summary
• Make a GDPR checklist
• Tailor it for websites, startups, HR, or SaaS
• Add cookie consent & privacy policy sections
Just tell me what version you want 😄