The General Data Protection Regulation (GDPR) is a comprehensive legal framework that governs the collection, processing, and storage of personal data belonging to individuals within the European Union and the European Economic Area. Although the UK has left the European Union it has retained the GDPR as the UK GDPR.
The GDPR gives people greater control over their personal data, replacing outdated laws that were designed before the internet was widely used, or social media existed. By standardising data protection rules across borders, the regulation provides a consistent legal baseline for core privacy rights.
The GDPR is made up of many elements which come together to create a comprehensive data protection framework.

Modern technology has increased the value of personal data dramatically. The ability to target advertisements, make personalised recommendations and monitor people in both the real and digital worlds have created multi-trillion dollar industries. Although there are penalties for non-compliance the main aim of the GDPR is to:
- help people control how their data are used
- ensure organisations use personal data lawfully, fairly and transparently
- push organisations to implement appropriate data security measures
Beyond the threat of significant financial penalties for non-compliance, there are severe risks to an organisation’s reputation and customer trust. Effectively managing data privacy is a critical indicator of organisational maturity and a competitive advantage. In short:
- GDPR is not simply about avoiding fines
- good data protection builds trust
- privacy and governance are business-critical functions
At its core the GDPR sets out:
- core privacy principles
- broad standards for data security that go beyond cybersecurity only
- lawful routes for collecting and processing personal data
- people’s data rights
- additional protections for sensitive data, like medical records
- special protections for children
- how organisations who share data should manage that relationship
- what to do if there is a breach of the GDPR (which we usually refer to as a data breach).
Organisations are accountable for demonstrating ongoing GDPR compliance. That is why most organisations you will deal with have privacy statements or policies on their websites, and routes for you to exercise data rights like making a subject access request.
The GDPR deliberately makes data protection an operational matter and not a one-off activity such as redesigning IT systems. This means it has to be considered in everything and organisation does. In effect organisations must maintain a constant vigilance over their collection, use and storage or personal data in a similar way to their oversight of their financial systems. Just as there are rules about who can access, collect and spend money, the same kind of rules should be in place for personal data.
As noted above there are financial and reputational costs to data breaches and GDPR non-compliance. Since the GDPR came into force in 2018 organisations have become highly risk averse when it comes to these costs.
The GDPR does not sit in isolation. It affects, and is affected by, legislation such as:
- the Freedom of Information Act
- the Privacy and Electronic Communications Regulations
- the Computer Misuse Act
- emerging regulations around artificial intelligence
- the Data Use and Access Act