The General Data Protection Regulation (GDPR) is a comprehensive legal framework that governs the collection, processing, and storage of personal data belonging to individuals within the European Union and the European Economic Area. Although the UK has left the European Union it has retained the GDPR as the UK GDPR.
The GDPR gives people greater control over their personal, replacing outdated laws that were designed before the internet was widely used, or social medica existed. By standardising data protection rules across borders, the regulation provides a consistent legal baseline for core privacy rights.
The scope of the GDPR is very broad. It applies to:
- any organisation that processes the personal data of people in countries that have adopted the GDPR, regardless of where the organisation is based.
- anything that by itself or in combination with other data could be used to identify someone. It goes beyond direct identifiers like name or reference numbers.
Modern technology has increased the value of personal data dramatically. The ability to target advertisements, make personalised recommendations and monitor people in both the real and digital worlds have created multi-trillion dollar industries. Although there are penalties for non-compliance the main aim of the GDPR is to:
- help people control how their data are used
- ensure organisations use personal data lawfully, fairly and transparently
- push organisations to implement appropriate data security measures
Beyond the threat of significant financial penalties for non-compliance, there are severe risks to an organisation’s reputation and customer trust. Effectively managing data privacy is a critical indicator of organisational maturity and a competitive advantage. In short:
- GDPR is not simply about avoiding fines
- good data protection builds trust
- privacy and governance are business-critical functions

What Is the GDPR?
The GDPR is a single, Europe-wide framework of rules that is the same across the countries that have adopted it. Other articles on this site go into more detail about specific GDPR provisions but at its core it sets out:
- core privacy principles
- broad standards for data security that go beyond cybersecurity only
- lawful routes for collecting and processing personal data
- people’s data rights
- additional protections for sensitive data, like medical records
- special protections for children
- how organisations who share data should manage that relationship
- what to do if there is a breach of the GDPR (which we usually refer to as a data breach).
It is important to understand that the GDPR applies to all personal data, whether in electronic form or in hard copy, and sets expectations for organisational culture and not just IT.
The exceptions to the GDPR are:
- data processed for purely personal purposes – your family photos are not covered by the GDPR
- deceased people – the GDPR only applies to living people
- anonymous data – the GDPR covers only personal data so aggregate data or data with no personal identifiers is outside the GDPR’s scope.
Why the GDPR Matters
Organisations are accountable for demonstrating ongoing GDPR compliance. That is why most organisations you will deal with have privacy statements or policies on their websites, and routes for you to exercise data rights like making a subject access request.
The GDPR deliberately makes data protection an operational matter and not a one off activity such as redesigning IT systems. This means it has to be considered in everything and organisation does. In effect organisations must maintain a constant vigilance over their collection, use and storage or personal data in a similar way to their oversight of their financial systems. Just as there are rules about who can access, collect and spend money, the same kind of rules should be in place for personal data.
As noted above there are financial and reputational costs to data breaches and GDPR non-compliance. Since the GDPR came into force in 2018 organisations have become highly risk averse when it comes to these costs.
Finally, the GDPR does not sit in isolation. If affects, and is affected by, legislation such as:
- the Freedom of Information Act
- the Privacy and Electronic Communications Regulations
- the Computer Misuse Act
- emerging regulations around artificial intelligence
- the Data Use and Access Act
The Core Principles of the GDPR
The GDPR is built around seven core principles that govern how organisations collect, use, store, and share personal data.
These principles are not simply legal requirements. They are the foundation of good information governance and should shape every decision an organisation makes about personal data.
The first six principles describe how personal data should be handled. The seventh principle, accountability, requires organisations to demonstrate that they are complying with the other six.
Together these principles create a framework that helps organisations process personal data lawfully, fairly, securely, and responsibly.
Lawfulness, fairness and transparency
All data processing must be covered by at least one of the lawful bases discussed below. If processing data organisations must be fair by only processing data in a way that people would understand and expect. As part of this they must be open about what data they collect and why (see also the right to be informed, below).
Purpose limitation
Organisations can only process personal data for the things, or purposes, they collected it for. This means it is very important for organisations to understand what data they need any why, as otherwise they cannot comply with this principle and therefore the wider GDPR.
Data minimisation
Organisations should only collect the personal data they need for any particular activity. That doesn’t mean they should avoid collecting personal data, but that they should only collect enough to achieve the outcome they need and no more than that.
Accuracy
The GDPR requires organisations to ensure personal data is accurate and up to date. This means some organisations need to regularly review and update the personal data they have to ensure it is still valid.
Storage limitation
This principle requires organisations to delete or destroy data they no longer need. Retaining data indefinitely increase the likelihood and consequence of a data breach, but also raises costs. The GDPR does allow for data archiving in some circumstances and data can be retained if personal identifiers are removed, making it fully anonymous.
Integrity and confidentiality
Any organisation processing personal data must ensure it is kept safe and secure. That means putting in place appropriate measures to prevent a data breach.
The GDPR requires both technical and organisational measures. This means physical or electronic security is not enough. Organisations must train their staff and have a culture that respects privacy and corrects poor behaviour.
Accountability
As noted above organisations are subject to a further principle: the principle of accountability. This holds organisations accountable for demonstrating compliance with these principles. That means organisations that process personal data must be able to show they are actively meeting the GDPR’s standards. It is not enough to assume you are compliant because you have not had a (known) data breach.
Special Category Data
The GDPR recognises that some types of personal data present greater risks to individuals if they are misused, disclosed, or processed inappropriately.
These categories of information are known as special category data and receive additional legal protections.
Special category data includes information relating to:
- health
- racial or ethnic origin
- religious or philosophical beliefs
- political opinions
- trade union membership
- genetic data
- biometric data used for identification
- sexual orientation
- sex life
Because of the potential impact on people’s privacy, organisations cannot usually process this information using only a standard lawful basis.
Instead, they must identify:
- A lawful basis under Article 6 of the GDPR; and
- An additional condition permitting the processing of special category data.
Examples include:
- providing healthcare
- safeguarding activities
- fulfilling employment law obligations
- obtaining explicit consent
Organisations processing special category data should apply enhanced safeguards, stronger access controls, and more rigorous oversight because the consequences of misuse are often significantly higher than for ordinary personal data.
Lawful Bases for Processing
All processing of personal data requires a lawful basis. Six core lawful bases set out by the GDPR cover data processing, although certain classes of sensitive data require an additional lawful basis as well. Later legislation added a seventh lawful basis that is also discussed below. Organisations should take care when deciding what lawful basis to rely on as people’s GDPR rights operate differently depending on what that lawful basis is.
Consent
Consent is a lawful basis for processing personal data most people have heard of. It is a good lawful basis if the data processing can be stopped without any harm to either the data subject or the company. Signing up to and unsubscribing from a newsletter is a good example.
It must be as easy to withdraw consent as it is to give it, and where consent is given organisations should keep a record of it as the GDPR expects consent to be given by positive action – ticking the “yes” box for example.
Organisations often over-rely on consent as a lawful basis or assume it is the default lawful basis for data processing. Sometimes organisations mistakenly believe that the data privacy principles set out above do not apply if consent is relied on. In fact consent is no better or worse than any other lawful basis and is only suitable for some limited data processing activities.
Contract
The GDPR allows processing of personal data to enter into or deliver a contract. Examples of contracts requiring the processing of personal data include:
- Employment contracts. Employers need to process personal data to consider if they should offer someone an employment contract, and to fulfil it if they do e.g. processing financial data to pay salaries.
- Delivery of good ordered online. Online retailers will need to process address information to fulfil the contract to provide good bought.
Legal obligation
Sometimes organisations have a statutory duty to collect and process certain types of personal information. For example, employers have a statutory duty to ensure their employees are legally entitled to work in the UK. This requires the processing of certain types of identity data.
Vital interests
In exceptional circumstances the GDPR recognises processing personal data may be necessary to protect someone from serious harm. If this is the case it can be done under the vital interests lawful basis. This can apply even if the personal data being processed is not that of the person at risk.
An example of processing under the vital interests lawful basis is an employer sharing medical information about an employee with the emergency services if that employee suffers an accident or other medical episode at work.
Public task
Also known as the public authority basis this lawful basis generally enables public sector organisations to process personal data to deliver their duties. For example, te NHS will process personal data to deliver medical care. The NHS has a statutory duty to provide care but cannot do so effectively without processing personal data.
Legitimate interests
Unless an organisation can rely on the public task lawful basis, legitimate interests can be another way to process personal data legally. For this lawful basis to be valid organisations must be able to:
- Identify the legitimate interests that require data processing
- Demonstrate that the personal data processing does not unduly invade someone’s privacy.
The legitimate interest does not have to be that of the person whose data are being processed. Legitimate interests can be a good lawful basis for marketing activity. For example, if someone has bought from your organisation before marketing additional products or services is in your legitimate interests and does not involve excessive or unwarranted data processing.
Recognised legitimate interests
This seventh lawful basis was added by the Data Use and Access Act. It is similar to legitimate interests but removes the need for the legitimate interests test set out above for certain highly specific activities. These include:
- safeguarding
- crime prevention, and
- public safety
Individual Rights Under the GDPR
The GDPR lists eight core rights everyone has to help them control their personal data and how it is used. Some of these are not new, while others are created by the GDPR for the first time. As noted above how these rights work depends on the lawful basis you are using to process personal data. It should also be noted these rights can often be exercised verbally – although you may need to obtain proof of a person’s identity before acting.
Right to be informed
People have the right to know how their data are being used. This links directly to the first privacy principle, set out above, around data processing being lawful fair and transparent.
This must be explained to people at the point their data are collected or as soon as possible thereafter, which is partly why websites like this have a privacy statement setting this information out.
Right of access
The right of access allows people to see a copy of the information organisations have about them and supplementary information such as the lawful basis for collecting and processing it. Accessing this right is often called making a subject access request.
There are limits to and exclusions from this right. For example, people are not entitled to the data of other people so this will usually be redacted. Certain things like confidential references are also excluded. If an appropriate professional like a doctor or social worker decides that releasing personal information would create a risk of harm then that information can also be withheld.
Requests can also be refused if they are manifestly unfounded or excessive. For example, a trade union could encourage members to make simultaneous requests of an employer purely to cause a burden on them, or people could make repeated requests despite their information not changing.
Information must be disclosed after a reasonable or proportionate search within 30 days of the request being received (or three months if the request is exceptionally complex) and this should be free of charge.
Right to rectification
People can ask to have their data complete or changed if it is incomplete or inaccurate. This right is limited because people cannot change data simply because they disagree with it. However, they can add their own views in a supplementary statement. If the organisation that has received the request for rectification has shared the relevant data with other organisations, it must also ask them to make the necessary changes too.
Right to erasure
The right to erasure, or right to be forgotten, is a right people can exercise in some circumstances to have their personal data deleted. This right has limits, primarily in relation to the lawful basis used to process the personal data.
If someone withdraws consent to their data processing then there is often no reason not to delete it. Conversely if you have a legal obligation to process the data then you cannot comply with the request.
Other exemptions include refusing the request because you need to retain the data to initiate or defend yourself against legal action.
If you receive a request for erasure of personal data and you have made the data public you are still expected to delete the data where possible.
As with the right to rectification if the organisation that has received the request for rectification has shared the relevant data with other organisations, it must also ask them to delete the data as well.
Right to restrict processing
Under some circumstances people have the right to restrict the processing of their personal data. This right can be exercised generally if:
- the data subject is contesting the accuracy of the information
- the data controller wants to delete the data but the data subject wants them to retain it
- if the data subject is challenging the legitimate interest is that is the lawfu basis for data processing.
Organisations can retain the data but not use it unless there are public interest reasons to do so, or to initiate or protect themselves from legal action. No other processing is allowed without explicit consent.
Organisations must have systems in place to ensure that, when someone exercises this right, a person’s data cannot be accessed or processed inappropriately. If any data subject to restriction is published then where possible it must be removed from the public domain. If the data controller has shared the data subject to restriction it must inform any data recipients of the restriction.
Right to Data Portability
This right allows individuals to obtain and reuse their personal data for their own purposes across different services. It is designed to give users more control over their information and to prevent “vendor lock-in” by making it easier to switch between service providers.
Individuals can receive their personal data in a structured, commonly used, and machine-readable format (such as a CSV or JSON file) to store for personal use. They can also request that the data be transmitted directly from one organisation to another, where technically feasible.
The right only applies under specific conditions:
- Data provided by the user: It relates to personal data that the individual has “provided to” a controller (including data observed about them, like usage history or search activities).
- Automated processing: It only applies to data processed by automated means (it does not cover paper-based files).
- Legal basis: The processing must be based on consent or the performance of a contract.
Organisations are not required to adopt compatible systems with other organisations, but they should avoid putting legal, technical, or financial obstacles in the way of a requested transfer.
In practice, this right simplifies the process of switching service providers (such as moving from one bank or social media platform to another) by ensuring that the data you have built up within a service is not trapped behind proprietary technical barriers.
Right to Object
This right can be exercised in two circumstances, the first of which is one of the few absolute rights under GDPR.
- Direct Marketing
Anyone has an absolute right to object to the use of their data for direct marketing. The organisation must stop processing the data for this purpose immediately upon receiving the objection. An organisation cannot refuse this type of request and should not invite the person to reconsider or explain.
- Public Interest, Official Authority, or Legitimate Interests
In other scenarios, the right to object is not absolute. This applies when processing is based on:
- Tasks carried out in the public interest.
- The exercise of official authority.
- The legitimate interests of the organisation or a third party.
In these cases, an individual can object on grounds relating to their “particular situation.” The organisation must stop processing unless it can demonstrate the need for the processing that override the individual’s interests, rights, and freedoms.
An organisation may continue processing despite a valid objection if it is necessary for:
- The establishment, exercise, or defence of legal claims.
- Certain scientific, historical, or statistical research purposes (where the processing is necessary for a public interest task).
Automated Decision Making and Profiling
With the emergence and adoption of AI in fields like recruitment and policing this right is becoming increasingly important. This right is designed to ensure that individuals are not subjected to decisions that have significant effects on them, such as credit approval, job screening, or insurance premiums, based solely on automated processing without human intervention.
Under the GDPR, individuals have the right not to be subject to a decision based solely on automated processing (including profiling) which produces legal effects or similarly significant effects concerning them. Exceptions are:
- It is necessary for entering into, or the performance of, a contract.
- It is authorised by law (such as for tax or fraud prevention).
- The individual has provided explicit consent.
The Safeguards
Even when one of the exceptions above applies, the organisation must implement suitable safeguards to protect the individual’s rights. At a minimum, these must include:
- A Right to Human Intervention: The individual must be able to ask for a human to review the decision.
- The Right to Express a View: The individual must have the opportunity to state their position.
- A Right to Contest the Decision: The individual must have the ability to challenge the outcome.
Transparency Requirements
Organizations must provide “meaningful information about the logic involved” in the automated decision. They must explain:
- The significance and the envisaged consequences of such processing for the individual.
- The reasoning behind why this type of processing is being used.
Important Restrictions
If the decision is based on sensitive data (e.g., health, race, or political opinions), automated decision making is generally prohibited unless the individual gives explicit consent or the processing is based on substantial public interest, and suitable measures are in place to protect the individual’s rights.
The GDPR also offers additional protection, generally discouraging the use of automated decision making that could significantly affect children.
Accountability and Organisational Responsibilities
One of the most important concepts within the GDPR is accountability.
Accountability means organisations must not only comply with the GDPR, but also be able to demonstrate that they comply.
This represents a significant shift from older approaches to data protection. It is no longer sufficient to assume compliance because no complaints have been received or no data breaches have occurred. Organisations must actively manage privacy risks and maintain evidence that appropriate controls are operating.
In practice, accountability requires organisations to establish suitable governance arrangements, documentation, oversight mechanisms, and assurance processes.
Governance and Ownership
Data protection should be treated as an organisational governance issue rather than solely an IT or legal responsibility.
Although specialist advice may be provided by legal teams, information governance teams, or Data Protection Officers, responsibility for compliance ultimately sits with organisational leadership.
Effective governance arrangements typically include:
- clearly defined responsibilities
- senior leadership oversight
- reporting and escalation processes
- periodic compliance reviews
- monitoring and assurance activity
Privacy considerations should be incorporated into decision-making, procurement, project management, system design, and operational processes.
Core Organisational Requirements
Depending on the nature and scale of processing activities, organisations may need to:
- maintain privacy notices
- document lawful bases for processing
- maintain records of processing activities
- undertake Data Protection Impact Assessments (DPIAs)
- manage data sharing arrangements
- oversee third-party processors
- maintain appropriate security controls
- manage data breaches effectively
- provide staff training
The exact requirements will vary depending on the organisation’s size, complexity, and risk profile, but every organisation processing personal data must be able to demonstrate that privacy has been considered and appropriately managed.
Data Protection Officers
Some organisations are legally required to appoint a Data Protection Officer (DPO), while others choose to do so voluntarily.
A DPO provides independent advice, supports compliance activities, and acts as a point of contact for both data subjects and regulators.
Where a DPO is not required, organisations should still ensure they have access to appropriate expertise and clearly allocate responsibility for data protection compliance.
Data Security and Personal Data Breaches
As set out in the privacy principles the GDPR expects organisations to keep personal data safe and secure. There are many ways that organisations can use to achieve this including:
- organisational measures such as policies, procedures and training
- technical measures such as access controls, encryption and cybersecurity
If these measures fail then organisations will experience data breaches.
What is a data breach?
A data breach is defined as
“A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.”
It is important to understand that this definition goes beyond external threats or malicious action. It can include simply human error.
Examples of data breaches include:
- sending an email containing personal data to the wrong person
- failing to remove remote access rights to people who stop working at your organisation
- continuing to send marketing materials after someone has exercise their right to object.
Handling Data Breaches
When a data breach occurs, speed and structure are essential. While the specific response will depend on the nature of the incident, the following actions are usually key priorities:
- Containment and Recovery
The immediate priority is to stop the breach from spreading or continuing. You must identify the source of the compromise and take active steps to “plug the leak.” This might include shutting down compromised systems, resetting passwords, severing network connections to affected devices, or revoking access for specific users. Once contained, focus on recovery, which means restoring systems from backups or implementing temporary workarounds. This helps to minimise the operational impact and ensure data security is restored.
- Assess Risk and Document the Incident
Once the immediate threat is contained, you must conduct a rapid risk assessment to determine the severity of the breach. Ask: What data was involved? How many people are affected? What are the potential consequences (e.g., identity theft, financial loss, reputational damage)? You must document what happened, when it was discovered, what data was exposed, and what steps you took to mitigate it. This internal record is vital for legal compliance and demonstrating accountability to regulators.
- Determine Notification Requirements
Under the GDPR, you must decide whether to report the breach to the supervisory authority (the ICO in the UK) and, if the risk is high, to the affected individuals.
- To the ICO: You should report a breach within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to individuals’ rights and freedoms.
- To Individuals: If the breach is likely to result in a “high risk” to the people involved, you have a legal duty to inform them without undue delay so they can take steps to protect themselves (such as changing passwords or monitoring for fraud).
International Data Transfers
One important aspect of the GDPR is around international data transfers. These rules exist to ensure the continuity of protection for data even if it is shared cross-border.
In essence international data transfers are only permitted to places with equivalent levels of protection. To ensure this the GDPR requires that any “restricted transfer” of personal data to a third country (or international organisation) must be covered by one of the following mechanisms:
- Adequacy Decisions: the Government can formally recognise that a specific country, territory, or sector provides a level of data protection “essentially equivalent” to that within the EU/UK.
- Appropriate Safeguards: In the absence of an adequacy decision, the organisation sending the data (the “exporter”) must provide legal tools that contractually bind the receiver to GDPR-level standards. Common examples include:
- Standard Contractual Clauses (SCCs) / International Data Transfer Agreement (IDTA): these are standardised, non-negotiable contract templates that mandate compliance with data protection laws.
- Binding Corporate Rules (BCRs): Internal codes of conduct for multinational groups of companies, approved by a regulator, to ensure consistent global privacy standards.
- Exceptions (Derogations): In very specific, limited circumstances (such as obtaining the individual’s explicit consent, fulfilling a contract, or for important reasons of public interest), a transfer may be permitted without formal adequacy or safeguards. However, these are strictly interpreted and generally not suitable for regular, large-scale data flows.
Without these rules, organisations could easily bypass the GDPR’s requirements by outsourcing data processing to countries with weak privacy laws, effectively “exporting” the data to avoid compliance costs.
Organisations must be careful when working with others or subscribing to online services or software that they do not inadvertently allow personal data to cross borders without a relevant enabling mechanism being in place.
A Practical GDPR Compliance Framework
Although the GDPR is a legal framework, compliance is primarily an operational activity.
Most organisations can simplify compliance by viewing it as a continuous cycle rather than a one-off implementation project.
A practical GDPR compliance framework consists of eight steps:
- Understand What Data You Hold
Identify:
- what personal data you collect
- where it comes from
- why it is needed
- where it is stored
- who has access
- Identify Lawful Bases
Document the lawful basis that supports each processing activity and ensure it aligns with the purpose of processing.
- Maintain Records
Create and maintain records of processing activities, privacy notices, policies, and data sharing arrangements.
- Assess Risk
Identify activities involving:
- large volumes of personal data
- vulnerable individuals
- special category data
- automated decision-making
Where necessary, complete a DPIA.
- Implement Controls
Apply appropriate technical and organisational measures to protect personal data.
- Train Staff
Ensure employees understand:
- privacy responsibilities
- incident reporting
- data subject rights
- secure handling of information
- Monitor Compliance
Regularly review:
- policies
- processing activities
- security arrangements
- supplier relationships
- training effectiveness
- Review and Improve
Privacy risks evolve over time.
New technologies, regulatory developments, organisational changes, and emerging threats require ongoing review and continuous improvement.
Effective GDPR compliance should therefore be viewed as an ongoing governance process rather than a fixed destination.
- find further reading and free resources you can adap and use to help implement or improve GDPR compliance here.
Common GDPR Mistakes and Misconceptions
Despite the GDPR being in force since 2018 organisations continue to make similar mistakes or assumptions when it comes to compliance and data protection. Organisations should be careful to avoid them because they make data breaches more likely and raise costs unnecessarily.
We Should Rely on Consent
Consent is only one of several lawful bases and is only appropriate in limited circumstances. Consent is no more important than any other lawful basis and it would be a mistake to default to consent as your go-to lawful basis for data processing.
GDPR Only Applies to Electronic Records
The GDPR applies to records in all formats, both paper and electronic.
GDPR Prevents Data Sharing
The GDPR explicitly recognises data sharing as a key organisational activity and seeks to enable it while respecting and protecting people whose data are being shared. There is a risk of over-compliance if you assume any data processing is not allowed because of the GDPR.
GDPR Does Not Apply to Employees
Employee data is covered by the GDPR in the same way as anyone else’s. Therefore would will need a lawful basis for processing employee data, provide appropriate privacy information to employees, and respect employee data rights.
GDPR only applies to large organisations
The GDPR applies to all organisations. Smaller organisations have slightly lighter compliance requirements, and the GDPR allows compliance efforts to reflect the resource available. However, all organisations however small are covered by the GDPR. There is no need to put in place a large and restrictive bureaucracy, but at a minimum consider the same control and assurance mechanisms you would put in place for financial management.
GDPR implementation is a one-off exercise
Maintaining appropriate standards of data protection is an ongoing process of review and enhancement. New data will be collected and old data destroyed or archived. Employees will start and leave, and new technology will be implemented. New threats will emerge. Organisations must treat GDPR compliance as an ongoing cycle of improvement, review and assurance.
The Role of the ICO
The Information Commissioner’s Office (ICO) serves as the UK’s independent regulatory authority, tasked with upholding information rights in the public interest and promoting openness by public bodies and data privacy for individuals.
The ICO has a dual focus: providing practical support and guidance to help organisations understand their obligations and navigate complex compliance landscapes, while simultaneously acting as an enforcer of regulations and people’s data rights.
The ICO clarifies evolving legal standards, ensuring that data protection remains achievable. However, when standards are ignored or violated, the ICO exercises its authority to launch investigations into suspected breaches.
With significant enforcement powers, the Commissioner can compel organisations to change their practices and, in the most serious cases, impose substantial fines to hold organisations accountable for failing to safeguard the personal information of the public.
More often if a data protection issue arises the ICO will provide advice and support. The ICO will use an organisation’s DPO as their first point of content.
While people have a right to complain to the ICO if they have been the victim of a data breach or an organisation does not comply with their data rights it is expected in the first place people will complain to the relevant organisation to resolve any concerns.
GDPR and Risk Management
One of the best ways of achieving GDPR compliance is to take a risk based approach. By understanding the nature and volume of the data you collect and process you can assess the likelihood and consequence of any data breach and take proportionate steps to mitigate those risks.
Processing personal data poses a number of risks, which GDPR compliance will help ti mitigate. Examples include:
Operational risks
- People clicking on links in phishing or spam emails
- Sending information to the wrong recipient
- Inefficiency arising from difficulty finding information or information being out of date
Financial risks
- Increased costs from excess data collection, retention and storage
- Fines and penalties from data breaches
- Having to spend additional money rectifying poorly designed or implemented systems
Reputational risks
- Poor customer reviews because of errors processing or sharing data
- Data breaches causing negative press coverage
- Lower staff confidence because of a lack of training or procedures
Key Definitions
Key GDPR terms and definitions are set out below:
| Term | Definition |
| anonymisation | The removal of all personal identifiers from data, including anything in the context like dates or locations that makes a person identifiable |
| consent | A lawful basis for data processing where a person agrees to let you collect and process their personal data until they withdraw their consent |
| controller | The person or organisation who decides what personal data is collected and the purposes for the data collection |
| data subject | The person whose personal data are being collected and who is the subject of the data processing
|
| DPIA | A Data Protection Impact Assessment is used to evaluate the risks to data subjects of processing sensitive personal data or high volumes of data |
| lawful basis | The legal mechanism for collecting and processing personal data
|
| personal data | Anything that by itself or in combination with other data could lead to a person being identified. This is not limited to direct identifiers like name |
| processing | The use of personal data to achieve and outcome, such as using medical data to diagnose a condition or financial data to process payroll |
| processor | A person or organisation who processes personal data on behalf of a data controller, and is accountable to the data controller for GDPR compliance |
| pseudonymisation | Removing personal identifiers but assigning each pseudonymised data set a key that allows reidentification later if necessary |
| special category data | Personal data that has special protections under the GDPR and requires an additional lawful basis for processing. Examples include medical data or data relating to religion, ethnicity or political views. |
Conclusion
The GDPR provides a legal framework anyone who processes personal data must abide by. It helps organisations develop the appropriate systems for responsible data governance and implements an ongoing compliance regime, GDOR compliance builds trust and confidence while holding data controllers and processors to account for safe and respectful persona data protection.
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: