Data protection

General Data Protection Regulation

Regulation (EU) 2016/679 European Union Applicable since 25 May 2018

Published Reviewed

What is GDPR?

GDPR governs how organisations collect, use, retain, secure and disclose personal data, with enforceable rights for people and accountability duties for controllers and processors.

At a glance
JurisdictionEuropean Union
AuthorityRegulation (EU) 2016/679
Current statusApplicable since 25 May 2018
Reviewed

Why it matters operationally

GDPR reaches any organisation that offers goods or services to people in the EU or monitors their behaviour — establishment in Europe is not required. Enforcement is mature: the two fine tiers reach €20 million or 4% of worldwide annual turnover, whichever is higher, and single decisions have exceeded €1 billion. The operational burden sits in the everyday record: knowing what you process, why, on which lawful basis, for how long — and being able to prove it the day a regulator or enterprise customer asks.

Are you aware?

The dates that bind

25 May 2018

Applicable in full — no phase-in remains

Every obligation, from records of processing (Article 30) to data-subject rights deadlines, is live law. New processing starts compliant or non-compliant on day one.

72 hours

The breach clock runs over weekends

A notifiable personal-data breach must reach the supervisory authority within 72 hours of awareness (Article 33). High-risk breaches also go to the affected individuals without undue delay (Article 34).

1 month

A data-subject request is a deadline

Access, erasure and portability requests must generally be answered within one month (Article 12(3)) — and the clock starts when the request arrives, not when someone notices it.

Where to start

  1. 1

    Map every processing activity to a purpose, a lawful basis and a retention period — this becomes the Article 30 record a regulator asks for first.

  2. 2

    Decide controller or processor for each activity, and put the matching Article 28 terms into every supplier contract that touches personal data.

  3. 3

    Rehearse the two clocks — the 72-hour breach path and the one-month rights-request path — each with a named owner and out-of-hours coverage.

Authority links

Read the official sources

The official text is the authority. This guide is only a short orientation for operational planning.

Common questions

Frequently asked questions

Does GDPR apply to organisations outside the EU?

Often, yes. Article 3 extends it to organisations anywhere that offer goods or services to people in the EU or monitor their behaviour. A webshop shipping to Berlin, or an analytics tag profiling EU visitors, is enough to be in scope.

How high can fines actually go?

Two tiers: up to €10 million or 2% of worldwide annual turnover for duties such as security and records, and up to €20 million or 4% for violations of the principles, lawful bases and data-subject rights — whichever is higher. Authorities have used the upper tier repeatedly, including single fines above €1 billion.

Do we need a Data Protection Officer?

Required for public authorities, and for organisations whose core activities involve large-scale regular and systematic monitoring or large-scale special-category data (Article 37). Many organisations outside those cases still appoint one to anchor accountability.

What is the difference between a controller and a processor?

The controller decides why and how personal data is processed; the processor acts on the controller’s documented instructions. The role determines your duties, your contracts and who answers to the regulator — and it is decided per activity, not per company.

Side by side

Operational deep dives

Work through the decision, not just the definition.

Key terms in this guide

A quick self-check

Are you ready?

  • Could you produce your record of processing activities today — current, complete and dated?
  • Do you know your retention policy for every category of personal data, and is it actually enforced anywhere?
  • If a breach were discovered on Friday evening, who starts the 72-hour clock, and what is their first step?
  • Which suppliers process personal data on your behalf — and does each one have Article 28 terms in place?

Every question above has a written, evidence-backed answer in a well-run compliance record. If one made you pause, that pause is the gap.

This guide is general information about public law, not legal advice, and does not create a client relationship. Rules change and apply differently by situation. Verify the current official source and seek qualified advice where needed.