Overview
The General Data Protection Regulation (GDPR) is a comprehensive dataprivacy law that came into effect across the European Union (EU) on May25,2018. It replaces the 1995 Data Protection Directive and sets a uniform legal framework for the processing of personal data of individuals residing in the EU, irrespective of where the data controller or processor is located.
Key objectives of the GDPR are to give individuals more control over their personal information, to simplify the regulatory environment for international business, and to strengthen and unify dataprotection measures throughout the EU.
Core Principles
The GDPR is built on six fundamental principles that all dataprocessing activities must respect:
- Lawfulness, fairness and transparency: Processing must have a valid legal basis, be fair to the data subject, and be explained in clear language.
- Purpose limitation: Data may only be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
- Data minimisation: Only the minimum amount of personal data necessary for the intended purpose should be collected.
- Accuracy: Personal data must be accurate and kept uptodate; inaccuracies must be corrected without delay.
- Storage limitation: Data should be retained only for as long as necessary for the purpose it was collected.
- Integrity and confidentiality: Appropriate security measures must protect data against unauthorised or unlawful processing, accidental loss, destruction, or damage.
Data Subject Rights
Individuals (data subjects) enjoy a set of enforceable rights under the GDPR:
- Right of access: Obtain confirmation that personal data is being processed and receive a copy of that data.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure (right to be forgotten): Request deletion of personal data when it is no longer needed, consent is withdrawn, or processing is unlawful.
- Right to restriction of processing: Limit how data is used while a dispute is resolved.
- Right to data portability: Receive personal data in a structured, commonly used format and transmit it to another controller.
- Right to object: Object to processing based on legitimate interests, direct marketing, or profiling.
- Rights concerning automated decisionmaking: Request human review of decisions made solely by automated means that have legal or similarly significant effects.
Controller & Processor Obligations
Both data controllers (who determine the purposes and means of processing) and data processors (who process data on behalf of controllers) have specific duties:
Data Protection Officer (DPO)
Public authorities, organisations that engage in largescale systematic monitoring, or those that process special categories of data must appoint a DPO to oversee compliance.
Lawful Basis for Processing
Processing must be based on at least one of the following grounds:
- Consent
- Performance of a contract
- Legal obligation
- Vital interests
- Public task
- Legitimate interests (balanced against the rights of the data subject)
Data Protection Impact Assessment (DPIA)
When processing is likely to result in a high risk to individuals rights and freedoms, a DPIA must be conducted to identify, assess, and mitigate risks.
Recordkeeping
Controllers and processors must maintain detailed records of processing activities, including purpose, categories of data, recipients, and retention periods.
Security Measures
Appropriate technical and organisational safeguardssuch as encryption, pseudonymisation, access controls, and regular testingmust be implemented.
Data Breach Notification
Data breaches must be reported to the relevant supervisory authority within 72hours of discovery, unless the breach is unlikely to result in a risk to individuals. Affected data subjects must be informed when the breach is likely to result in a high risk to their rights and freedoms.
International Transfers
Transfers of personal data outside the EU/EEA are permissible only when an adequate level of protection is ensured, through mechanisms such as:
- European Commission adequacy decisions
- Standard Contractual Clauses (SCCs)
- Binding Corporate Rules (BCRs)
- Specific derogations (e.g., explicit consent)
Compliance Checklist
| Area | Action Required | Status |
|---|---|---|
| Legal Basis | Document the lawful basis for each processing activity. | |
| Transparency | Update privacy notices to be concise, clear, and easily accessible. | |
| Data Subject Rights | Implement procedures to handle access, rectification, erasure, and portability requests within 30days. | |
| DPIA | Conduct DPIAs for highrisk processing (e.g., largescale profiling). | |
| Records of Processing | Maintain uptodate logs of processing activities (Article30). | |
| Security | Apply encryption, access controls, and regular security testing. | |
| Data Breach Plan | Establish a breach response plan and train staff on notification timelines. | |
| International Transfers | Verify adequacy mechanisms or update contracts with SCCs/BCRs. | |
| DPO | Appoint a Data Protection Officer where required and publish contact details. |
