TERM · SECURITY

GDPR

What is GDPR?

GDPR, the General Data Protection Regulation, is the European law that sets out how organisations may collect, store and use personal data about people in the EU. It covers a contact form, a mailing list, a CRM and a shop’s order history alike. It gives people the right to see, correct and delete their data, and it requires a lawful basis before anything is collected.

Example

An online shop takes a name, an address and a phone number with every order, and offers a newsletter tick box. Order data is processed because the contract needs it; the newsletter runs on consent, so the box starts empty and is logged separately. The two bases carry different retention: accounting records stay for the period the law sets, a newsletter address stays until the person unsubscribes.

A year later the customer asks to be deleted. The shop removes the address from the list but not the invoice, which is held on another basis. The answer goes back in writing within a month, and that is where an orderly process shows against a disorderly one.

Why it matters for a business

GDPR asks for order rather than software. The core of it can be listed: a record of processing activities, a lawful basis behind every collection, retention periods, contracts with the suppliers who see the data, and a plan for a breach — the supervisory authority informed within 72 hours where people are at risk. A data protection officer is required in defined cases, such as large-scale systematic monitoring; an ordinary shop rarely falls inside them, but the reasoning is written down.

Fines reach €20 million or 4% of worldwide annual turnover, whichever is higher. The commoner damage is duller: an advertising account suspended, trust lost, hours spent answering complaints. Consent for subscriber lists is covered under email marketing.

What to ask

  • Which forms on the site collect data, and on what basis?
  • Which outside providers see that data, and is there a contract with each?
  • How long is each kind of record kept, and who deletes it?
  • How is an access or deletion request handled, and within what time?
  • Who is responsible in a breach, and what happens in the first 72 hours?

Forms, access rights and the privacy notice are settled alongside the site itself during website development.

A term you do not recognise? Write to us and we will add it.

The glossary grows with the questions we are asked.