Category: GDPR
The General Data Protection Regulation is the EU law governing how personal data may be collected, used, shared and stored. It applies to any organisation processing the personal data of people in the EU, wherever that organisation is based — which is why it reaches far beyond Europe.
Seven principles sit at its core: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. The last is the one that creates most of the work, because accountability means you must be able to demonstrate compliance, not merely achieve it.
In practice that demonstration is documentary. A record of processing activities, privacy notices, a lawful basis for each processing purpose, data processing agreements with every processor, data protection impact assessments for high-risk processing, a breach register and a documented procedure for handling data subject requests within one month.
The guides below cover the principles, the eight data subject rights, what a compliant DPA must contain under Article 28, how to run a gap analysis, the full documentation checklist, and how GDPR interacts with ISO 27701.