Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

GDPR compliance explained - the seven principles, lawful bases, data subject rights and duties

GDPR Explained: A Complete Compliance Guide

GDPR compliance is a legal requirement for almost any organization that handles the personal data of people in the EU — and a genuine driver of customer trust. The General Data Protection Regulation set a global benchmark for privacy, and getting it right protects you from serious fines while signalling that you handle data responsibly. This guide is your complete introduction to GDPR and how to comply.

GDPR compliance explained - the seven principles, lawful bases, data subject rights and duties

Below we cover what the GDPR is, who it applies to, its seven principles, the six lawful bases, data subject rights, your core obligations, international transfers, penalties, how the UK regime differs, and a practical path to compliance.

What is the GDPR?

The General Data Protection Regulation (Regulation (EU) 2016/679) is the EU’s comprehensive data protection law, applicable since 25 May 2018. It governs how organizations collect, use, store, and share the personal data of individuals — any information relating to an identified or identifiable person. Because it is a regulation rather than a directive, it applies directly across every member state without needing national implementing law, and its influence has shaped privacy regimes worldwide.

Two definitions do most of the work. Personal data is broader than most people expect: it covers names and email addresses, but also IP addresses, cookie identifiers, device IDs, location data, and any pseudonymised record that could be re-linked to a person. Processing is broader still — it means virtually anything you do with data, including collecting, storing, viewing, sharing, and deleting it. If you hold a spreadsheet of customer emails and never touch it, you are still processing personal data.

A subset called special category data (Article 9) attracts stricter rules: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic and biometric data used for identification, health data, and data about sex life or sexual orientation. Processing it requires both a lawful basis under Article 6 and a separate condition under Article 9.

Who does GDPR apply to?

The GDPR has broad, extraterritorial reach. It applies to any organization established in the EU that processes personal data, and — under Article 3(2) — to organizations outside the EU that either offer goods or services to people in the EU, or monitor their behaviour. A company anywhere in the world can be in scope simply by serving European customers or running analytics that track EU visitors.

The regulation distinguishes between controllers, who decide why and how data is processed, and processors, who process data on a controller’s behalf. Most businesses are controllers for their own customer and employee data, and processors when they handle data for clients. SaaS vendors are typically processors; their customers are controllers. The distinction matters because the two roles carry different duties, and contracts between them are mandatory.

Non-EU controllers caught by Article 3(2) usually also need to appoint a representative in the EU under Article 27 — a named contact point in a member state where the affected individuals are located. This obligation is widely overlooked by non-European businesses that otherwise take compliance seriously.

The 7 principles of GDPR

Article 5 sets out seven principles that govern all processing. They are not abstract ideals — regulators assess real cases against them, and the final principle makes you responsible for proving the other six.

Principle What it requires in practice
Lawfulness, fairness and transparency Have a valid lawful basis, do not use data in ways people would find unexpected or misleading, and tell them clearly what you do in a privacy notice.
Purpose limitation Collect data for specified, explicit purposes and do not repurpose it later for something incompatible without a fresh basis.
Data minimisation Collect only what you actually need. Optional form fields “in case they are useful later” are a classic failure.
Accuracy Keep data correct and up to date, and correct or erase inaccurate records without delay.
Storage limitation Keep data no longer than necessary. This is why a documented retention schedule is a compliance artefact, not admin.
Integrity and confidentiality Protect data with appropriate technical and organizational security measures (Article 32) — access control, encryption, backups, testing.
Accountability Be able to demonstrate compliance through records, policies, and evidence. Doing the right thing without documentation does not satisfy this.

Article 25 adds data protection by design and by default: privacy considerations must be built into new systems and processes from the start, and the most privacy-protective settings should be the default rather than something users have to find.

Lawful bases for processing

You may only process personal data if you have one of six lawful bases under Article 6. You must decide the basis before you start processing, document it, and tell people which one you rely on. You cannot switch bases later because the first one became inconvenient.

Lawful basis Best suited to Watch out for
Consent Marketing emails, non-essential cookies, optional features. Must be freely given, specific, informed, unambiguous, and as easy to withdraw as to give. Pre-ticked boxes and bundled consent are invalid.
Contract Fulfilling an order, providing an account, processing payment. Only covers what is genuinely necessary to deliver the contract — not marketing bolted onto it.
Legal obligation Tax records, statutory employment reporting. Must point to an actual legal requirement, not general prudence.
Vital interests Genuine life-or-death situations, typically medical emergencies. Very narrow. Rarely appropriate for commercial processing.
Public task Public authorities and bodies exercising official functions. Needs a clear basis in law.
Legitimate interests Fraud prevention, network security, some direct marketing, internal administration. The most flexible but the most work: you must run and record a three-part balancing test (purpose, necessity, and the individual’s rights) and it is unavailable to public authorities acting in their official capacity.

Data subject rights

The GDPR grants individuals eight rights over their data. You must respond to a request without undue delay and within one month, extendable by a further two months for complex or numerous requests, provided you tell the person within the first month why you need longer. Responses are normally free; you may only charge or refuse where a request is manifestly unfounded or excessive, and you must be able to justify that judgement.

Right What you must do
To be informed Provide clear privacy information at the point of collection (Articles 13–14).
Of access Supply a copy of their data plus context: purposes, recipients, retention, and the source.
To rectification Correct inaccurate data and complete incomplete data.
To erasure Delete data in defined circumstances — the “right to be forgotten” is conditional, not absolute.
To restrict processing Pause processing while a dispute over accuracy or legitimate interests is resolved.
To data portability Provide data in a structured, commonly used, machine-readable format — applies where processing rests on consent or contract and is automated.
To object Stop processing based on legitimate interests or public task unless you show compelling grounds. For direct marketing the objection is absolute and immediate.
Automated decision-making Provide human review of solely automated decisions with legal or similarly significant effects, including profiling.

In practice the operational risk is not the law but the clock. Organizations that fail data subject access requests usually do so because nobody recognised the request as one — it arrived as an ordinary email to support rather than a formal letter. Train frontline staff to spot and escalate them.

Key GDPR obligations for organizations

Beyond principles and rights, the regulation imposes concrete duties that turn privacy into an operating discipline.

  • Records of processing activities (Article 30). A written inventory of what you process and why. Organizations with fewer than 250 employees are exempt only if the processing is occasional, poses no risk to rights and freedoms, and involves no special category or criminal data — conditions most businesses fail, so assume the record is required.
  • Security measures (Article 32). Appropriate technical and organizational controls proportionate to the risk, with a process for regularly testing and evaluating their effectiveness.
  • Data Protection Impact Assessments (Article 35). Required before high-risk processing — large-scale special category data, systematic monitoring of public areas, or systematic automated evaluation with significant effects.
  • Data Processing Agreements (Article 28). A written contract with every processor covering subject matter, duration, purpose, security, sub-processors, and deletion or return at the end.
  • Data Protection Officer (Article 37). Mandatory for public authorities, for large-scale regular and systematic monitoring, and for large-scale processing of special category or criminal data.
  • Breach notification (Articles 33–34). Notify your supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach, unless it is unlikely to result in risk. Where the risk to individuals is high, tell them too. The clock starts at awareness, not at confident diagnosis — so a partial notification followed by an update beats a late, complete one.

International data transfers

Chapter V restricts sending personal data outside the EEA. Getting this wrong is one of the more common findings in enforcement, because transfers happen invisibly through everyday cloud tooling. A transfer needs one of the following:

  • An adequacy decision (Article 45). The European Commission has determined the destination offers essentially equivalent protection. Recognised countries include the UK, Switzerland, Japan, South Korea, Canada (commercial organizations), and New Zealand, among others.
  • Appropriate safeguards (Article 46). Most commonly the Commission’s Standard Contractual Clauses, which since the Schrems II judgment must be paired with a transfer impact assessment examining the destination country’s surveillance laws and any supplementary measures needed.
  • Binding Corporate Rules (Article 47). Approved internal rules for transfers within a corporate group.
  • The EU–US Data Privacy Framework. Adopted in July 2023, it allows transfers to US organizations that have self-certified to the framework — check the recipient’s current certification rather than assuming it.

Practical point: your CRM, email provider, analytics platform, help desk, and backup provider are all potential transfer routes. Map them before you assert that you make no international transfers.

GDPR penalties

Enforcement under Article 83 is significant. The upper tier reaches €20 million or 4% of global annual turnover, whichever is higher, and covers breaches of the basic principles, lawful bases, data subject rights, and transfer rules. A lower tier of up to €10 million or 2% applies to obligations such as records, security, breach notification, and DPO appointment.

Fines are not the only exposure. Supervisory authorities can order you to stop processing entirely — commercially far worse than a fine for a data-dependent business. Individuals also have a right to compensation for material and non-material damage, and the reputational cost of a public enforcement action typically outlasts the financial one.

UK GDPR: what is different?

After Brexit the GDPR was retained in domestic law as the UK GDPR, sitting alongside the Data Protection Act 2018. The principles, lawful bases, rights, and 72-hour breach rule are substantively the same. The practical differences are jurisdictional: the regulator is the Information Commissioner’s Office, maximum fines are expressed as £17.5 million or 4% of global turnover, and the UK maintains its own adequacy list and its own version of the Standard Contractual Clauses (the International Data Transfer Agreement, or the Addendum to the EU SCCs).

Organizations serving both markets are usually in scope of both regimes and may need a representative in each. The efficient approach is one compliance programme documented once, with jurisdiction-specific annexes for regulator details and transfer mechanisms.

How to achieve GDPR compliance

A practical route runs roughly as follows. Each step produces a document you can show a regulator — which is what the accountability principle actually demands.

  1. Map your data. What personal data you hold, why, where it lives, who you share it with, and how long you keep it. Everything else depends on this. Output: a data inventory and Article 30 record.
  2. Establish and document lawful bases. One per processing activity, with a legitimate interests assessment where you rely on that basis.
  3. Update privacy notices. Written for the reader, covering Articles 13–14 in plain language rather than legal boilerplate.
  4. Fix consent mechanics. Cookie banners that make rejecting as easy as accepting, unbundled marketing opt-ins, and a working withdrawal route.
  5. Put processor agreements in place. Article 28 contracts with every vendor that touches personal data, and a maintained list of sub-processors.
  6. Assess and document transfers. Identify every export, attach the right mechanism, and complete transfer impact assessments where SCCs apply.
  7. Implement security measures. Access control, encryption in transit and at rest, logging, backups, and a tested restore process.
  8. Build rights and breach processes. A named owner, a logged intake route, response templates, and the one-month and 72-hour clocks written into the procedure.
  9. Train staff and review annually. Awareness training for everyone, deeper training for teams handling data, and a scheduled review so the programme does not decay.

Starting from a mapped set of templates turns this into a structured programme rather than a blank page — you adapt evidence that already references the right articles instead of drafting policy from scratch.

Achieve GDPR compliance the fast way.

Our GDPR Toolkit delivers the policies, privacy notices, records of processing, DPIA and DPA templates, and data-subject-rights procedures you need — mapped to the regulation and editable in Word and Excel.

Explore the GDPR Toolkit →

Frequently asked questions

What is GDPR compliance in simple terms?

It means handling the personal data of people in the EU in line with the GDPR — following its principles, having a lawful basis, respecting individuals’ rights, securing the data, and being able to demonstrate all of this with documentation.

Who has to comply with GDPR?

Any organization established in the EU that processes personal data, and any organization outside the EU that offers goods or services to, or monitors the behaviour of, people in the EU. There is no small-business exemption from the regulation itself, although a few specific duties scale with size and risk.

What are the GDPR fines?

Up to €20 million or 4% of global annual turnover for the most serious breaches, and up to €10 million or 2% for other infringements — whichever is higher in each case. Regulators can also order processing to stop.

How long do I have to respond to a data subject access request?

One month from receipt, extendable by two further months for complex or numerous requests if you inform the individual within the first month.

Do I need a Data Protection Officer?

Only if you are a public authority, carry out large-scale regular and systematic monitoring, or process special category or criminal offence data on a large scale. Many organizations appoint a privacy lead voluntarily without giving them formal DPO status.

Does GDPR apply to B2B data?

Yes. Business contact details that identify a person — a named work email address, for instance — are personal data. Generic addresses such as info@ are not, because they identify no individual.

Is GDPR the same as the UK GDPR?

Substantively very close. The principles, rights, and deadlines match; the regulator, the currency of the fine caps, and the transfer paperwork differ. Organizations serving both markets usually need to satisfy both.

How do I become GDPR compliant?

Map your data, establish lawful bases, update privacy notices, implement security and processor agreements, assess international transfers, build data-subject-rights and breach processes, train your staff, and document everything for accountability.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.