Brickwork Knowledge Glossary

A working reference of the sales, research and technology terms our advisory teams use every day — search or browse alphabetically to find a definition.

F G

GDPR

GDPR

1. Introduction

The General Data Protection Regulation (GDPR) is data protection legislation aimed at enhancing data privacy rights and regulating how organizations collect, process, store, and use personal data. It is centered mainly on organizations in the European Union (EU) or dealing with the personal data of EU citizens.

If you are still not sure what is GDPR, then here’s a simple definition for you. It is a law that sets out the rules for how companies and other entities can handle people's information. For companies that collect or handle personal data, understanding what is GDPR compliance is extremely crucial. This guide will explore the definition of GDPR, key regulations, benefits, and how to ensure GDPR compliance.

2. What Is GDPR?

GDPR is a far-reaching data protection law that came into force on 25th May 2018. It superseded the EU Data Protection Directive and provided harmonized and uniform data protection conditions across EU member states.

The rules apply to personal data such as names, email addresses, identification numbers, location information, and online identifiers. It can also be used to protect sensitive data, such as health or biometric data, contingent on the conditions.

Under the GDPR, individuals have several rights: to access their personal data, request corrections, request deletion in some cases, and be informed about the processing of their data.

3. What Is GDPR Compliance?

GDPR compliance involves implementing appropriate policies, procedures, and technical safeguards to meet GDPR requirements. It is not just about having a privacy policy on a website.

An organization should be aware of the nature of the personal information being collected, the purpose of its collection, where it is kept, who has access to it, and how long it must be held. It should also have procedures in place for responding to data subject requests and handling potential data breaches.

If an organization collects customer data via an online form, for instance, it should be clear why the information is being collected, and there should be a clear procedure for keeping the data secure.

4. What are the GDPR Regulations?

So, what are the GDPR regulations? The GDPR is based on several principles relating to the processing of personal data:

  • Lawfulness, fairness, and transparency: Organizations need to have a lawful basis for processing personal data and to be clear about their practices.
  • Purpose limitation: Data should be collected for specific and legitimate purposes and not used in incompatible ways, something that would deviate from the original purpose.
  • Data minimization: Organizations should collect only the data necessary, something they are going to genuinely use.
  • Accuracy: The accuracy of the personal information should be ensured, and it should be kept up-to-date where appropriate.
  • Storage limitation: Data should not be stored or retained for longer than required.
  • Integrity and confidentiality: Personal information should be appropriately secured for integrity and confidentiality.
  • Accountability: Organizations should be able to demonstrate compliance with GDPR requirements.

For instance, a company gathering e-mail addresses in the interest of a newsletter ought not to use them for other purposes without a proper legal basis. To put it simply, the purpose should not deviate. They cannot even use them for unrelated marketing activities.

5. Why Is GDPR Used?

GDPR is intended to enhance personal data privacy and increase accountability in handling personal information. Adhering to the regulation can also enhance customer trust and promote better data management for companies.

Key benefits include:

  • Greater transparency in how data is used and in data processing.
  • Enhanced security and protection from unauthorized access.
  • Stronger customer confidence
  • Inclusion of more structured data governance
  • Increased likelihood of avoiding fines from regulators
  • More efficient data handling within the organization

Therefore, GDPR compliance can be, and should be, integrated into a broader information security and risk management approach, rather than being treated as a mere compliance mandate.

6. How to Comply With GDPR?

For organizations seeking to know how to comply with GDPR, a structured approach can be a good starting point.

1. Identify personal data: Map out what is being collected, processed, shared, and stored around personal data.

2. Establish a lawful basis: Determine the lawful basis for processing each activity, e.g., contract, consent, or legitimate interests.

3. Review privacy notices: Inform people about the use and purpose of their personal information, and keep a timely review of such information, whether it’s up to date or not.

4. Strengthen security controls: Implement risk-appropriate security measures, including access controls, encryption, and monitoring.

5. Manage data subject requests: Establish procedures for responding to individual’s requests for access, correction, destruction, and/or rights to their data.

6. Prepare for data breaches: Develop data breach detection, assessment, documentation, and response plans for personal data breaches.

7. Review third-party processors: Confirm that third-party processors comply with their contractual and data protection obligations.

7. Final Thoughts

GDPR offers a clear structure to safeguard personal data and holds organizations primarily accountable for their data practices. Understand that compliance is a process; it requires clear ownership and security controls in place - it is not a one-time documentation task.

For organizations requiring further guidance on GDPR compliance, Brickwork can offer structured compliance and operational support to help businesses manage compliance requirements, document processes, and improve compliance as they grow.

Read more
Enquire Call