The General Data Protection Regulation (GDPR) is the European Union’s comprehensive data protection law. This regulation, which came into force on 25 May 2018, is designed to protect the personal data and privacy of individuals within the EU and the European Economic Area (EEA). The GDPR sets strict rules on how organisations collect, use, store, and share personal data, and gives EU citizens more control over their information.
Before the GDPR, data protection laws varied across EU member states. The main objectives of the GDPR, which was introduced to bring clarity to this complexity, are as follows:
- Harmonising data protection laws across the EU
- Strengthening individuals’ privacy rights
- Increasing transparency in how organisations process data
- Holding companies accountable for the misuse of personal information
In today’s digital world, where personal data is constantly collected online, the GDPR provides a consistent and modern legal framework. Under the GDPR, personal data means any information that can directly or indirectly identify an individual. Examples include:
- First and last name
- Email address
- Telephone number
- Home address
- IP address
- Location data
- Online identifiers (cookies, device IDs)
- Financial or health information
If data can be linked to an identifiable individual, it is protected under GDPR.
GDPR applies to:
- Organisations located in the EU, regardless of where the data processing takes place.
- Organisations outside the EU, if:
- They offer goods or services to EU residents or
- They monitor individuals’ behaviour within the EU (e.g., through tracking cookies).
This means that the GDPR has a global impact. Even companies outside Europe must comply with this regulation if they process the data of EU citizens.
Rights of EU Citizens under the GDPR
The GDPR grants individuals strong rights over their personal data:
1. Right to be informed: Individuals should know how and why their data is being used.
2. Right of Access: They can request a copy of their personal data.
3. Right to Rectification: They can request that incorrect or incomplete data be corrected.
4. Right to Erasure (‘Right to be Forgotten’): They can request that their personal data be erased in certain circumstances.
5. Right to Restrict Processing: They may restrict how their data is used.
6. Right to Data Portability: They may receive their data in a transferable format.
7. Right to Object: They may object to certain types of processing, such as direct marketing.
8. Rights Related to Automated Decision-Making: They are protected against fully automated decisions that significantly affect them.
You can review the following topics to determine how compliant your organisation is with the GDPR:
- Awareness and Training
- Data Inventory
- Legal Basis
- Data Subject Rights
- Data Protection Officer (DPO
- Data Processing Records
- Consent Management
- Data Minimisation
- Data Security
- Data Breach Response
- Third-Party Processors
- Privacy by Design
- Data Protection Impact Assessments (DPIAs)
- Records of Processing Activities
- Data Protection Policies
- Children’s Data
- Regular Audits and Monitoring
- Documentation and Reporting
- Training and Awareness
- Data Retention
- Legal Review
- Supplier Management
- Incident Response
While GDPR focuses on protecting individuals’ personal data and privacy rights, ISO 27001 provides a comprehensive system for establishing, implementing, maintaining, and continuously improving information security management systems (ISMS). The ISO 27701 Privacy Information Management System, with its updated 2025 version, certifies your GDPR and DPA compliance.
CFECERT offers audit services accredited by UKAS and IAS.
As CFE Academy, you can contact us for registration and information about our GDPR Awareness and DPO/Data Protection Officer training courses.