Privacy

GDPR

Also called General Data Protection Regulation.

GDPR is the EU General Data Protection Regulation, in force since 25 May 2018. It governs processing of personal data about people in the EU, wherever the processor sits.

How it is measured

It works through principles, lawful bases, and rights. Every processing activity needs one of six bases, such as consent, contract, or legitimate interest. People have rights to access, correct, erase, restrict, and object.

Test yourself with a record of processing: what you collect, why, on which basis, for how long, and who else receives it. Penalties reach 20 million euros or 4 percent of worldwide annual turnover, whichever is higher.

Worked example

A US design newsletter has 800 EU subscribers, which puts it in scope because it targets them. One subscriber asks for a copy of their data. The sender exports 3 records and replies on day 12, inside the one-month limit.

A second subscriber objects to profiling. The sender switches off open-tracking for that address and notes the date.

How it differs

GDPR is the regulation. Personal data is the thing it protects, and the definition decides whether the rules apply to a given field. The regulation excludes truly anonymous data; the definition tells you whether yours qualifies.

Common errors

Believing it applies only to companies based in the EU. Treating consent as the only basis. Having no route for access requests. Forgetting that vendors are your problem too. Treating a cookie banner as compliance.

In practice

Write a one-page record of processing this week. Name a lawful basis for each line and a retention period. Then send yourself a test access request and see how long it takes to answer.

See also

Personal data, Data controller, Legitimate interest

Sources

Count this on a real site.

Watch my website