Skip to content

What is GDPR?

Cybersecurity & Compliance, explained by the engineers who build it. Definition, how it works, use cases and common questions.

GDPR definition

GDPR, the General Data Protection Regulation, is the European Union's data protection law, applying since 25 May 2018. It governs how organizations collect, use, store and share personal data of people in the EU, requires a lawful basis for processing, grants individuals rights over their data, and allows fines of up to 4% of global annual turnover.

Who does GDPR apply to?

GDPR applies to organizations established in the EU that process personal data, wherever the processing happens. It also applies to organizations outside the EU when they offer goods or services to people in the EU or monitor their behavior there, for example through tracking on a website. An Indian or US SaaS company with EU customers can therefore fall within scope. Personal data means any information relating to an identified or identifiable person, including names, emails, device identifiers and location data.

GDPR distinguishes controllers, who decide why and how data is processed, from processors, who process data on a controller's behalf, such as a hosting or software vendor. Both have obligations, and processors must work under a written data processing agreement. The UK applies its own closely aligned version, known as the UK GDPR. Processors must also help controllers meet breach and rights obligations.

Key GDPR principles

Article 5 sets out the principles that every processing activity must follow. They shape design decisions in software as much as legal paperwork, since collecting less data, keeping it for shorter periods and securing it properly are engineering choices. The controller must be able to demonstrate compliance with each principle. Regulators expect records of processing activities, and privacy notices must explain each purpose clearly.

  • Lawfulness, fairness and transparency.
  • Purpose limitation: use data only for specified purposes.
  • Data minimization: collect only what is necessary.
  • Accuracy: keep data correct and up to date.
  • Storage limitation: keep data no longer than needed.
  • Integrity and confidentiality: protect data with appropriate security.
  • Accountability: document and demonstrate compliance.

Lawful bases and individual rights

Every processing activity needs one of six lawful bases: consent, contract, legal obligation, vital interests, public task or legitimate interests. Consent is only one option and must be freely given, specific, informed and as easy to withdraw as to give. Individuals have rights to be informed, to access their data, to rectification, to erasure, to restrict processing, to data portability, to object, and protections around solely automated decisions with significant effects. Organizations generally must respond to requests within one month.

Breaches, fines and what it means for software teams

Controllers must notify the relevant supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless it is unlikely to result in risk to individuals, and inform affected people when the risk is high. The highest tier of fines reaches 20 million euros or 4% of worldwide annual turnover, whichever is higher. For software teams, GDPR translates into privacy by design: data mapping, minimal collection, encryption, access control, retention and deletion jobs, consent management and export tools for access requests.

Nexzem builds these capabilities into client applications as part of its GDPR compliance work. This page is general information, not legal advice; consult a qualified privacy lawyer for decisions about your obligations. Data protection authorities also publish guidance that helps interpret specific situations.

GDPR: common questions

Something else on your mind? Ask a consultant and get a reply within one business day.

Does GDPR apply to companies outside the EU?

Yes, in certain cases. Under Article 3, GDPR applies to organizations outside the EU that offer goods or services to people in the EU, even free services, or that monitor their behavior in the EU, such as through tracking and profiling. Such organizations may also need to appoint a representative in the EU.

Is consent always required under GDPR?

No. Consent is one of six lawful bases. Processing may instead be necessary for a contract with the person, a legal obligation, vital interests, a public task, or legitimate interests balanced against the person's rights. Choose the basis before processing begins and document it, because switching bases later is generally not allowed.

What is the difference between GDPR and India's DPDP Act?

Both protect personal data and grant individuals rights, but they differ in detail. GDPR offers six lawful bases and covers personal data in any form, while India's DPDP Act focuses on digital personal data and relies mainly on consent plus defined legitimate uses. Penalties, enforcement bodies, children's data rules and cross-border transfer approaches also differ.

Keep exploring the cybersecurity & compliance glossary

Need GDPR in your product?

A solutions consultant replies within one business day with next steps, a rough estimate and a suggested team.