GDPR: the EU’s data-protection law, explained
The General Data Protection Regulation (GDPR) is the EU’s law for handling personal data. It applies to anyone processing the data of people in the EU — wherever they’re based — sets core principles, grants individuals strong rights, requires a lawful basis for processing, and mandates breach notification. GDPR is a legal regulation, not a certification: you must be able to demonstrate ongoing compliance.
A legal regulation, not a certificate
Unlike ISO 27001 or SOC 2, you don’t get “GDPR certified.” GDPR is a binding EU law: you’re expected to comply continuously and to be able to demonstrate it, and regulators can impose significant penalties. A strong security program helps — an ISO 27001 ISMS supports GDPR’s security principle — but GDPR also covers legal and privacy obligations that go beyond security. Treat this guide as an orientation and pair it with qualified legal advice for your situation.
The principles behind GDPR
Lawfulness, fairness & transparency
Process personal data lawfully and fairly, and be clear with people about what you do with their data.
Purpose limitation & minimisation
Collect data for specified, legitimate purposes and only what you actually need — no more.
Accuracy & storage limitation
Keep personal data accurate and up to date, and don't retain it for longer than necessary.
Integrity, confidentiality & accountability
Secure the data appropriately, and be able to demonstrate your compliance — accountability is a principle in its own right.
The rights GDPR gives people
GDPR hands individuals a set of rights over their personal data. You need processes to recognize and respond to these requests — usually within a set timeframe:
- Be informed about how their data is used
- Access the personal data you hold about them
- Have inaccurate data rectified
- Have their data erased (the right to be forgotten)
- Restrict or object to certain processing
- Data portability — receive and reuse their data
Six ways to lawfully process
You need a valid lawful basis before processing personal data. There are six — pick and document the one that fits each activity.
Consent & contract
The person has given clear consent, or processing is necessary to perform a contract with them.
Legal obligation & legitimate interests
Processing is required by law, or is necessary for your legitimate interests balanced against the person's rights.
Vital & public interest
Processing protects someone's vital interests, or is carried out in the public interest or official authority.
Breach notification
GDPR expects you to detect, investigate, and report personal-data breaches. Where a breach is likely to risk people’s rights and freedoms, you generally must notify the relevant supervisory authority without undue delay, and where the risk is high, inform the affected individuals too. Because the exact thresholds and timelines are enforced, confirm the current requirements against the official regulation and take legal advice where appropriate.
GDPR, answered
Organize your GDPR readiness
Komply maps data-protection controls into one control set alongside ISO 27001, drafts policies, and tracks evidence — support your compliance program and pair it with legal advice.