The General Data Protection Regulation
Europe’s central data protection law, and what it asks of the people handling personal data every day.
The GDPR has applied across all EU member states since May 2018. It governs how organisations collect, use, store and protect personal data, and it reaches any organisation handling data about people in the EU, wherever that organisation is based.
What the Regulation sets out
It establishes principles for lawful processing, gives individuals enforceable rights over their own information, and places a duty on organisations to keep that data secure. Those rights include access, correction, erasure and objection, each creating an obligation the organisation must be able to meet.
Where compliance usually breaks down
Most failures are not technical. They happen when someone shares data they should not have, keeps records longer than necessary, or does not recognise a request from a person exercising their rights. The controls may be sound while everyday handling is not.
Why it is a workforce issue
Because the risk sits in routine decisions, awareness across the whole organisation matters more than depth in any one team. Staff need to recognise personal data, handle it correctly, and know when to escalate.
Train your teams on this
Our GDPR & Cyber Defence courses cover data protection alongside NIS2 and DORA resilience.
