Why It Matters
GDPR affects virtually every business that operates online and has customers or contacts in the UK or EU. Non-compliance carries significant penalties. Fines can reach 4% of annual global turnover or 20 million euros, whichever is higher. Beyond fines, a data protection failure damages trust, and trust is difficult to rebuild. For business owners, GDPR compliance means understanding what personal data you hold, why you hold it, how it is protected, and how long you keep it. It also means having lawful grounds for processing data, being transparent with users about what you do with their information, and responding promptly to data subject requests.
Example
A small e-commerce business collects customer email addresses during checkout. Under GDPR, the business must tell customers clearly why their email is being collected (order confirmation, delivery updates), and cannot use it for marketing unless the customer specifically consents. If a customer requests to see all data held about them, the business must provide it within 30 days. If the customer asks to be deleted, the business must comply unless there is a legal obligation to retain certain records, such as tax documentation. A data breach that exposes this kind of information must also be reported to the relevant authority within 72 hours. Browse the glossary for related definitions.