Skip to main content

Glossary

What Is GDPR

GDPR is the EU regulation governing how organisations collect, store, and use personal data. Plain-English definition for business owners.

Definition

GDPR (General Data Protection Regulation) is a data protection law introduced by the European Union in 2018. It governs how organisations collect, store, process, and share personal data belonging to individuals in the EU and UK. Personal data means any information that can identify a person: names, email addresses, IP addresses, location data, and more. GDPR gives individuals rights over their data, including the right to access it, correct it, and request its deletion. It applies to any organisation that handles EU or UK residents' data, regardless of where the organisation is based.

Why It Matters

GDPR affects virtually every business that operates online and has customers or contacts in the UK or EU. Non-compliance carries significant penalties. Fines can reach 4% of annual global turnover or 20 million euros, whichever is higher. Beyond fines, a data protection failure damages trust, and trust is difficult to rebuild. For business owners, GDPR compliance means understanding what personal data you hold, why you hold it, how it is protected, and how long you keep it. It also means having lawful grounds for processing data, being transparent with users about what you do with their information, and responding promptly to data subject requests.

Example

A small e-commerce business collects customer email addresses during checkout. Under GDPR, the business must tell customers clearly why their email is being collected (order confirmation, delivery updates), and cannot use it for marketing unless the customer specifically consents. If a customer requests to see all data held about them, the business must provide it within 30 days. If the customer asks to be deleted, the business must comply unless there is a legal obligation to retain certain records, such as tax documentation. A data breach that exposes this kind of information must also be reported to the relevant authority within 72 hours. Browse the glossary for related definitions.

Portrait of Alexander De Sousa, founder of Digital Royalty
Founder-led
“I’ve put everything I know into how this company works — the standards, the method, the care on every project. It runs through the whole team, and I hold us all to it.”

Alexander De Sousa · Founder LinkedIn

Featured on BBC Radio Solent

Get started

Tell us what you need

A few quick questions, then a straight answer from a real person — usually within a few hours.

Tell us what you're working on

Whether it's a new site, a platform, or a process that shouldn't be manual any more — we'll tell you honestly if we can help.