The General Data Protection Regulation (GDPR) became applicable in 2018 and changed how many organizations approach personal data. This overview is general information and not legal advice.
Process data lawfully and transparently
Organizations need an appropriate legal basis and should explain what they collect, why, how long they retain it and with whom it is shared.
Limit collection and purpose
Personal data should be adequate and relevant to a defined purpose. Information collected for one reason should not be reused incompatibly without a valid basis.
Protect accuracy and security
Maintain appropriate technical and organizational safeguards, correct inaccurate data and define incident-response responsibilities.
Support individual rights
Depending on the context, people may have rights involving access, correction, deletion, restriction, portability and objection.
Demonstrate accountability
Document decisions, contracts, risk assessments and governance. A privacy notice alone is not a complete compliance program.
Applicability and obligations depend on the organization and processing activity. Consult current official guidance and qualified counsel for a specific case.