Are you in scope? Lawful bases, data subject rights, the 72-hour breach clock, and when a data protection officer is mandatory.
What is the GDPR?
The GDPR is the General Data Protection Regulation, Regulation (EU) 2016/679. It is the EU's core law for processing personal data. It rests on a small set of principles in Article 5: lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability.
Unlike NIS2, the GDPR is a regulation, not a directive, so it applies directly across the EU. It has been in force since 25 May 2018. In Germany it is supplemented by the BDSG (Bundesdatenschutzgesetz), which adds national rules, including a lower threshold for when a data protection officer is mandatory.
Are you in scope?
Two tests decide this: material scope and territorial scope.
Material scope (Article 2)
The GDPR applies whenever you process personal data, meaning any information relating to an identified or identifiable living person. A name, an email address, an IP address, a customer ID, or a location can all be personal data. If you process no personal data at all, the GDPR does not apply.
Territorial scope (Article 3)
- You have an establishment in the EU and process personal data in that context, regardless of where the processing happens
- You are outside the EU but offer goods or services to people in the EU
- You are outside the EU but monitor the behaviour of people in the EU (for example online tracking)
This long reach is why even non-EU companies often fall under the GDPR.
Controller or processor?
A controller decides why and how personal data is processed. A processor acts on a controller's instructions. The roles carry different duties, and they must be set out in a written data processing agreement (Article 28). Most businesses are controllers for their own staff and customer data and processors when they handle data on behalf of clients.
The six lawful bases (Article 6)
Every processing activity needs exactly one lawful basis. Pick it before you start, and record it.
- Consent: freely given, specific, informed, and as easy to withdraw as to give
- Contract: necessary to perform a contract with the data subject
- Legal obligation: necessary to comply with a law
- Vital interests: necessary to protect someone's life
- Public task: necessary for a task in the public interest
- Legitimate interests: necessary for your interests, balanced against the person's rights
Special category data (Article 9)
Some data needs extra protection: health, biometric and genetic data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, and data on sex life or sexual orientation. Processing it is prohibited unless a specific Article 9 exception applies, such as explicit consent or a legal basis in employment law.
Data subject rights (Articles 12 to 22)
People have enforceable rights over their data. You usually have one month to respond, free of charge:
- Information and transparency (Articles 13 to 14): clear privacy notices
- Access (Article 15): a copy of their data and how it is used
- Rectification (Article 16): correct inaccurate data
- Erasure, the right to be forgotten (Article 17)
- Restriction (Article 18) and objection (Article 21)
- Data portability (Article 20): receive and reuse their data
- Rights related to automated decision-making and profiling (Article 22)
Core obligations and accountability
Accountability (Article 5(2)) means you must not only comply, but be able to demonstrate it. The practical building blocks are:
- Records of processing activities, ROPA (Article 30): a register of what you process, why, on what basis, and with whom you share it
- Data protection by design and by default (Article 25): build privacy in from the start and default to the least data
- Security of processing (Article 32): appropriate technical and organisational measures, such as encryption, access control, and backups
- Data protection impact assessment, DPIA (Article 35): required before high-risk processing, such as large-scale profiling or monitoring
- Processor contracts (Article 28) and safeguards for any onward sharing
The 72-hour breach clock (Articles 33 to 34)
A personal data breach is any breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of, or access to, personal data.
- 72 hours: notify the supervisory authority without undue delay, unless the breach is unlikely to result in a risk to people
- Without undue delay: tell the affected people directly if the breach is likely to result in a high risk to them
- Always: document every breach internally, including those you do not report
This clock often fires at the same time as the NIS2 and DORA reporting clocks. Run one integrated incident process, not three that drift apart.
When you need a data protection officer (Articles 37 to 39)
Under the GDPR a DPO is mandatory if your core activities involve large-scale regular and systematic monitoring, or large-scale processing of special category data, or you are a public authority. Germany sets the bar lower: under section 38 BDSG, a DPO is mandatory once you constantly employ at least 20 people involved in automated processing of personal data, which in practice means almost anyone working with a computer. A DPIA obligation also triggers a DPO.
International transfers (Chapter V, Articles 44 to 49)
Sending personal data outside the EU and EEA needs a transfer mechanism: an adequacy decision (the country is deemed safe), standard contractual clauses (SCCs) with a transfer impact assessment, binding corporate rules, or a specific derogation. Using a US cloud provider can be a transfer, which is one reason EU-hosted tooling is attractive to EU buyers.
Fines (Article 83)
- Lower tier: up to €10 million or 2% of worldwide annual turnover, whichever is higher (for example breaches of records or security duties)
- Upper tier: up to €20 million or 4% of worldwide annual turnover, whichever is higher (for example breaches of the principles, lawful basis, or data subject rights)
Who enforces it
- Each EU country has one or more supervisory authorities. Germany is unusual: each federal state (Land) has its own authority, plus the federal BfDI for federal bodies and telecoms
- The European Data Protection Board (EDPB) coordinates consistency across the EU
- German authorities are increasingly active against smaller companies, so the risk is no longer only for big tech
How the GDPR interacts with the other frameworks
- EU AI Act: most AI systems process personal data, so the GDPR applies alongside it. An AI Act conformity step and a GDPR DPIA often cover overlapping ground
- NIS2 and DORA: significant overlap on incident reporting. A security incident is frequently also a personal data breach. Integrated incident response is essential
- ISO 27001: strong technical and organisational measures under ISO 27001 help satisfy Article 32, but the GDPR adds rights, lawful basis, and accountability duties that a security standard does not cover
What to do next
- Build or update your records of processing activities (Article 30). This is the foundation everything else hangs on
- Assign a lawful basis to each activity (Article 6) and refresh your privacy notices (Articles 13 to 14)
- Set up a request workflow so you can answer access and erasure requests within a month
- Stand up the 72-hour breach process and a single incident log shared with NIS2 and DORA where relevant
- Check whether a DPO is mandatory (Articles 37 to 39; in Germany also section 38 BDSG)
- Run a DPIA for any high-risk processing before you launch it (Article 35)
- Use the classifier tool to check the GDPR alongside the other ten frameworks
This lesson is educational, not legal advice. Confirm with qualified counsel before relying on any classification for compliance submissions.