Back to lessons
Lesson 11

GDPR Fundamentals

Are you in scope? Lawful bases, data subject rights, the 72-hour breach clock, and when a data protection officer is mandatory.

What is the GDPR?

The GDPR is the General Data Protection Regulation, Regulation (EU) 2016/679. It is the EU's core law for processing personal data. It rests on a small set of principles in Article 5: lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability.

Unlike NIS2, the GDPR is a regulation, not a directive, so it applies directly across the EU. It has been in force since 25 May 2018. In Germany it is supplemented by the BDSG (Bundesdatenschutzgesetz), which adds national rules, including a lower threshold for when a data protection officer is mandatory.

Are you in scope?

Two tests decide this: material scope and territorial scope.

Material scope (Article 2)

The GDPR applies whenever you process personal data, meaning any information relating to an identified or identifiable living person. A name, an email address, an IP address, a customer ID, or a location can all be personal data. If you process no personal data at all, the GDPR does not apply.

Territorial scope (Article 3)

This long reach is why even non-EU companies often fall under the GDPR.

Controller or processor?

A controller decides why and how personal data is processed. A processor acts on a controller's instructions. The roles carry different duties, and they must be set out in a written data processing agreement (Article 28). Most businesses are controllers for their own staff and customer data and processors when they handle data on behalf of clients.

The six lawful bases (Article 6)

Every processing activity needs exactly one lawful basis. Pick it before you start, and record it.

  1. Consent: freely given, specific, informed, and as easy to withdraw as to give
  2. Contract: necessary to perform a contract with the data subject
  3. Legal obligation: necessary to comply with a law
  4. Vital interests: necessary to protect someone's life
  5. Public task: necessary for a task in the public interest
  6. Legitimate interests: necessary for your interests, balanced against the person's rights

Special category data (Article 9)

Some data needs extra protection: health, biometric and genetic data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, and data on sex life or sexual orientation. Processing it is prohibited unless a specific Article 9 exception applies, such as explicit consent or a legal basis in employment law.

Data subject rights (Articles 12 to 22)

People have enforceable rights over their data. You usually have one month to respond, free of charge:

Core obligations and accountability

Accountability (Article 5(2)) means you must not only comply, but be able to demonstrate it. The practical building blocks are:

The 72-hour breach clock (Articles 33 to 34)

A personal data breach is any breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of, or access to, personal data.

This clock often fires at the same time as the NIS2 and DORA reporting clocks. Run one integrated incident process, not three that drift apart.

When you need a data protection officer (Articles 37 to 39)

Under the GDPR a DPO is mandatory if your core activities involve large-scale regular and systematic monitoring, or large-scale processing of special category data, or you are a public authority. Germany sets the bar lower: under section 38 BDSG, a DPO is mandatory once you constantly employ at least 20 people involved in automated processing of personal data, which in practice means almost anyone working with a computer. A DPIA obligation also triggers a DPO.

International transfers (Chapter V, Articles 44 to 49)

Sending personal data outside the EU and EEA needs a transfer mechanism: an adequacy decision (the country is deemed safe), standard contractual clauses (SCCs) with a transfer impact assessment, binding corporate rules, or a specific derogation. Using a US cloud provider can be a transfer, which is one reason EU-hosted tooling is attractive to EU buyers.

Fines (Article 83)

Who enforces it

How the GDPR interacts with the other frameworks

What to do next

This lesson is educational, not legal advice. Confirm with qualified counsel before relying on any classification for compliance submissions.
All lessonsTry the classifier
SchutzIQ - EU compliance platform