The GDPR, Regulation (EU) 2016/679, governs protection of natural persons when personal data is processed and the free movement of that data. Applicability depends on the specific activity, establishment, people affected and territorial reach. Duties may include principles, legal basis, transparency, rights, security, processors, records, assessments and breach notification according to the processing. Compliance is not achieved by publishing a policy or buying a tool. An organisation should know purposes, data, flows, retention, recipients and owners and demonstrate risk-proportionate decisions. Anonymisation, pseudonymisation and encryption are not equivalent. A general definition cannot determine obligations for one case; the current official text, competent authorities and qualified advice should be consulted where appropriate.
IT glossary
GDPR
Let's talk
Need help with this?
30 minutes with a senior consultant. No commitment, no sales pitch. An honest conversation about what you need and what we can do together.