What is the GDPR? The General Data Protection Regulation is the principal European Union legal framework governing the processing and protection of personal data. It establishes rules for organisations that collect, use, store, share or otherwise process information relating to identifiable individuals.
In today’s digital economy, almost every company, public institution, association, educational provider or professional service provider processes personal data. This may include information relating to employees, clients, customers, website visitors, newsletter subscribers, job applicants, business partners or users of online services.
Data protection is therefore not merely an administrative task. It is a legal, organisational and reputational responsibility.
The GDPR is Regulation (EU) 2016/679 of the European Parliament and of the Council. It was adopted on 27 April 2016 and has applied since 25 May 2018. Its purpose is to protect natural persons in relation to the processing of personal data while allowing the lawful movement of such data within the European Union.

What is the GDPR?
The General Data Protection Regulation is the principal European Union legal framework governing the processing and protection of personal data. It establishes rules for organisations that collect, use, store, share or otherwise process information relating to identifiable individuals.
In today’s digital economy, almost every company, public institution, association, educational provider or professional service provider processes personal data. This may include information relating to employees, clients, customers, website visitors, newsletter subscribers, job applicants, business partners or users of online services.
Data protection is therefore not merely an administrative task. It is a legal, organisational and reputational responsibility.
The GDPR is Regulation (EU) 2016/679 of the European Parliament and of the Council. It was adopted on 27 April 2016 and has applied since 25 May 2018. Its purpose is to protect natural persons in relation to the processing of personal data while allowing the lawful movement of such data within the European Union.
The official text of the General Data Protection Regulation is available on EUR-Lex.
Understanding what is the GDPR? requires organisations to examine how personal data is collected, used, stored, shared and protected throughout its entire life cycle.
What is the GDPR designed to protect?
The GDPR protects personal data relating to natural persons.
Personal data means any information connected to an identified or identifiable individual. It does not include only obvious information such as a person’s name, home address, telephone number or email address.
Depending on the circumstances, personal data may also include:
- identification numbers;
- location data;
- online identifiers;
- IP addresses;
- employment information;
- financial information;
- photographs and video recordings;
- customer account details;
- device identifiers;
- information collected through cookies;
- data that can identify someone when combined with other information.
The GDPR is technology-neutral. It can apply regardless of whether personal data is processed through modern software, an online platform, an internal database or a structured paper filing system.
This is why GDPR compliance cannot be reduced to one privacy notice copied from another website. An organisation must understand what information it processes, why it uses it, where it is stored, who can access it, how it is protected and when it should be deleted.
Who must comply with the GDPR?
A common misconception is that the GDPR applies only to large international corporations or technology companies.
In practice, it may also apply to:
- small and medium-sized companies;
- public authorities and institutions;
- schools and universities;
- hospitals and healthcare providers;
- law firms;
- associations and non-profit organisations;
- online shops;
- marketing agencies;
- employers;
- training providers;
- professional service providers;
- companies offering digital services.
The number of employees or the size of the organisation is not the only relevant factor. What matters is whether personal data is processed, whose data is involved, why it is processed and how that processing is carried out.
When companies ask what is the GDPR?, they should consider both the legal requirements and their everyday data-processing activities.
The GDPR may also apply to organisations established outside the European Union when they offer goods or services to people in the EU or monitor their behaviour under the conditions defined by the Regulation.
Personal data processing is not only digital
When organisations ask what is the GDPR?, they often assume that it concerns only websites, mobile applications and online databases.
However, processing is a much broader concept. It can include collecting, recording, organising, storing, changing, consulting, using, disclosing, combining, restricting, deleting or destroying personal data.
Personal data may therefore be processed through:
- website contact forms;
- newsletter platforms;
- customer relationship management systems;
- employment records;
- job applications;
- customer databases;
- cloud services;
- accounting software;
- video surveillance systems;
- attendance lists;
- internal spreadsheets;
- structured paper records.
A company may have an attractive website privacy policy and still fail to comply if its internal employment records, marketing database, video surveillance or service-provider contracts are not properly regulated.
What are the main GDPR principles?
The GDPR establishes several fundamental principles that organisations must follow whenever they process personal data.
Lawfulness, fairness and transparency
Personal data must be processed on a valid legal basis, fairly and in a manner that is understandable to the individual.
Purpose limitation
Data should be collected for specific, explicit and legitimate purposes. It should not later be used for unrelated purposes without an appropriate legal basis.
Data minimisation
An organisation should collect only the personal data that is genuinely necessary for the intended purpose.
Accuracy
Personal data should be accurate and corrected when it is incomplete or incorrect.
Storage limitation
Data should not be retained for longer than necessary. Organisations should establish realistic retention periods.
Integrity and confidentiality
Personal data must be protected through appropriate organisational and technical security measures.
Accountability
The organisation must not only comply with the GDPR but also be able to demonstrate its compliance.
A practical answer to what is the GDPR? must therefore include both legal obligations and the day-to-day procedures used within an organisation.
What legal basis is required for processing?
The GDPR does not state that every processing activity requires consent.
Depending on the circumstances, processing may be based on:
- consent;
- performance of a contract;
- compliance with a legal obligation;
- protection of vital interests;
- performance of a task carried out in the public interest;
- legitimate interests pursued by the controller or a third party.
The correct legal basis depends on the purpose and circumstances of the processing. Consent should not be used automatically when another legal basis is more appropriate.
An organisation should identify and document the legal basis before it begins processing personal data. It should also ensure that the information provided to individuals accurately reflects that basis.
What rights do individuals have under the GDPR?
One of the main objectives of the GDPR is to give individuals greater control over their personal data.
Depending on the circumstances, data subjects may have:
- the right to receive information about processing;
- the right of access;
- the right to rectification;
- the right to erasure;
- the right to restriction of processing;
- the right to data portability;
- the right to object;
- rights relating to automated decision-making and profiling.
These rights are not identical in every situation and may be subject to legal conditions or exceptions. However, organisations must have a clear procedure for receiving, reviewing and responding to requests.
This means that it is not enough to store personal data securely. Organisations must also know how to respond when an individual asks:
- what information is held about them;
- why it is being used;
- where it came from;
- who has received it;
- how long it will be retained;
- whether it can be corrected or deleted.
Why is transparency important?
Transparency is a central element of GDPR compliance.
Individuals should receive clear information about:
- the identity of the organisation processing their data;
- the purposes of the processing;
- the legal basis;
- the categories of personal data involved;
- recipients or categories of recipients;
- retention periods;
- international data transfers;
- their rights;
- the right to complain to a supervisory authority;
- automated decision-making where applicable.
This information is commonly provided through website privacy notices, employee notices, applicant notices, customer information documents and other targeted notices.
However, a privacy notice must reflect actual processing activities. A generic document that does not match the organisation’s practices may create legal and reputational risk rather than genuine compliance.
What documentation may be required?
The documents required will depend on the organisation and its processing activities.
A GDPR compliance system may include:
- records of processing activities;
- privacy notices;
- employee data protection notices;
- cookie information;
- data processing agreements;
- internal data protection policies;
- data retention rules;
- procedures for data subject requests;
- personal data breach procedures;
- legitimate interest assessments;
- consent forms where consent is appropriate;
- data protection impact assessments;
- security procedures;
- documentation regulating international transfers.
Documents should not exist only to satisfy a checklist. They must describe and support the organisation’s actual procedures.
When an organisation considers what is the GDPR?, it should also examine whether its documentation matches the way personal data is really processed in practice.
What is the role of processors and service providers?
Many organisations use external service providers for hosting, cloud storage, payroll, accounting, marketing, newsletters, customer support, analytics or software services.
When a service provider processes personal data on behalf of an organisation, the parties may have a controller–processor relationship. In such cases, the relationship generally needs to be regulated through an appropriate data processing agreement.
The organisation should also assess:
- what data the service provider receives;
- why the provider needs the data;
- where the data is stored;
- whether subcontractors are used;
- what security measures are applied;
- whether data is transferred outside the European Economic Area;
- what happens to the data when the service ends.
Using a well-known platform does not remove the organisation’s responsibility to understand how its personal data is processed.
What should happen after a personal data breach?
A personal data breach may involve accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
Examples may include:
- sending personal data to the wrong recipient;
- losing a device containing personal data;
- unauthorised access to an account;
- ransomware;
- publishing personal data accidentally;
- losing paper records;
- an employee accessing information without authorisation.
An organisation should have a procedure for identifying, containing, assessing and documenting a breach.
Depending on the level of risk, the GDPR may require notification to the competent supervisory authority and, in some situations, communication with affected individuals.
The organisation should not wait for a breach to occur before deciding who is responsible and what steps must be taken.
GDPR compliance as a business advantage
The GDPR is often discussed only in relation to fines and inspections. However, responsible data processing can also provide practical business value.
An organisation that handles personal data transparently can build stronger trust with:
- clients;
- employees;
- users;
- customers;
- donors;
- business partners;
- public authorities.
Clear procedures also reduce uncertainty within the organisation. Employees know what information they may collect, where it should be stored, who may receive it and how long it should be retained.
For organisations using newsletters, customer databases, cloud services, online forms, video surveillance or automated tools, privacy is part of professional and responsible business conduct.
What should companies and institutions do first?
The first step should not be copying template documents.
The organisation should first map its actual data-processing activities.
It should identify:
- what categories of personal data it processes;
- whose personal data it processes;
- why the data is processed;
- what legal basis applies;
- where the data is collected from;
- where it is stored;
- who has access to it;
- which service providers receive it;
- whether international transfers occur;
- how long the data is retained;
- what security measures are in place;
- how individuals can exercise their rights.
Only after this assessment can the organisation prepare documentation that accurately reflects its business operations.
The European Data Protection Board guidelines provide additional guidance, recommendations and best practices for the consistent application of EU data protection law.
Understanding what is the GDPR? is therefore the first step towards creating a structured and effective data protection compliance system.

How can we help with GDPR compliance?
Understanding what is the GDPR is only the first step. The greater challenge is applying its rules to real business processes.
Organisations commonly need answers to questions such as:
- What personal data do we actually process?
- Which legal basis should we use?
- Do we need consent?
- Are our privacy notices accurate?
- Do we need data processing agreements?
- Are our service providers properly regulated?
- How should we respond to data subject requests?
- Do we need a data protection impact assessment?
- What should we do if a personal data breach occurs?
- How long may we retain specific categories of data?
Kec grupa can provide support in assessing existing processing activities, identifying legal and organisational risks and preparing practical data protection documentation.
Our approach focuses on documents and procedures that correspond to actual business operations rather than generic templates.
Support may include:
- assessment of existing compliance;
- mapping of personal data processing;
- privacy notices;
- records of processing activities;
- employee data protection notices;
- data processing agreements;
- internal policies;
- procedures for data subject requests;
- personal data breach procedures;
- retention rules;
- GDPR-related documentation.
For additional education on practical data protection responsibilities, see our DPO training programme.
What is the GDPR – conclusion
What is the GDPR? It is a comprehensive legal framework that regulates how organisations process personal data and protects the rights of individuals.
Compliance requires more than publishing a privacy notice. It involves understanding data flows, identifying lawful purposes, applying security measures, regulating service providers, responding to individual rights and maintaining accurate documentation.
Every organisation should be able to explain:
- what data it processes;
- why it processes that data;
- how long the data is retained;
- who has access to it;
- which service providers receive it;
- how the data is protected;
- how individuals can exercise their rights.
A structured GDPR compliance system reduces legal risk, strengthens internal procedures and helps build trust with clients, employees and business partners.
How we can help?
GDPR compliance often appears simple until an organisation starts asking practical questions.
What personal data do we actually process? What is our legal basis for processing? Do we need consent, or do we rely on another lawful basis? Do we have proper privacy notices? Do we have data processing agreements with service providers? Do our internal procedures actually work in practice? Are we prepared to respond to data subject requests? Do we know what to do in the event of a personal data breach?
This is exactly where we can help.
Our team can provide professional support in assessing your current level of compliance, identifying potential risks and preparing the documentation required for a structured and practical data protection compliance system.
We focus on practical solutions, not documents that exist only formally. Our goal is to help companies and institutions establish a system that reflects their real business operations and their actual data processing activities.
We can assist with the preparation and adjustment of privacy notices, records of processing activities, employee data protection notices, data processing agreements, internal policies, procedures for handling data subject rights, procedures for personal data breaches and other GDPR-related documentation.
If you are not sure whether your company or institution is compliant with the GDPR, the first step is to understand how you actually process personal data. We can help you make that process clear, legally structured and applicable in practice.
Official sources used: European Commission, EUR-Lex, European Data Protection Board and European Data Protection Supervisor.
