{"id":19586,"date":"2026-08-31T11:34:11","date_gmt":"2026-08-31T09:34:11","guid":{"rendered":"https:\/\/teamwire.eu\/en\/?post_type=lexicon&#038;p=19586"},"modified":"2026-08-31T11:34:11","modified_gmt":"2026-08-31T09:34:11","slug":"gdpr-compliance","status":"publish","type":"lexicon","link":"https:\/\/teamwire.eu\/en\/lexicon\/gdpr-compliance\/","title":{"rendered":"GDPR compliance"},"content":{"rendered":"<h2>What is the GDPR?<\/h2>\n<p>The General Data Protection Regulation (GDPR) is a European Union regulation governing the protection of personal data of natural persons. It came into force on 25 May 2018 and applies to all organisations that process data relating to EU citizens, regardless of where the organisation is based. The GDPR aims to harmonise data protection across the EU and to strengthen the rights of data subjects.<\/p>\n<p>The regulation establishes clear rules that organisations must follow when processing personal data. These include transparency obligations, the requirement to obtain consent, and the implementation of appropriate security measures.<\/p>\n<p>&nbsp;<\/p>\n<h2>Why is GDPR compliance important?<\/h2>\n<p>GDPR compliance is of great importance to organisations \u2014 not only because it is a legal obligation, but because it also strengthens customer trust. Organisations must ensure they comply with the GDPR for the following reasons:<\/p>\n<ul>\n<li><strong>Avoiding penalties:<\/strong> Violations of the GDPR can result in significant fines of up to \u20ac20 million or 4% of global annual turnover, whichever is higher.<\/li>\n<li><strong>Customer trust:<\/strong> Compliance with the GDPR demonstrates that an organisation takes its customers&#8217; privacy seriously, leading to higher customer satisfaction and loyalty.<\/li>\n<li><strong>Competitive advantage:<\/strong> Organisations that operate in compliance with the GDPR can differentiate themselves from competitors that do not.<\/li>\n<\/ul>\n<p>The importance of GDPR compliance cannot be overstated.<\/p>\n<p>&nbsp;<\/p>\n<h2>What personal data is covered?<\/h2>\n<p>The GDPR protects personal data that relates to an identified or identifiable natural person. This includes:<\/p>\n<ul>\n<li><strong>Identification data:<\/strong> Name, address, date of birth, telephone number and email address.<\/li>\n<li><strong>Financial data:<\/strong> Bank account details, credit card information and other financial information.<\/li>\n<li><strong>Health data:<\/strong> Information about a person&#8217;s state of health, such as medical history.<\/li>\n<li><strong>Behavioural data:<\/strong> Data collected through the use of websites and applications, such as cookies.<\/li>\n<\/ul>\n<p>It is important to understand that pseudonymised data also falls within the scope of the GDPR, as long as the identification of the individual remains possible.<\/p>\n<p>&nbsp;<\/p>\n<h2>What are the obligations of organisations?<\/h2>\n<p>Organisations must fulfil a range of obligations to ensure GDPR compliance. These include:<\/p>\n<ul>\n<li><strong>Transparency:<\/strong> Organisations must explain clearly and comprehensibly to data subjects how their data is being processed.<\/li>\n<li><strong>Consent:<\/strong> Consent to the processing of personal data must be freely given, specific, informed and unambiguous.<\/li>\n<li><strong>Security measures:<\/strong> Organisations must implement appropriate technical and organisational measures to ensure the security of the data.<\/li>\n<li><strong>Documentation:<\/strong> Processing activities must be documented in order to demonstrate compliance with the GDPR in the event of an audit by the supervisory authority.<\/li>\n<\/ul>\n<p>These obligations are essential for ensuring legal compliance and building customer trust.<\/p>\n<p>&nbsp;<\/p>\n<h2>How is consent to data processing obtained?<\/h2>\n<p>Consent to the processing of personal data is a central element of the GDPR. To be legally compliant, organisations must ensure that:<\/p>\n<ul>\n<li><strong>Consent is freely given:<\/strong> The data subject must not be pressured into providing their data.<\/li>\n<li><strong>Consent is specific:<\/strong> It must clearly state the purposes for which the data will be processed.<\/li>\n<li><strong>Consent is informed:<\/strong> The data subject must be provided with all relevant information, including any potential risks.<\/li>\n<li><strong>Consent is revocable:<\/strong> Data subjects must be able to withdraw their consent at any time.<\/li>\n<\/ul>\n<p>A cookie banner on a website is a common example of how consent is obtained in practice under the GDPR.<\/p>\n<p>&nbsp;<\/p>\n<h2>What are the rights of data subjects?<\/h2>\n<p>The GDPR grants particular importance to the rights of data subjects. These include:<\/p>\n<ul>\n<li><strong>Right of access:<\/strong> Data subjects have the right to find out what data is held about them and for what purpose it is being processed.<\/li>\n<li><strong>Right to rectification:<\/strong> Individuals may request the correction of inaccurate or incomplete data.<\/li>\n<li><strong>Right to erasure:<\/strong> Under certain conditions, data subjects have the right to request the deletion of their data.<\/li>\n<li><strong>Right to restriction of processing:<\/strong> In certain circumstances, individuals may request that the processing of their data be restricted.<\/li>\n<li><strong>Right to data portability:<\/strong> Data subjects have the right to receive their data in a structured, commonly used and machine-readable format.<\/li>\n<\/ul>\n<p>These rights are essential for protecting privacy and maintaining control over one&#8217;s own data.<\/p>\n<p>&nbsp;<\/p>\n<h2>What penalties apply in the event of violations?<\/h2>\n<p>Violations of the GDPR can result in significant penalties. These may take the form of financial fines or other legal consequences:<\/p>\n<ul>\n<li><strong>Fines:<\/strong> The GDPR provides for fines of up to \u20ac20 million or 4% of global annual turnover, whichever is higher.<\/li>\n<li><strong>Publication of violations:<\/strong> In cases of serious violations, organisations may be required to disclose the breach publicly, which can cause considerable reputational damage.<\/li>\n<li><strong>Compensation claims:<\/strong> Data subjects may seek compensation for the loss or unlawful processing of their data.<\/li>\n<\/ul>\n<p>These potential consequences make compliance with the GDPR&#8217;s requirements essential.<\/p>\n<p>&nbsp;<\/p>\n<h2>How can a Data Protection Officer help?<\/h2>\n<p>A Data Protection Officer (DPO) can support organisations in meeting the requirements of the GDPR. The role of the DPO includes:<\/p>\n<ul>\n<li><strong>Advisory function:<\/strong> The DPO advises the organisation on all matters relating to data protection and GDPR compliance.<\/li>\n<li><strong>Monitoring:<\/strong> The DPO monitors compliance with data protection regulations and conducts regular training sessions for staff.<\/li>\n<li><strong>Point of contact:<\/strong> The DPO acts as the contact point for data subjects and supervisory authorities.<\/li>\n<\/ul>\n<p>The appointment of a Data Protection Officer is a legal requirement for many organisations, particularly those that process large volumes of personal data.<\/p>\n<p>&nbsp;<\/p>\n<h2>What is a record of processing activities?<\/h2>\n<p>A record of processing activities is an important document that captures all of an organisation&#8217;s processing activities. It contains information such as:<\/p>\n<ul>\n<li><strong>Purpose of processing:<\/strong> Why is the data being processed?<\/li>\n<li><strong>Categories of personal data:<\/strong> What data is being collected?<\/li>\n<li><strong>Recipients of the data:<\/strong> To whom is the data being disclosed?<\/li>\n<li><strong>Retention period:<\/strong> How long will the data be stored?<\/li>\n<\/ul>\n<p>The record of processing activities serves as evidence of GDPR compliance and must be made available to the supervisory authority upon request.<\/p>\n<p>&nbsp;<\/p>\n<h2>What technical and organisational measures are required?<\/h2>\n<p>To ensure GDPR compliance, organisations must implement appropriate technical and organisational measures (TOMs). These include:<\/p>\n<ul>\n<li><strong>Technical measures:<\/strong> Encryption, firewalls, access controls and regular security audits.<\/li>\n<li><strong>Organisational measures:<\/strong> Staff training, clear data processing policies and the appointment of a Data Protection Officer.<\/li>\n<\/ul>\n<p>Implementing these measures is essential for ensuring the security of personal data and meeting the requirements of the GDPR.<\/p>\n<p>&nbsp;<\/p>\n<h2>Key takeaways<\/h2>\n<ul>\n<li>The GDPR protects personal data and has been in force since May 2018.<\/li>\n<li>GDPR compliance is important for avoiding penalties and building customer trust.<\/li>\n<li>Organisations must provide transparent information about how personal data is processed.<\/li>\n<li>Consent to data processing must be freely given, specific and informed.<\/li>\n<li>Data subjects have rights including access, rectification and erasure of their data.<\/li>\n<li>Violations of the GDPR can result in significant fines and reputational damage.<\/li>\n<li>A Data Protection Officer can help organisations comply with the GDPR.<\/li>\n<li>A record of processing activities is necessary to demonstrate GDPR compliance.<\/li>\n<li>Technical and organisational measures are essential for protecting personal data.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>What is the GDPR? The General Data Protection Regulation (GDPR) is a European Union regulation governing the protection of personal data of natural persons. It came into force on 25 May 2018 and applies to all organisations that process data relating to EU citizens, regardless of where the organisation is based. The GDPR aims to [&hellip;]<\/p>\n","protected":false},"featured_media":19652,"template":"","class_list":["post-19586","lexicon","type-lexicon","status-publish","has-post-thumbnail","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/teamwire.eu\/en\/wp-json\/wp\/v2\/lexicon\/19586","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teamwire.eu\/en\/wp-json\/wp\/v2\/lexicon"}],"about":[{"href":"https:\/\/teamwire.eu\/en\/wp-json\/wp\/v2\/types\/lexicon"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teamwire.eu\/en\/wp-json\/wp\/v2\/media\/19652"}],"wp:attachment":[{"href":"https:\/\/teamwire.eu\/en\/wp-json\/wp\/v2\/media?parent=19586"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}