Cyber & Data Security

What is GDPR?

This article was updated on:
Aug 20th, 2018

Let’s start with those 4 letters that are everywhere at the moment:

General Data Protection Regulation or GDPR as its commonly known as.

So, what is GDPR and why is it so important?

GDPR is an EU regulation (Brexit changes nothing by the way) that has been created because of the increase in the amount of data being created.  Furthermore, the ways in which it can be used are not covered in the currently dated acts and regulations.  

The UK has the Data Protection Act 1998 currently which was enacted following an EU directive and that will be superseded by this new regulation.

What are The Main Differences?

  1. If your business is not in the EU, you will still have to comply with the Regulation – it’s worldwide if you deal with any EU Citizens!  
  2. The definition of Personal Data is broader, bringing more data into scope.
  3. Parental consent is required to process the data of children.
  4. There are changes to the rules on obtaining valid consent for the use of data.
  5. The appointment of a Data Protection Officer will be mandatory for some businesses.
  6. Introduction of mandatory privacy risk impact assessments.
  7. There are new Data Breech reporting requirements
  8. Users have new rights (and lots of them).

When does it apply from?

The regulation became law on the 25th May 2018, but it has been finalised since 26th May 2016.  

Who does GDPR Apply to?

The regulation divides you into data controllers and data processors. A data controller decides how and why personal data is processed, while a processor can be a party doing the actual processing of the data. So, the controller could be any organisation. A processor could be a third-party company doing the actual data processing. It is your responsibility as the controller to ensure the processor is acting within the regulation.

Even if you are based outside the EU, GDPR will still apply to you if you are handling the data of any EU citizen.  

Summary

That’s a very brief intro to GDPR and as such there are still many areas that need to be covered, but hopefully that’s given you an idea as to what GDPR is all about and to help you move forward with.  

As with most regulations, it’s all about guidance and not much specifics. Our advice for now is to show willing and the ICO won’t be coming down on you with the harshest penalties. Have you taken the ICO’s 12 Steps to GDPR? Have you taken technical measures such as getting Cyber Essentials certified etc?  

For more information on what Cyber Essentials is and the benefits of becoming certified (we can certify you), please see our article HERE.

Keen to learn more? Explore our other related resources below:
December 13, 2025
Password ‘Sextortion’ and Ransomware
Cyber & Data Security
July 1, 2025
How Might Hackers Exploit My Cyber Security? 7 Tricks Small Business Owners Need-To-Know!
Cyber & Data Security
May 1, 2025
MFA Isn’t Optional Anymore: Here’s Why
Cyber & Data Security
IT Management, Policies & Certifications
April 1, 2025
Why Digital Offboarding Needs to Be on Your Radar!
Cyber & Data Security
February 12, 2025
Upgrading to Windows 11: It’s ESSENTIAL, Let us explain why!
Cyber & Data Security
February 1, 2025
11 Simple Steps to Keep Your Microsoft 365 Data Safe
Cyber & Data Security
Microsoft 365
May 23, 2022
The 5 Benefits of Outsourcing IT Support
IT Management, Policies & Certifications
Cyber & Data Security
May 12, 2021
Cyber Essentials Toolkit
Cyber & Data Security
April 19, 2021
Why your Business needs Microsoft 365 Backup
IT Management, Policies & Certifications
Cyber & Data Security
March 4, 2021
Is Microsoft 365 Secure? Our 5 Essential Tips to Stay Safe
Microsoft 365
Cyber & Data Security
February 1, 2021
Free Cyber Security Awareness Training!
Cyber & Data Security
December 20, 2020
Why Do Businesses Only Care About Cyber Security Once They Get Hacked?
Cyber & Data Security
October 17, 2019
Ransomware – Should You Be Worried? 
Cyber & Data Security
August 12, 2019
Identity Fraud - Easier Than Ever
Cyber & Data Security
March 28, 2019
Invoice Diversion Scenario
Cyber & Data Security
March 26, 2019
Phishing/Ransom Attack Scenario, What Would You Do?
Cyber & Data Security
March 13, 2019
The difference between Cyber Essentials and Cyber Essentials PLUS
Cyber & Data Security
December 4, 2018
What is the Difference Between Penetration Testing and Vulnerability Scanning?
IT Management, Policies & Certifications
Cyber & Data Security
November 28, 2018
How Secure is My Password?
Cyber & Data Security
November 2, 2018
How much help do I need to get Cyber Essentials Certified?
Cyber & Data Security
October 23, 2018
What is an SSL certificate and why do I need one?
IT Management, Policies & Certifications
Cyber & Data Security
October 3, 2018
Defining the Scope for Cyber Essentials
Cyber & Data Security
October 1, 2018
Is it time to switch your IT partner?
Cyber & Data Security
October 1, 2018
The Facebook Breach: This is What You Need to do NOW...
Cyber & Data Security
September 20, 2018
Email Spoofing Scenario
IT Management, Policies & Certifications
Cyber & Data Security
August 24, 2018
What is OneDrive and why should my business be using it? 
Telecoms & Connectivity
Cyber & Data Security
August 15, 2018
Server VS Cloud - Which is best for your business?
Telecoms & Connectivity
Cyber & Data Security
August 14, 2018
Why Should I get my business Cyber Essentials certified?
Cyber & Data Security
August 14, 2018
How Much Does Outsourced IT Support Cost in 2023?
IT Management, Policies & Certifications
Cyber & Data Security
May 1, 2018
The Difference between NCSC Small Business Guide & Cyber Essentials
Cyber & Data Security
December 2, 2017
Cyber Essentials Certification: Everything You Need to Know
Cyber & Data Security
January 22, 2009
Are there any substitutes to ISO 27001 suitable for my business?
Cyber & Data Security
IT Management, Policies & Certifications