Guide

GDPR: Rights and Responsibilities

GDPR sets privacy rights for people and data duties for many businesses.

GDPR: Rights and Responsibilities

What GDPR means

GDPR stands for General Data Protection Regulation. It is a privacy law that has applied since May 25, 2018. It sets rules for how personal data is collected, used, stored, and shared. Its main aim is to protect people’s personal information and give them more control over it.

The rules apply across the European Union and the European Economic Area (EEA). They can also apply to a company based elsewhere if it offers goods or services to people in the EU, or tracks their behaviour there. So, a business does not escape the rules simply because its office is in the United States or another country.

Personal data means information that identifies a person, either on its own or when combined with other details. Names, email addresses, location data, online identifiers, and payment details can all count. Some data, such as health details or political views, receives extra protection. The full rules appear in the official GDPR text on EUR-Lex.

The principles behind GDPR

Blank stacked paper and a brass weight on a softly lit stone surface
Orderly blank papers with warm brass detail

GDPR is built on principles that shape every stage of data use. Businesses need a lawful reason to use personal data. They must also handle it fairly and explain their practices in plain language. These duties make transparency a core part of data privacy.

Purpose limitation means data should be gathered for clear, stated reasons. A business should not quietly reuse it for a new aim that does not fit those reasons. Data minimization means collecting only what the task needs. Accuracy means taking reasonable steps to keep records correct and up to date.

Storage limitation means not keeping personal data longer than needed. Security means protecting it from loss, theft, or access by people who should not see it. Accountability means a business must be able to show how it follows the rules. These are the nine core principles:

  • Lawfulness, fairness, and transparency
  • Purpose limitation
  • Data minimization
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality, which includes security
  • Accountability

The first principle groups three linked duties, while security is often used as a plain term for integrity and confidentiality. Together, these principles guide decisions about data collection, access, retention, and sharing.

Rights people have over their data

GDPR gives people rights over personal data held about them. A person can ask a business whether it uses their data and request a copy. They can seek a correction if details are wrong. In some cases, they can ask the business to delete their data.

People may also ask a business to limit how it uses their data. They can object to certain uses, such as direct marketing. Data portability lets a person request their data in a common digital form and, in some cases, move it to another provider. These rights have limits and do not mean every request must always be granted.

A business must respond within one month in most cases. It can extend the time by up to two more months for complex or numerous requests, but it must explain the delay. The person may need to confirm their identity. If they believe a business has mishandled their data, they can complain to a data protection authority.

Consent is one possible legal basis for using data, but it is not the only one. A business may rely on a contract, a legal duty, or another basis allowed by the law. When consent is used, it must be freely given, clear, and easy to withdraw.

What GDPR means for businesses

A closed blank folder and fountain pen on a dark wood tabletop
A considered still life for business data care

GDPR affects businesses that process data about people in the EU, even when the business operates abroad. It does not make every US company subject to the rules. A US company may fall within scope if it sells to EU residents, provides a service to them, or tracks their online behaviour in the EU.

For a business in scope, the rules affect more than its privacy notice. It needs to map the personal data it holds, know why it uses each type, and limit access to staff who need it. It should set clear retention periods and remove data when there is no sound reason to keep it.

Businesses also need to tell consumers what data they collect, why they use it, who receives it, and how long they keep it. They should use plain wording rather than broad claims. Clear information helps people make choices and can build trust in how the business handles data.

Some firms must name a data protection officer, based on their work and the scale or nature of their data use. A business may also need a written impact check before starting high-risk data use. If an outside firm handles data for it, the parties need a contract that sets out each side’s duties.

Core steps for meeting GDPR rules

Good compliance starts with a clear record of data use. List the data, its source, its purpose, who can see it, and how long it stays on file. Then check that each use has a valid legal basis. Keep evidence of those choices and review the record when the work changes.

Businesses should give people an easy way to use their rights. Staff need to know where requests go and who checks them. Set a process to find the data, confirm the requester, assess any limits, and send a timely reply. Keep a record of the request and the steps taken.

Security measures should match the risk. Useful steps can include access controls, staff training, secure backups, and a plan for handling data breaches. Under GDPR, a breach that risks people’s rights and freedoms may need to be reported to the relevant authority within 72 hours of awareness. Some breaches must also be reported to affected people.

Fines can be high. For serious breaches, the top tier is up to €20 million or 4% of the company’s total worldwide annual turnover from the prior financial year, whichever is higher. Other breaches can carry fines up to €10 million or 2% of turnover. The exact level depends on the breach and the factors set out in the law.

What GDPR means for consumers

For consumers, GDPR means a company should explain its use of personal data before or when it collects that data. You should be able to find out what the company holds and why it uses it. You can also ask for a correction, deletion, or limit on use when the law gives you that right.

Start by contacting the business through its privacy contact or support channel. State the right you want to use and give enough detail to help it find your records. Avoid sending extra sensitive details unless needed to confirm who you are. Keep a copy of your request and the reply.

If the answer is unclear or you think the company has not followed the rules, ask it to explain its decision. You can then contact the data protection authority in the place where you live or work, or where the issue happened. GDPR gives you a route to raise concerns, but it does not promise that every request will lead to deletion.

GDPR in simple terms

What does GDPR mean in simple terms? It means companies need a proper reason to use your personal data, must tell you what they are doing, and must keep the data safe. You have rights to see and correct data, and sometimes to delete it or limit its use.

For businesses, the short version is just as direct: collect less, explain more, protect what you hold, and be ready to show your work. For consumers, the key point is that your personal information is not free for any use a company chooses. The law sets rules, rights, and consequences when those rules are broken.

Frequently asked questions

What does GDPR mean?
GDPR means General Data Protection Regulation. It is an EU privacy law that sets rules for using personal data and gives people rights over that data.
What does GDPR mean for consumers?
It means companies must explain how they use personal data. Consumers can ask to access or correct data, and may have the right to delete it or limit its use.
What does GDPR mean for US companies?
A US company may need to follow GDPR if it offers goods or services to people in the EU, or tracks their behaviour there. Being based in the United States does not by itself rule out GDPR duties.
What does GDPR mean in simple terms?
Companies need a valid reason to use personal data, must tell people what they do with it, and must protect it. People gain rights to see, correct, and sometimes remove or restrict their data.
What is the maximum GDPR fine?
For the most serious breaches, the maximum is €20 million or 4% of total worldwide annual turnover from the prior financial year, whichever is higher. The actual fine depends on the case.
personal data rightsEU privacy lawdata protection rulesconsumer data privacyGDPR compliance steps

Related reading

Cookies

We keep a small number of cookies to run this site and to see which briefings get read. You decide which. Details in our Cookie Policy.