GDPR GDPR
GDPR is the European law that sets out how a business may collect, keep and use the personal information of the people it serves.
Also known as General Data Protection Regulation EU data protection law data privacy law
Definition
GDPR is a European law about personal information, and personal information means anything that points to a living person. That takes in a name, an email address, a phone number, a photo, even a list of past orders. Because the net is that wide, the law asks only three plain things of you. You keep the information for a clear reason, you keep it safe, and you hand it over or delete it when the person asks.
The part everyone remembers is the 72 hours. If personal information is lost or stolen and that loss could harm someone, you have three days to tell the data protection authority. The clock starts the moment you notice, not the moment you finish working out what happened. You warn the people themselves as well when the risk to them is high, and the deadline is short on purpose. That is why deciding today who makes that call in your business matters more than any policy document in a drawer.
You do not have to be in Europe, because the law follows the person and not the company. A shop in Cairo that posts orders to Germany is inside it, and so is a clinic in Dubai with British patients. The same goes for a school selling courses to families in France. If you serve only customers at home and never aim at Europe, though, you are outside it. And a website that a European can happen to visit does not change that on its own.
Your own country probably has a law of its own by now, and they rhyme with each other. Egypt's Law 151 of 2020 asks for consent, for care, and for a named person who is responsible. Saudi Arabia and the United Arab Emirates have their versions, and Turkey has had one since 2016. The wording differs, but the habits they ask for are the same. Collect less, keep it for less time, lock it properly, and be able to say who can see it.
In practice this is a building question more than a legal one. When Linkysoft starts a web application, we ask which fields the business truly needs, because a field you never collect can never leak. The piece that is painful to add later is removing one customer completely, from every table, every report and every backup. So Linkysoft treats that and the 72-hour question as part of the cybersecurity plan, not as paperwork at the end.
Questions about GDPR
Does GDPR apply to my business outside Europe?
What does the 72-hour rule actually mean?
Do I need a cookie banner on my website?
What are the fines really like for a small business?
Can a customer ask me to delete everything about them?
Still not sure how this applies to your project?
Tell us what you are building and we will answer in plain language.