GDPR GDPR

The European rule that says you keep customer data for a clear reason, guard it, and report a serious loss within three days.

Also known as General Data Protection Regulation EU data protection law data privacy law

Definition

GDPR is a European law about personal information. Personal information means anything that points to a living person. A name, an email address, a phone number, a photo, a list of past orders. The law asks three things of you. Keep that information for a clear reason, keep it safe, and hand it over or delete it when the person asks.

The part people remember is the 72 hours. If personal information is lost or stolen and the loss could harm someone, you have three days to tell the data protection authority. Three days from the moment you notice, not from the moment you finish working out what happened. If the risk to people is high, you tell them as well. Three days is short on purpose. That is why deciding now who makes that call in your business matters more than any policy document in a drawer.

You do not have to be in Europe. The law follows the person, not the company. A shop in Cairo that posts orders to Germany is inside it. So is a clinic in Dubai with British patients, and a school selling courses to families in France. If you serve only customers at home and never aim at Europe, you are outside it. A website Europeans can happen to visit is not enough on its own.

Your own country probably has a law of its own now, and they rhyme. Egypt's Law 151 of 2020 asks for consent, care and a named person who is responsible. Saudi Arabia and the United Arab Emirates have their versions, and Turkey has had one since 2016. The wording differs. The habits they ask for are the same. Collect less, keep it for less time, lock it properly, and be able to say who can see it.

In practice this is a building question more than a legal one. When Linkysoft starts a web application, we ask which fields the business truly needs, because a field you never collect can never leak. Removing one customer completely, from every table, report and backup, is the piece that is painful to add later. Linkysoft treats that and the 72-hour question as part of the cybersecurity plan, not as paperwork at the end.

Questions about GDPR

Does GDPR apply to my business outside Europe?
It applies if you sell to people in Europe or track how they behave, wherever your office is. Serving only local customers keeps you outside it, though your own national law still counts.
What does the 72-hour rule actually mean?
From noticing a serious loss of personal data you have three days to report it, even while you are still investigating. Send what you know and update it later.
Do I need a cookie banner on my website?
Only for cookies the site does not need to work, such as advertising or visitor tracking. A banner that offers no real choice is worse than no banner.
What are the fines really like for a small business?
The headline millions are for large firms. Small companies are far more often ordered to fix the problem and to tell their customers, and that clean-up is the real cost.
Can a customer ask me to delete everything about them?
Yes, unless another law makes you keep the record, such as tax or medical rules. Deleting from reports and backups as well is the part most systems handle badly.

Still not sure how this applies to your project?

Tell us what you are building and we will answer in plain language.