GDPR GDPR

GDPR is the European law that sets out how a business may collect, keep and use the personal information of the people it serves.

Also known as General Data Protection Regulation EU data protection law data privacy law

Definition

GDPR is a European law about personal information, and personal information means anything that points to a living person. That takes in a name, an email address, a phone number, a photo, even a list of past orders. Because the net is that wide, the law asks only three plain things of you. You keep the information for a clear reason, you keep it safe, and you hand it over or delete it when the person asks.

The part everyone remembers is the 72 hours. If personal information is lost or stolen and that loss could harm someone, you have three days to tell the data protection authority. The clock starts the moment you notice, not the moment you finish working out what happened. You warn the people themselves as well when the risk to them is high, and the deadline is short on purpose. That is why deciding today who makes that call in your business matters more than any policy document in a drawer.

You do not have to be in Europe, because the law follows the person and not the company. A shop in Cairo that posts orders to Germany is inside it, and so is a clinic in Dubai with British patients. The same goes for a school selling courses to families in France. If you serve only customers at home and never aim at Europe, though, you are outside it. And a website that a European can happen to visit does not change that on its own.

Your own country probably has a law of its own by now, and they rhyme with each other. Egypt's Law 151 of 2020 asks for consent, for care, and for a named person who is responsible. Saudi Arabia and the United Arab Emirates have their versions, and Turkey has had one since 2016. The wording differs, but the habits they ask for are the same. Collect less, keep it for less time, lock it properly, and be able to say who can see it.

In practice this is a building question more than a legal one. When Linkysoft starts a web application, we ask which fields the business truly needs, because a field you never collect can never leak. The piece that is painful to add later is removing one customer completely, from every table, every report and every backup. So Linkysoft treats that and the 72-hour question as part of the cybersecurity plan, not as paperwork at the end.

Questions about GDPR

Does GDPR apply to my business outside Europe?
It applies if you sell to people in Europe or track how they behave, wherever your office is. Serving only local customers keeps you outside it, though your own national law still counts.
What does the 72-hour rule actually mean?
From noticing a serious loss of personal data you have three days to report it, even while you are still investigating. Send what you know and update it later.
Do I need a cookie banner on my website?
Only for cookies the site does not need to work, such as advertising or visitor tracking. A banner that offers no real choice is worse than no banner.
What are the fines really like for a small business?
The headline millions are for large firms. Small companies are far more often ordered to fix the problem and to tell their customers, and that clean-up is the real cost.
Can a customer ask me to delete everything about them?
Yes, unless another law makes you keep the record, such as tax or medical rules. Deleting from reports and backups as well is the part most systems handle badly.

Still not sure how this applies to your project?

Tell us what you are building and we will answer in plain language.