Glossary · simply explained

GDPR (General Data Protection Regulation)

The General Data Protection Regulation (GDPR) is the EU-wide legal framework for processing personal data. It obliges companies to principles such as purpose limitation, data minimisation and transparency — and requires technical and organisational measures appropriate to the risk.

For IT leaders the GDPR is not a purely legal topic: encryption, access control, deletion concepts, incident notification readiness and clean provider contracts are technical tasks with legal effect.

What the GDPR requires technically

Article 32 demands security of processing according to the state of the art: encryption, pseudonymisation, access control following least privilege, resilience of systems and regular effectiveness testing. In case of a breach, a 72-hour clock runs for notifying the supervisory authority — those who do not detect incidents cannot report them in time.

As soon as providers process personal data, data processing agreements are required; for transfers to third countries, suitable safeguards on top. For cloud services this practically means: know and control processing locations — via EU regions or the providers’ regional services features, for example.

GDPR touchpoints in infrastructure

  • Access control and logging: who accessed which data and when?
  • Notification readiness: detection and processes for the 72-hour deadline.
  • Data flows to providers: DPAs and processing locations in view.
  • Deletion concepts that also consider backups and archives.

Frequently asked questions about GDPR (General Data Protection Regulation)

What is personal data under the GDPR?

All information relating to an identified or identifiable person — from names via email and IP addresses to behavioural data. Pseudonymised data also remains personal as long as attribution is possible.

What does Article 32 specifically require of IT?

Measures appropriate to the risk according to the state of the art: encryption, access control, availability and resilience, recoverability after incidents and regular effectiveness testing. The selection must be justified and documented.

Which deadlines apply to a data breach?

Notification to the supervisory authority must happen without undue delay, where feasible within 72 hours of becoming aware; at high risk, data subjects must be informed as well. Detection capability is the prerequisite — unnoticed incidents still start the clock.

Is using US cloud services possible in a GDPR-compliant way?

In principle yes, with the right safeguards: adequacy decisions such as the EU-US Data Privacy Framework, standard contractual clauses and technical measures such as EU processing regions. Assessing the individual case belongs to the data protection officer.

What does the GDPR have to do with network security?

A lot: access control, segmentation, encryption and incident detection are simultaneously data protection measures under Article 32. Running network and access cleanly fulfils a substantial part of the technical GDPR duties along the way.

Wondering how this looks in your own network? Talk to KAEMI: we plan, build and manage the right solution with you.