Cybersecurity Glossary

GDPR

The European data protection regulation governing how personal data is handled.

What GDPR means

The General Data Protection Regulation requires a lawful basis for processing personal data, transparency about what you collect, respect for individual rights, appropriate security, and notification of certain breaches within seventy two hours. It applies to organisations outside Europe when they target or monitor people inside it.

Why GDPR matters for small businesses and nonprofits

A United States business with a German entity, European clients or European website visitors is in scope. The practical requirements are a clear privacy notice, a record of processing, a lawful basis for marketing, and a breach process that can move within three days.

What to do about GDPR

Three steps to deal with GDPR

  • Keep a record of what personal data you hold, why, and for how long
  • Make sure your privacy notice matches the tools your site actually runs
  • Ensure your incident plan can meet the seventy two hour notification deadline

Not sure where you stand on this?

We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.