GDPR in a Nutshell

Our “Did You Know?” section offers bite-sized facts that simplify complex GDPR rules into easy-to-understand nuggets of information. Learn something new, one fact at a time. We’re regularly adding more facts, so check back often to stay updated!

GDPR in a Nutshell

You must be able to prove your retention rules
Accountability under GDPR means a company must be able to demonstrate and document why it keeps personal data for as long as it does - "we've always done it this way" isn't a defence.

GDPR in a Nutshell

There is no set shelf life for your data
GDPR doesn't set a fixed retention period - instead, personal data can only be kept for as long as it's actually needed for the purpose it was collected for.

GDPR in a Nutshell

Seven principles run through GDPR
Every GDPR obligation traces back to seven core principles: lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability.

GDPR in a Nutshell

GDPR does not stop at Europe's borders.
Non-EU companies that offer goods or services to, or monitor the behaviour of, people in the EU must comply with GDPR - regardless of where the company itself is based.

GDPR in a Nutshell

GDPR stands for the General Data Protection Regulation.
The GDPR is an EU regulation that safeguards privacy rights while ensuring organizations process personal data lawfully and fairly. It sets clear principles for data handling, helping businesses build trust and demonstrate accountability, without imposing disproportionate burdens.