General Data Protection Regulation: What It Actually Covers and Why It’s Easy to Get Wrong
Introduction
General Data Protection Regulation, better known as GDPR, is a European Union regulation on how organizations must collect, use, and store people’s data, not just a list of requirements that can be easily achieved by updating a privacy policy.
At first glance, this may appear quite straightforward; nevertheless, the multitude of interconnected requirements is what makes it confusing for companies to comply.
Why GDPR Is More Complex Than It Appears
GDPR compliance does not constitute an absolute and unified obligation but, rather, represents a composite entity consisting of the following:
- The requirements of a legal basis for processing personal information
- Individual rights that should be fulfilled by the company
- Security measures (technical and organizational)
Several firms believe that GDPR applies exclusively to organizations that operate in the EU geographically, but this is a misconception since GDPR extends beyond its borders and covers all organizations processing the information of EU citizens.
In order to comply with GDPR when working with data from different sources, separate compliance assessments should be performed for each kind of processing activity since different obligations will apply in each case.
Major Areas of GDPR Compliance
Lawful Basis for Processing
Rules Governing
- Consent as a lawful basis for specific data processing operations
- Legitimate interests assessments as the lawful basis for other processing operations
- The need for processing as a lawful basis for certain data operations
Using one general lawful basis is the most common and expensive problem since this can lead to:
- Processing operations not having any legal ground
- Inadequate consent mechanism which does not meet GDPR standards
- Penalties for improper processing of personal data

Individual Rights Fulfillment
Compliance with GDPR usually implies that the organizations should develop procedures where the systems need to comply with certain deadlines when responding to requests made by the data subjects.
Individual Rights Often Include
- The right of access to one’s own personal data
- The right to erasure, or right to be forgotten
- Right to data portability in a structured format

Data Protection Impact Assessments
Handling is composed of both normal processing functions and the growing need to conduct a formal risk assessment of risky processing, such as mass surveillance.
Those Assessments Usually Vary in Many Respects Including
- What causes the need for a formal risk assessment
- Documentation requirements expected by regulators
- Risk mitigation measures needed
Data Protection Officer Requirements
In many cases, the GDPR obliges some organizations to:
- Appoint a specific Data Protection Officer
- Ensure that the officer has sufficient independence and authority
- Keep processing activity records
The obligation to appoint a Data Protection Officer is conditional on the volume and kind of processing done by the organization.
Breach Notification Obligations
Some GDPR compliance programs demand that companies stay ready for the following:
- The ability to detect any breach early
- Notifying regulatory authorities within 72 hours where necessary
- Communicating to the individuals concerned in case the risk is too high
This readiness must be kept up since there are additional regulatory penalties for delayed breach notifications, apart from those for the actual breach.

Why GDPR Compliance Gaps Happen Even at Well-Intentioned Companies
Non-compliance rarely results from the company ignoring the regulation altogether.
Rather, non-compliance may be caused by the following factors:
- Consent procedures that do not meet the GDPR standards in terms of clarity and granularity.
- Existing processes for handling requests from data subjects that do not undergo any testing for speed of response.
- The initiation of new processing procedures without undergoing a compliance check.
How Organizations Approach GDPR Compliance
Mapping Data Processing Activities First
Bigger companies may keep track of every instance of personal data processing prior to compliance efforts, particularly where data is processed in more than one system and department.
Compliance Practices Supporting Genuine Readiness
Various compliance models allow organizations to:
- Test processes of fulfilling requests from data subjects on a regular basis
- Perform impact assessments for new instances of high-risk processing
- Keep clear records of processing activities
Ongoing Compliance Reviews
Periodic reviews are performed by organizations on:
- The legitimacy of the lawful basis used for processing
- The ability to detect and respond to breaches
- New guidance issued by data protection authorities
Through periodic reviews, organizations ensure GDPR compliance keeps pace with changes in processing activities and regulatory guidance.
Common GDPR Mistakes
Assuming GDPR Doesn’t Apply Outside the EU
Failing to take into account the regulation’s extraterritorial effect, for organizations that handle personal information of EU citizens.
Treating Consent as a Universal Lawful Basis
Misusing consent for processing activities, which may be done more appropriately under legitimate interest or contractual necessity.
Untested Data Subject Request Processes
Having a process for handling requests from individuals, but never having put that process to the test.
Poor Breach Response Readiness
Lack of proper preparedness for:
- Identification of the breach within the timeframe to report it
- Assessment of whether a breach should be reported to the regulators
- Effective communication with those affected
Ineffective breach management can result in further regulatory fines beyond the original problem.
Bottom Line
Compliance with the GDPR is very broad and includes many different factors like the lawful basis, fulfillment of individual rights, impact assessment, Data Protection Officer obligations, and breach notifications.
Given the extent of the regulation’s applicability beyond enterprises that have physical presence within the EU, it will be far more beneficial for businesses to analyze and develop processes to become compliant instead of simply updating their policies.