Top 10 GDPR Questions Answered | Skillcast (2024)

  • Information Security
  • GDPR

Posted by

Vivek Dodd

on 22 Jan 2024


The GDPR harmonised data privacy laws across Europe. It continues to give people greater protection over how their personal data is used.

Top 10 GDPR Questions Answered | Skillcast (1)

Almost six years after it came into force, many are still unsure of the basics of GDPR. And in the UK, Brexit has not exactly helped bring clarity.

So, we have answered the top 10 questions everyone has been asking.

For those wanting to avoid the hefty fines resulting from GDPR breaches, read our GDPR roadmap, which explains how to maintain compliance.

Top 10 GDPR Questions Answered | Skillcast (2)

Top 10 GDPR questions answered

1. What is the GDPR?

GDPR stands for the General Data Protection Regulation. GDPR came into effect on the 25th May 2018 as the new European Union Regulation, replacing the Data Protection Directive (DPD) and The UK Data Protection Act 1998.

After many years of debate, it was approved by the EU Parliament on April 14th 2016. It relates to the protection of personal data and the rights of individuals. Its main aim is to ease the flow of personal data and increase privacy and rights for EU residents across all member states.

In the UK, the Data Protection Act 2018 enshrined a version of the EU GDPR into the UK law, now called the UK GDPR.

2. When did the GDPR come into effect?

The Regulation came into effect on the 25th of May, 2018 and brought significant changes to current data protection laws.

Top 10 GDPR Questions Answered | Skillcast (3)

3. To whom does the GDPR apply?

Any organisation which processes and holds the personal data of EU citizens is obliged to abide by the laws set out by GDPR. This applies to every organisation, regardless of whether or not they reside in one of the 27 EU member states.

The UK retains the GDPR as the UK GDPR in domestic law, granting the country the freedom to evaluate and revise the framework as needed continuously. The UK GDPR also extends its jurisdiction to controllers and processors operating outside of the UK if their processing activities involve providing goods or services to individuals in the UK or monitoring the behaviour of individuals taking place within the UK.

This means that organisations based outside of the UK must still comply with the UK GDPR if they engage in these activities.

4. What responsibilities do companies have under the GDPR?

Under the UK GDPR, organisations have to meet seven data protection principles whenever they process personal data - including ensuring that their use of personal data is lawful, fair and transparent. Those who do collect it are obliged to protect it from misuse and exploitation.

If a data breach does happen, for example, if information gets lost or stolen. Then organisations are required under the GDPR to report certain types of breaches to the relevant supervisory authority within 72 hours of them becoming aware of it.

Top 10 GDPR Questions Answered | Skillcast (4)

5. What kind of information does the GDPR apply to?

Much like the Data Protection Act 1998, GDPR applies to personal data, meaning any information relating to an identifiable person who can be directly or indirectly identified by reference to an identifier.

According to gdpr-info.eu, this definition provides for a wide range of personal identifiers "such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person".

The ICO provides a full list of identifiers that could be used to distinguish an individual.

Crucially, organisations need to take extra care when processing special category (sensitive) data - for example, personal information about someone's race or ethnic origin, political or religious beliefs, biometric data, health, sex life or sexual orientation.

6. What rules should businesses follow to ensure compliance?

GDPR Article 5 states that personal data must be:

  • Processed lawfully, fairly and in a transparent manner
  • Collected only for specified, explicit and lawful purposes
  • Adequate, relevant and limited to what is necessary
  • Accurate and kept up-to-date
  • Kept only for as long as it is needed and no longer
  • Protected in a manner that ensures its security and integrity
    Top 10 GDPR Questions Answered | Skillcast (5)

7. What are the penalties for GDPR breaches?

The GDPR introduced a tiered approach to fines, meaning that the severity of the breach determines the fine imposed.

The maximum fine a company can face is 4% of their annual global turnover, or €20 million, whichever is the highest. For less serious violations, such as having improper records, there is a maximum of 2% of their annual global turnover, or €10 million. In the UK, this is £17.5 million or 4% of the total annual worldwide turnover in the preceding financial year, whichever is higher.

Each year,significant fines are issued for GDPR breaches. In the year following the introduction of the regulation, these reached hundreds of millions. Although the biggest penalties have gotten smaller, they still reach tens of millions.

8. How does Brexit affect GDPR?

If a company processes data about individuals in the context of selling goods or services to citizens in other EU countries, it needs to comply with the GDPR.

From the 1st of January 2021, the UK stopped being part of the EU, meaning that the EU GDPR no longer protected UK citizens. Now, the general data protection regime that applies to most UK businesses and organisations is the UK General Data Protection Regulation (UK GDPR), tailored by the Data Protection Act 2018.

It explains each of the data protection principles, rights and obligations. It summarises the key points you need to know, answers frequently asked questions and contains practical checklists to help you comply.

Top 10 GDPR Questions Answered | Skillcast (6)

9. Does everyone need a Data Protection Officer (DPO)?

It is not compulsory for organisations to appoint a DPO. It depends upon a number of factors.

The ICO stated a DPO is required if companies:

  • Are a public authority; with the exception of courts acting in their judicial capacity)
  • Carry out large-scale systematic monitoring of individuals, such as online behaviour tracking or
  • Carry out large-scale processing of special categories of data or data relating to criminal convictions and offences

Any organisation can appoint a DPO if they wish to do so. However, even if a company chooses not to appoint a DPO because the above doesn't apply to them, they must still ensure that they have sufficient staff and skills in place to be able to carry out their obligations under the GDPR.

10. What are GDPR fundamental rights?

  • The right to be informed - Individuals have a right to be told what personal data our organisation collects about them, the lawful basis that applies, how their data will be used, and who else it will be shared with. Companies must be completely transparent in how they are using personal data.
  • The right of access - Individuals have the right to obtain a copy of personal information that is held about them. This lets them check how their data is being processed and whether it is lawful.
  • The right of rectification - Individuals are entitled to have personal data rectified if it is inaccurate or incomplete.
  • The right to erasure - Also known as 'the right to be forgotten', this refers to an individual's right to have their personal data deleted or removed in certain circ*mstances.
  • The right to restrict processing - This refers to an individual's right to block or suppress the processing of their personal data (e.g. if there is an appeal pending).
  • The right to data portability - Individuals are entitled to move, copy or transfer their personal data from one IT environment to another, should they choose to do so (e.g. to "port" their data to another price comparison site).
  • The right to object - In certain circ*mstances, individuals are entitled to object to their personal data being processed. This includes if a company uses personal data for direct marketing, for its legitimate interests, for scientific and historical research, or for the performance of a task in the public interest.
  • Rights related to automated decision-making and profiling - The GDPR has put in place safeguards to protect individuals against the risk that a potentially damaging decision is made without human intervention. Individuals are entitled to request human intervention or challenge decisions where automated decisions are made and where the consequence has a legal or significant effect on them.

Top 10 GDPR Questions Answered | Skillcast (7)

Want to learn more about GDPR?

We've created a comprehensive GDPR roadmap to help you navigate the compliance landscape, supported by a comprehensive library of GDPR Courses.

We also have 100+ free compliance training aids, including assessments, best practice guides, checklists, desk-aids, eBooks, games, posters, training presentations and even e-learning modules!

Finally, the SkillcastConnect community provides a unique opportunity to network with other compliance professionals in a vendor-free environment, get priority access to our free online learning portal and other exclusive benefits.

Top 10 GDPR Questions Answered | Skillcast (2024)

FAQs

What are the 10 key requirements of GDPR? ›

The 10 Key Requirements of the GDPR
  • Recordkeeping: ...
  • Data Protection Officers. ...
  • Data Protection Impact Assessments. ...
  • Privacy by Design and Default. ...
  • Transparency and GDPR. ...
  • Informed Consent or another Basis for Processing. ...
  • Third Party Processing. ...
  • Data Subject Access Requests.

How to answer GDPR interview questions? ›

If you've worked with the GDPR in previous roles, offer an explanation of the type of work you carried out and how the GDPR related to it. You may also wish to mention any strategies you've used to ensure compliance with the GDPR in your previous work.

What are the 4 important principles of GDPR? ›

These principles include the lawful, fair, and transparent processing of personal data; the purpose limitation principle, which emphasizes the need to collect data for specified and legitimate purposes; the minimization principle, which requires organizations to only collect and retain the data necessary for the ...

What are the 4 key characteristics of GDPR? ›

Answer
  • fair and lawful processing;
  • purpose limitation;
  • data minimisation and data retention.

What are the golden rules of GDPR? ›

Necessary, proportionate, relevant, accurate, timely and secure: Ensure that the information you share is necessary for the purpose for which you are sharing it, is shared only with those people who need to have it, is accurate and up-to-date, is shared in a timely fashion, and is shared securely.

What are the 7 laws of GDPR? ›

The UK GDPR sets out seven key principles:
  • Lawfulness, fairness and transparency.
  • Purpose limitation.
  • Data minimisation.
  • Accuracy.
  • Storage limitation.
  • Integrity and confidentiality (security)
  • Accountability.
May 19, 2023

What is GDPR in one sentence? ›

GDPR stands for General Data Protection Legislation. It is a European Union (EU) law that came into effect on 25th May 2018. GDPR governs the way in which we can use, process, and store personal data (information about an identifiable, living person).

What is the GDPR for dummies? ›

The GDPR is a data privacy regulation from Europe that describes the rights individuals based in the EU/EEA have over their personal information processed by businesses (or natural persons outside of their personal use) and explains what guidelines businesses worldwide must follow to process their personal data legally ...

How to demonstrate knowledge of GDPR? ›

Maintain records of processing activities: Organisations must maintain detailed records of all GDPR compliance activities, including data protection audits, policies and procedures, training, and reviews. These records can be used to demonstrate compliance to data protection authorities if required.

What are the 8 pillars of GDPR? ›

Lawfulness, fairness, and transparency; ▪ Purpose limitation; ▪ Data minimisation; ▪ Accuracy; ▪ Storage limitation; ▪ Integrity and confidentiality; and ▪ Accountability. These principles are found right at the outset of the GDPR, and inform and permeate all other provisions of that legislation.

What are the key pillars of GDPR? ›

What are the 7 principles of the GDPR?
  • Lawfulness, fairness, and transparency.
  • Purpose limitation.
  • Data minimisation.
  • Accuracy.
  • Storage limitations.
  • Integrity and confidentiality.
  • Accountability.

What are the 8 rights of individuals under GDPR? ›

The GDPR has a chapter on the rights of data subjects (individuals) which includes the right of access, the right to rectification, the right to erasure, the right to restrict processing, the right to data portability, the right to object and the right not to be subject to a decision based solely on automated ...

What are the three main goals of GDPR? ›

There are three main goals of the GDPR that can be broken down into: 1) protecting the rights of users in regards to their data, 2) ensuring that data privacy laws keep up with the ever-changing landscape of technology, and 3) creating unified and consistent legislation across the EU.

What are the three primary conditions in GDPR? ›

Lawfulness, fairness and transparency

Your data processing must also not breach any other laws. To process data 'fairly', it must not be unduly detrimental, unexpected or misleading to data subjects.

What are the 6 lawful bases of GDPR? ›

Article 6 of the General Data Protection Regulation (GDPR) sets out what these potential legal bases are, namely: consent; contract; legal obligation; vital interests; public task; or legitimate interests.

What is GDPR and its requirements? ›

The GDPR sets out the information you should supply and when individuals should be informed. A Privacy Notice should include: (i) That you are the Data Controller and your contact details; (ii) The purpose of processing and legal basis for doing so (to assist with their complaint);

What are the 8 principles of GDPR? ›

Lawfulness, fairness, and transparency; ▪ Purpose limitation; ▪ Data minimisation; ▪ Accuracy; ▪ Storage limitation; ▪ Integrity and confidentiality; and ▪ Accountability. These principles are found right at the outset of the GDPR, and inform and permeate all other provisions of that legislation.

What is the GDPR compliance checklist? ›

In your list, you should include: the purposes of the processing, what kind of data you process, who has access to it in your organization, any third parties (and where they are located) that have access, what you're doing to protect the data (e.g. encryption), and when you plan to erase it (if possible).

What are the key regulations of GDPR? ›

Then, organizations must ensure that these operations comply with GDPR processing rules. Some of the most important GDPR principles include the following: All processing must have an established legal basis: Data processing is only acceptable if the organization has an approved legal basis for that processing.

Top Articles
Fees Versus Costs – Fees Are Important; It’s Costs That Matter
When Amazon Trade-In Is No Longer an Option, What Is? - BookScouter Blog
What Did Bimbo Airhead Reply When Asked
Prosper TX Visitors Guide - Dallas Fort Worth Guide
Do you need a masters to work in private equity?
Lycoming County Docket Sheets
Costco in Hawthorne (14501 Hindry Ave)
Roblox Character Added
Fire Rescue 1 Login
Ktbs Payroll Login
Nier Automata Chapter Select Unlock
104 Whiley Road Lancaster Ohio
Mills and Main Street Tour
Nutrislice Menus
Wicked Local Plymouth Police Log 2022
U Break It Near Me
Everything you need to know about Costco Travel (and why I love it) - The Points Guy
Rimworld Prison Break
Plaza Bonita Sycuan Bus Schedule
PCM.daily - Discussion Forum: Classique du Grand Duché
Which Sentence is Punctuated Correctly?
Hannaford Weekly Flyer Manchester Nh
Barista Breast Expansion
Pawn Shop Moline Il
fft - Fast Fourier transform
Top 20 scariest Roblox games
Buhl Park Summer Concert Series 2023 Schedule
130Nm In Ft Lbs
Rainfall Map Oklahoma
Gridwords Factoring 1 Answers Pdf
Wake County Court Records | NorthCarolinaCourtRecords.us
Where Can I Cash A Huntington National Bank Check
Metro 72 Hour Extension 2022
4083519708
Etowah County Sheriff Dept
Myanswers Com Abc Resources
Hellgirl000
The Banshees Of Inisherin Showtimes Near Reading Cinemas Town Square
Craigslist Mexicali Cars And Trucks - By Owner
Nsav Investorshub
Simnet Jwu
Updates on removal of DePaul encampment | Press Releases | News | Newsroom
Craigslist Farm And Garden Reading Pa
Coroner Photos Timothy Treadwell
Strange World Showtimes Near Century Stadium 25 And Xd
N33.Ultipro
The Complete Uber Eats Delivery Driver Guide:
Turok: Dinosaur Hunter
Theater X Orange Heights Florida
O'reilly's On Marbach
Les BABAS EXOTIQUES façon Amaury Guichon
Latest Posts
Article information

Author: Ms. Lucile Johns

Last Updated:

Views: 6156

Rating: 4 / 5 (61 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Ms. Lucile Johns

Birthday: 1999-11-16

Address: Suite 237 56046 Walsh Coves, West Enid, VT 46557

Phone: +59115435987187

Job: Education Supervisor

Hobby: Genealogy, Stone skipping, Skydiving, Nordic skating, Couponing, Coloring, Gardening

Introduction: My name is Ms. Lucile Johns, I am a successful, friendly, friendly, homely, adventurous, handsome, delightful person who loves writing and wants to share my knowledge and understanding with you.