What the GDPR governs
The EU General Data Protection Regulation governs how organisations handle the personal data of individuals in the EU. It applies wherever you are based if you process that data, and it is principles-based rather than a control checklist — which makes it easy to nod along to and hard to operationalise. Its weight falls on lawful processing, transparency, the rights of individuals, security, and demonstrable accountability.
Establish a lawful basis
Every processing activity needs one of six lawful bases. Consent is only one of them, and often not the most robust — pick the basis that genuinely fits the activity and document it.
| Basis | Use when |
|---|---|
| Consent | The individual has given clear, freely-given, withdrawable permission |
| Contract | Processing is necessary to deliver a contract with the individual |
| Legal obligation | You must process to comply with the law |
| Vital interests | Processing protects someone's life |
| Public task | Processing is in the public interest or official authority |
| Legitimate interests | Your (or a third party's) interests aren't overridden by the individual's rights |
Honour data-subject rights
Individuals have rights over their data, and you need a repeatable process to satisfy a request within the statutory timeframe.
Receive
Any channel
Verify
Confirm identity
Locate
Across systems
Action
Access / erase / fix
Respond
Within the deadline
Demonstrate accountability
GDPR's accountability principle means it is not enough to comply — you must be able to show it. That means a Record of Processing Activities, documented lawful bases, security measures, DPIAs for high-risk processing, and a breach process able to notify within 72 hours where required. A connected evidence approach — where each obligation links to the artefact that proves it — is what keeps accountability real rather than aspirational, and much of it is reusable across ISO 27001 and India's DPDPA.
Common pitfalls to avoid
- Defaulting to consent for everything, when another lawful basis fits better and is more durable.
- Treating the Record of Processing Activities as optional — it is the practical foundation of the whole programme.
- Overlooking processors and sub-processors that handle personal data on your behalf.
- Having a breach policy but no tested process to actually meet the 72-hour notification window.